ainfra

Roadmap

The ainfra v1 roadmap begins with the core lifecycle and expands through hardening, templates, integrations, and release readiness. It is generated directly from the authoritative specification.

Total
23
Shipped
10
Idea
13

Confidential infrastructure

attested platforms and confidential secret release

Phase 22 Idea

Confidential computing and live attestation

Provision and describe confidential-computing targets, supported TEE and runtime capabilities, Trustee and KBS services, attestation and reference-value policy, confidential secret backends, and signed live or remote evidence; prove an ainfra-to-aibox handover that binds deployment provenance to current attested infrastructure without making ainfra the workload or secret-management authority.

Engine evolution

deliberately distant architectural options

Phase 21 Idea

Exchangeable infrastructure engine

Evaluate a versioned provisioning-engine contract that could support alternatives to OpenTofu, including configuration-led or Ansible-only templates, without weakening native inputs, reviewed change approval, teardown semantics, recovery, or audit evidence.

Policy and coordination

potential directions

Phase 20 Idea

Remote execution protocol

Run the same CLI lifecycle in a controlled remote environment while preserving explicit credentials, reviewed plans, child-tool boundaries, and auditable results.

Phase 19 Idea

Deployment-set coordination

Coordinate several independent deployments while preserving separate state, locks, reviewed plans, approvals, and failure boundaries.

Phase 18 Idea

External policy checks

Pass sanitized manifests or plan summaries to an external policy engine at explicit lifecycle gates and enforce its result without owning a policy language.

Extended provisioning

infrastructure-adjacent bootstrap

Phase 17 Idea

External cluster bootstrap

Invoke a dedicated external tool for initial k3s or comparable Kubernetes installation through a bounded child-process contract, like OpenTofu and Ansible, without taking on cluster maintenance.

Template ecosystem

authoring, compatibility, and trust

Phase 16 Idea

Authoring and editor integration

Publish schema bundles, completions, and editor integrations that consume doctor JSON without introducing another configuration language.

Phase 15 Idea

Operational evidence export

Export sanitized and attributable deployment evidence for audits and support without exporting plans, state, credentials, or sensitive output.

Phase 14 Idea

Catalog and trust metadata

Define interoperable discovery metadata for certified Git-hosted templates, including compatibility, publisher identity, signatures, attestations, and revocation.

Phase 13 Idea

Compatibility and migration experience

Improve fixtures, compatibility diagnosis, deprecation reporting, and safe template-contract migration previews as contracts evolve.

Template coverage

useful deployments out of the box

Phase 12 Idea

Specialized compute templates

Add templates for Vast.ai and similar GPU or on-demand compute providers, with explicit lifecycle and teardown limitations.

Phase 11 Idea

Complete major-cloud templates

Add comparable certified templates for AWS, Microsoft Azure, and Google Cloud while preserving the same native-file and output contracts.

Phase 10 Idea

Verifiable consumer target handover

Evolve the single standardized infrastructure result with a versioned, non-secret target projection for workload consumers; cover capabilities, endpoints, symbolic secret-provider, credential, and trust references, compatibility, deterministic deployment provenance, DSSE signing, signer and freshness policy, and one proven ainfra-to-aibox handover without treating discovery or signatures as proof of current live infrastructure state.

Phase 9 Shipped

Initial production template

Ship and certify the first Kubernetes-ready template with private access, tunneled ingress, and temporary administrative access.

Read phase note →

Template authoring

the v1 authoring promise

Phase 8 Shipped

Template authoring and conformance

Publish schemas, examples, conformance diagnostics, and human and AI guidance, then prove through clean-room authoring that a new template can be created without reading ainfra implementation source.

Read phase note →

Automation interface

read-only by default with explicitly authorized agent operations

Phase 7 Shipped

Guarded MCP server mode

Serve doctor, inspection, status, schemas, and sanitized run results over MCP stdio by default, and expose explicitly allowlisted planning and plan-bound lifecycle mutations through the same typed application use cases, authorization, locking, evidence, and recovery contracts.

Read phase note →

Infrastructure lifecycle

opentofu and ansible orchestration

Phase 6 Shipped

Destruction, recovery, and hardening

Add reviewed destroy plans, teardown verification, interruption recovery, redaction, binding checks, cache defenses, and negative security fixtures.

Read phase note →
Phase 5 Shipped

Output, inventory, and Ansible

Validate standardized non-secret output, generate deterministic inventory, run Ansible with native variables, and verify zero-change convergence.

Read phase note →
Phase 4 Shipped

Reviewed OpenTofu plans

Initialize native OpenTofu configuration, create bound saved plans, apply only the reviewed plan, and record durable run evidence.

Read phase note →

Foundation

the product contract

Phase 3 Shipped

Immutable template sources

Resolve local and Git-subdirectory sources, lock revisions and digests, materialize contained workspaces, and detect source or cache drift.

Read phase note →
Phase 2 Shipped

Contracts and doctor

Discover deployments, parse manifests and native files, validate ainfra-owned contracts, and report stable text and JSON diagnostics plus safe local reconciliation through one doctor surface.

Read phase note →
Phase 1 Shipped

Go project foundation

Establish the Go module, command shell, typed results, process and filesystem boundaries, test fixtures, developer tools, and Linux/macOS builds.

Read phase note →
Phase 0 Shipped

Product specification

Finalize the v1 boundary, native-file contracts, security model, Go architecture, schemas, examples, and acceptance journeys.

Read phase note →