2026 · Q2
Done
The end-to-end spine is wired: enrollment, ad-hoc
backup, status, persisted job runs. Bearer + HMAC auth shipped.
Self-serve install scripts and the central portal go too.
Now
In flight
Phase B — owner model for repos and jobs (local vs
server), local-vault encryption of sensitive columns,
inventory sync, override governance.
Next
Phase C
NATS JWT per-agent credentials so multi-tenant isolation stops
being honour-system. Resume in-flight jobs after agent restart.
Later
Phase E
Restore workflows in the portal, Keycloak SSO for admins,
installer generation, agent auto-update with signed manifests.