Operate Web Fleet

Roadmap

Web Fleet is being built from the monitoring foundation outward. CP1 through CP29 are implemented in development: performance history, manual browser Audit, privacy-first analytics, backup/restore, Linux service lifecycle, PostgreSQL support and retention/maintenance now sit on top of the monitoring foundation.

Phase 1 · done

Prove the monitoring loop

Application foundation, admin authentication, grouped site inventory, HTTP checks, scheduler, fleet health, incidents and in-app alerts.

Phase 2 · implemented in development

Understand websites

TLS, DNS, headers, redirects, crawling, link health and server-side performance history are implemented. Audit is manual by default, and audit history is opt-in.

Phase 3 · implemented in development

Privacy-first analytics

Optional tracker, ingestion, retention, rollups, dashboards, custom events and goals.

Phase 4 · implemented in development

Self-hosting reliability

Backup/restore, service lifecycle, first-run SQLite/PostgreSQL choice and retention/maintenance.

Phase 5 · implemented in development

Agency and enterprise foundations

Organizations/RBAC, scoped API tokens, OIDC, optional worker separation and a measured no-extra-infrastructure-yet scale decision.

Phase 5

Agency and enterprise scale

Users, organizations, RBAC, API tokens, OIDC and optional worker/process separation.

Phase 6

Integrations and public preview

Deployment observations, notifications, accessibility, large-fleet UX, hardening and release readiness.

Explicitly not first

Website hosting, DNS management, CDN/proxy services, deployment execution, session replay, heatmaps, visitor fingerprinting and host telemetry are intentionally outside the first product.

The application repository contains the detailed living checkpoint plan. Public documentation will be updated as checkpoints move from planned to implemented.

Battle-hardening and release

Implementation is complete through CP29. CP30 is deliberately an adversarial campaign: PostgreSQL parity, external OIDC interoperability, SSRF/security review, cross-platform CI, scale measurements, recovery rehearsals and ordinary-user UX attacks. CP31 remains blocked until that evidence is clean.