Every line of the roadmap is an RFC in the shpyrd repository that is not done yet: in progress is partly shipped, ready to implement is decided and waiting for someone to pick it up, proposal still has open questions (each with a default). What is done is in the rest of these docs. Priorities move with feedback in GitHub issues.
Platform
| Item | RFC | Status |
|---|---|---|
| Cost visibility | RFC-0048 | ready to implement |
| Workspaces: the workspace every project, team and person belongs to | RFC-0033 | in progress (control-plane database and the Workspace page in v0.4.0; sign-in at the edge, the user role, access modes and the launcher in v0.5.0; login methods, join policy, company domains, the everyone team and suspension in v0.6.0; allow lists v0.7.0; CLIs v0.8.0; the workspace from the host, sign-in at the workspace host, plan limits, the CLI over the API in v0.9.x; an audit in v0.9.10 fixed allow lists, suspension of public apps and backups of every workspace; v0.9.11 keeps the edge's promises: personal tokens open apps, sign-out from an app, key rotation, JSON 401 for API clients, a NetworkPolicy for the server, denial counters; v0.9.11/v0.9.12: native uuid identifiers with golang-migrate, image repositories keyed by the workspace id; v0.9.13: workspace roles (owner, admin, member) and invitations accepted by signing in; v0.9.15: per-workspace SSO, the email-first login step for claimed domains, the reader role; v0.9.16: address change with redirects, custom workspace domains (CNAME mode), the launcher for everyone with search and featured apps, workspace branding, the MCP server — the remaining gaps (workspace delete, per-workspace login methods, custom workspace domains) are listed in the RFC) |
Deploying
| Item | RFC | Status |
|---|---|---|
Shared volumes (storage-rwx) | RFC-0041 | ready to implement |
| Private repositories (tokens, deploy keys) | RFC-0017 | proposal |
| Auto-deploy on push (webhooks, polling) | RFC-0018 | proposal |
| GitHub App: connect once, pick repositories, statuses | RFC-0054 | ready to implement |
| Autoscaling mode (min/max, HPA, KEDA) | RFC-0047 | ready to implement |
| Maintenance mode | RFC-0020 | proposal |
| Run history and scheduled tasks | RFC-0024 | proposal |
| Web terminal | RFC-0026 | ready to implement |
| Builds namespace and enforce-mode Pod Security | RFC-0043 | ready to implement |
Data stores
| Item | RFC | Status |
|---|---|---|
| Postgres pooling, credential rotation, resize | RFC-0039 | ready to implement |
| Redis high availability and metrics exporter | RFC-0040 | proposal |
| Resource detail pages with their own metrics | RFC-0028 | proposal |
Observability
| Item | RFC | Status |
|---|---|---|
| Structured (JSON) logs in the viewer and CLI | RFC-0021 | ready to implement |
Log storage and history (Loki as an add-on, --since) | RFC-0022b | proposal |
| Application metrics v2 (per instance, aggregation, totals) | RFC-0027 | ready to implement |
| OpenTelemetry collector and export | RFC-0029 | proposal |
| Tracing backend (Jaeger) and a Traces tab | RFC-0056 | ready to implement |
| Notifications: webhook, Slack, email | RFC-0030 | proposal |
| Audit trail v2 (durable, cluster-wide, export) | RFC-0025 | proposal |
Access
| Item | RFC | Status |
|---|---|---|
kubectl through the platform's sign-in (shpyrd auth kubectl) | RFC-0062 | proposal |
| Dashboard access zones: public dashboard with intranet-only areas | RFC-0063 | proposal |
| Account lifecycle: reset, verification, lockout (invitations shipped with RFC-0033 in v0.9.13) | RFC-0014 | done (v0.9.45) |
| Signed-in detection on identified apps: a signed-in person is identified from the first page, however they arrive | RFC-0068 | proposal |
| Embedded git: a repository per project the platform keeps — deploys commit, pushes deploy, agents work on it | RFC-0069 | proposal |
Internal names: http://crm.internal between projects, with a service identity | RFC-0070 | proposal |
| AI gateway: model calls through the platform, metered and budgeted per project | RFC-0071 | proposal |
| App actions: endpoints an app declares that the platform runs for a person (assistants, launcher) | RFC-0072 | proposal |
| Data in backups: database archives and volumes in the platform backup; workspace data export | RFC-0073 | proposal |
| SCIM provisioning: people and teams from the company directory, immediate deprovisioning | RFC-0074 | proposal |
| MFA and passkeys | RFC-0053 | ready to implement |
| Grafana behind shpyrd sign-in | RFC-0015 | proposal |
| MCP connector for AI agents: every workspace is a remote MCP server with OAuth 2.1 and read tools | RFC-0032 | in progress (v0.9.16: remote server, OAuth 2.1, read tools; writing tools, stdio mode still missing) |
| Supply chain and encryption at rest | RFC-0044 | ready to implement |