Skip to content

v2 Appliance Roadmap — sequencing & gates (provisional) #394

Description

@VijitSingh97

Single source of truth for the v2 appliance plan — same format as #364. Provisional by design: this is the far-horizon epic tier; it re-sequences whenever the v1.x line ships something it depends on. Re-sequenced 2026-07-22 on the ratified dual-distribution plan (full ADR lands as docs/dev/dual-distribution-plan.md with the phase-0 PR; decision comments on #77/#78).

The theme: v2 turns the stack from software you install into a machine you boot. One immutable appliance image — Debian 13 + Rugix A/B updates, running the stack on Podman/Quadlet — serving both the flashable USB path and a raw self-deployable image, plus a curl installer for the DIY channel, which stays on Docker Compose unchanged. The 2026-07-22 plan supersedes the earlier Ubuntu-autoinstall phasing (#77) and the open runtime question (#78 → outcome A, spike pending). Deployment flexibility — remote Tari (#103) and co-hosting (#181) — is out of the dual-distribution plan's scope: both are stack config features that apply to every channel, and they sequence independently.

   #78  Quadlet spike on Debian 13 ──► binding go/no-go (netavark firewall port first)
                 │                     hand-written units become renderer fixtures
                 ▼
   #77  dual distribution (the epic — plan ratified 2026-07-22)
         phase 1: curl installer + render-quadlet + mandatory cosign
         phase 2: Rugix appliance — exit bar: boots / atomic update / rollback /
                  7-day unattended soak on the #54 bench
         phase 3: first-boot provisioning (config.json pre-seed, then the #33 wizard)
         phase 4: release os-image lane, stable/beta channels, boot-test per cut

   Deployment-flexibility facet — independent of the dual-distribution plan:
   #103  tari.mode: remote — verdict GO (trusted-network-only); implementation
         open as PR #754. With Monero remote mode, a full-remote stack runs
         zero node containers — the nodes' runtime decoupling completes here
   #181  co-hosting — DIY-channel concern (the appliance assumes a dedicated box);
         auth-fail-closed rule applies

Release status — tier not open

Gates: #78 spike passes its go/no-go · #77 phase-2 exit bar (boots / atomic update / rollback / 7-day soak on the #54 bench) · #77 phase-4 boot-test wired into the release cut · #103 lands via PR #754 (verdict was GO; different-machine e2e folds into its release) · #181 split merged with the auth-fail-closed rule.

Metadata

Metadata

Assignees

No one assigned

    Labels

    appliancePithead OS appliance work — lands on feat/phase2-bakery-imageinfraDeployment, packaging, releases

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions