Skip to content

Roadmap

What we are building now, what comes next, and what has already landed.

The current plan is security and stability. It is built in waves: first make upgrades safe, then make the breaking changes while few sites depend on today's shapes, then harden the network, then stability, then new capabilities. Now is being built, Soon is planned, and a date means it is built and running on the unstable channel. Every two weeks the next version is cut for staging and reaches production two weeks later; the version on a landed item is the one that carries it.

Now

One NixOS baseline

Every app VM builds on the same hardened base configuration, instead of each module carrying its own copy.

wave 1
Now

Module blueprint check

A check that every module ships what it should, and apps grouped by stack in the repository.

wave 1
Now

Recovery you have rehearsed

Restores practised on the test system, and a documented, tested way to rebuild a firewall or a node.

wave 1
Now

VM lifecycle & capacity

Memory and disk defaults based on measurement, drift detection, clean shutdowns and a sensible boot order.

wave 3
Now

App module fixes

Home Assistant, Nextcloud Talk, LiteLLM and friends: the known rough edges fixed, and tested so they stay fixed.

wave 3
Soon

Secrets & privileged access

One interface for secrets — simple first, OpenBao behind it later — and Proxmox hardened to its guide.

wave 1
Soon

Firewall hardening

Tighter defaults: the admin GUI only from management, anti-spoofing always on, no zone-wide gateway rule — each change shown as a dry-run diff before it applies.

wave 2
Soon

Sturdier DNS

DNSSEC, a clear IPv6 stance, public DNS that follows a dynamic WAN address, and optional blocklists.

wave 2
Soon

Single sign-on, everywhere

Every app wired to the identity provider the same way, with a login page that shows your site.

wave 3
Soon

Production-grade AI stack

LiteLLM and Open WebUI tested, sized to their defaults, and kept current.

wave 3
Soon

Easier first install

An installer that can resume, shows its progress, and only asks what applies to your hardware.

wave 3
Soon

Alerting

Be told when a node drops out or the cluster loses quorum, with a second cluster link for resilience.

wave 4
Soon

Finer-grained publishing

Publish only some paths of an app, or only to some zones or source addresses.

wave 4
Soon

Storage & devices

Network storage for the cluster (NFS first), and modules for physical devices on your network.

wave 4
27 Sep 2026

Security scan

After every update, TAPPaaS lists what runs — machines, containers, nodes and firewall — as a CycloneDX SBOM, checks it against CVE databases, and tells the owner what needs a fix.

2.2
25 Sep 2026

Nextcloud 35

Nextcloud moves to version 35. The Talk stack for calls ships with it and is still being finished end to end (see App module fixes).

2.2
25 Sep 2026

NixOS 26.05

The whole estate moves to NixOS 26.05. A release move is staged for the next boot, never half-applied to a running machine.

2.1
23 Sep 2026

Release channels

Unstable, staging and production: a site takes a change only after it has run on the channel before it.

2.1
22 Sep 2026

A control plane that checks itself

The management VM checks itself after every update, and rolls back when the check fails.

2.1
21 Sep 2026

Site-wide settings

Time zone, keyboard, location and time source set once for the site, and applied to every machine.

2.1 · wave 1
20 Sep 2026

One module contract

Every module has the same shape, and its version and status claims mean something.

2.1 · wave 1
19 Sep 2026

Backups where you want them

You choose where backups go, hosts get file-level backups, and existing Debian machines can be brought under management.

2.1 · wave 1
16 Sep 2026

Safe upgrades

Versioned config migrations with a backup and a dry run, and a failed install that cleans up after itself.

2.1 · wave 0
15 Sep 2026

Updates you can trust

Honest pre-update checks, an update window you schedule, and an email to the owner when an update fails.

2.1 · wave 0
21 Jul 2026

TAPPaaS 2.0

One model for people, apps, environments and health, a new website, and a migration path from 1.x.

v2.0
13 Apr 2026

TAPPaaS 1.0

The first release: automated installation for a home or a small business, running on real systems.

v1.0.0

How we plan