The roadmap
Nothing on this page is written by hand. Every figure is read from two files this site pins: the specification’s generated feature board with the version manifests behind it, and the implementation status the binary’s repository keeps in the same pull request as the work it describes.
That has a consequence worth stating plainly. This page is as fresh as the revisions at the foot of it, not as fresh as this morning — the site renders a pinned checkout so a reader following instructions gets the instructions that match the release they installed. When the pins move, these numbers move.
- 3 of 12 milestones complete
- 225 of 239 recorded deliverables done
- 73 features and 1022 requirements, in areas A–L
A number here is a count of marks in the file behind it. Nothing is weighted: where a deliverable is half built, it counts as not done rather than as half, because “half” is a judgement the source file does not make.
The version train
Section titled “The version train”Releases run as a train — one version in flight at a time, its goals fixed before the work starts, and a gate that refuses to tag until every goal is demonstrably built. The version train explains the mechanism; this is the train itself.
It is one sequence, and it ends at 1.0.0 — the point where everything
specified is built and the interfaces stop moving. No version ships a stub: a
release refuses while a feature it locks is not yet built.
Each version below names the milestone it serves, how many of its locked requirements the status file marks done, and the features it carries, each with how far the catalogue says it is built. Expand one to see them.
0.1.0ReleasedCore: manifest, compose driver, CLIThe features it carries
B1Forms & partial stacksShippedCarried by 0.8.015 of 15 requirements builtC1DiagnosticsShippedCarried by 0.8.014 of 14 requirements built
0.2.0ReleasedSetup wizard + doctorThe features it carries
A1Prerequisites & account guidanceShippedCarried by 0.2.013 of 13 requirements builtA2Setup wizardShippedCarried by 0.2.015 of 15 requirements builtA3Credential validationShippedCarried by 0.13.015 of 15 requirements builtC1DiagnosticsShippedCarried by 0.8.014 of 14 requirements builtC5Storage & hardlink managementShippedCarried by 0.6.014 of 14 requirements built
0.3.0ReleasedBackup & restoreThe features it carries
E3Backup & restoreBuilding14 of 14 requirements built
0.4.0ReleasedAuto-wiring, seed, quality, trace and the first-content walkThe features it carries
C9Config drift detection & seed policyShippedCarried by 0.7.015 of 15 requirements builtD1Service auto-wiringShippedCarried by 0.12.018 of 18 requirements builtD2Quality presets in plain languageShippedCarried by 0.4.012 of 12 requirements builtD3First-content walkthroughShippedCarried by 0.4.013 of 13 requirements builtD9"Where is my show?" pipeline traceShippedCarried by 0.4.014 of 14 requirements built
0.5.0ReleasedHow the product speaks — errors, notifications, health, dashboard dataThe features it carries
B3Live dashboardBuilding12 of 15 requirements builtB5Notifications & alertingShippedCarried by 0.5.014 of 14 requirements builtG4Error & remedy modelShippedCarried by 0.5.015 of 15 requirements builtG7Overall health summaryShippedCarried by 0.5.013 of 13 requirements built
0.6.0ReleasedTrust checks: VPN, storage, queue healthThe features it carries
C2VPN verificationShippedCarried by 0.6.020 of 20 requirements builtC5Storage & hardlink managementShippedCarried by 0.6.014 of 14 requirements builtC7Queue health & stuck itemsShippedCarried by 0.6.015 of 15 requirements built
0.7.0ReleasedTrust checks: providers, support bundle, auto-remediationThe features it carries
C3Auto-remediationShippedCarried by 0.7.015 of 15 requirements builtC4Support bundleShippedCarried by 0.7.014 of 14 requirements builtC8Provider health & quota trackingShippedCarried by 0.7.014 of 14 requirements builtC9Config drift detection & seed policyShippedCarried by 0.7.015 of 15 requirements built
0.8.0ReleasedLive TUI: forms, lifecycle, logs and diagnostics as surfacesThe features it carries
B1Forms & partial stacksShippedCarried by 0.8.015 of 15 requirements builtB2Lifecycle controlShippedCarried by 0.8.015 of 15 requirements builtB4Log viewingShippedCarried by 0.8.013 of 13 requirements builtC1DiagnosticsShippedCarried by 0.8.014 of 14 requirements built
0.9.0ReleasedSpeaking plainly — interface tiers and the plain-language layerThe features it carries
C6Web UI security & binding policyShippedCarried by 0.10.017 of 17 requirements builtG1Interface tiersShippedCarried by 0.9.014 of 14 requirements builtG2Plain-language layer & in-product helpShippedCarried by 0.9.013 of 13 requirements builtG3AccessibilityShippedCarried by 0.10.015 of 15 requirements built
0.10.0ReleasedThe front door, its security, and the privacy stanceThe features it carries
C6Web UI security & binding policyShippedCarried by 0.10.017 of 17 requirements builtG3AccessibilityShippedCarried by 0.10.015 of 15 requirements builtG5The front doorShippedCarried by 0.11.013 of 13 requirements builtG8Privacy stanceBuilding12 of 14 requirements built
0.11.0ReleasedThe household asks — requests, identity, client appsThe features it carries
D4Household request flowShippedCarried by 0.11.014 of 14 requirements builtD6Household identity & invitationsShippedCarried by 0.11.014 of 14 requirements builtG5The front doorShippedCarried by 0.11.013 of 13 requirements builtG6Client app guidanceShippedCarried by 0.11.013 of 13 requirements builtG8Privacy stanceBuilding12 of 14 requirements built
0.12.0ReleasedLiving within limits — disk, retention, bandwidthThe features it carries
D1Service auto-wiringShippedCarried by 0.12.018 of 18 requirements builtD5Disk space managementShippedCarried by 0.12.014 of 14 requirements builtD7Request approval & quotasShippedCarried by 0.12.014 of 14 requirements builtD8Parental controlsShippedCarried by 0.12.013 of 13 requirements builtD10Bandwidth & schedulingShippedCarried by 0.12.014 of 14 requirements built
0.13.0ReleasedChanging your mind — reconfigure, migrate, uninstall, credentialsThe features it carries
A3Credential validationShippedCarried by 0.13.015 of 15 requirements builtA4ReconfigurationShippedCarried by 0.13.012 of 12 requirements builtA5Migration from an existing stackShippedCarried by 0.13.012 of 12 requirements builtA6Clean uninstallShippedCarried by 0.13.013 of 13 requirements builtA7Credential management & rotationShippedCarried by 0.13.014 of 14 requirements built
0.14.0StagedKeeping it running — updates, backup, rollback, the journalThe features it carries
E1Stack updatesBuildingNot tracked in the status file yetE2lemonfiber self-updateBuildingNot tracked in the status file yetE3Backup & restoreBuilding14 of 14 requirements builtE4RollbackBuilding0 of 2 requirements builtE5Changelog & release notesBuildingNot tracked in the status file yetG8Privacy stanceBuilding12 of 14 requirements built
0.15.0PlannedThe last of v1 — remote control, autostart, customisationThe features it carries
B6Controlling a stack on another machinePlannedNot tracked in the status file yetB8Autostart & boot persistencePlannedNot tracked in the status file yetB10Hosting long-running commandsShippedCarried by 0.13.016 of 16 requirements builtF1Customisation & escape hatchesPlannedNot tracked in the status file yetF2Service cataloguePlannedNot tracked in the status file yet
0.16.0PlannedPlugins — what one is, how it wires, and what it may stand in forThe features it carries
F3Plugin manifests and recipesPlannedNot tracked in the status file yetF4Capabilities and substitutionPlannedNot tracked in the status file yet
0.17.0PlannedPlugins — where they come from, what installing one does, and what it leaves readableThe features it carries
F5The plugin catalogue and what vouches for a pluginPlannedNot tracked in the status file yetF6Plugin lifecyclePlannedNot tracked in the status file yetF7Plugin provenancePlannedNot tracked in the status file yetG9Mobile client handoffPlannedNot tracked in the status file yet
0.18.0PlannedEcosystem glue: cross-seed, autobrr, quality-sync, subtitlesThe features it carries
H1Cross-seedingPlannedNot tracked in the status file yetH2Announce-driven grabbingPlannedNot tracked in the status file yetH3Quality-profile syncPlannedNot tracked in the status file yetH4SubtitlesPlannedNot tracked in the status file yet
0.19.0PlannedEcosystem glue: self-healing, cleanup, transcoding, statisticsThe features it carries
H5Queue self-healingPlannedNot tracked in the status file yetH6Library cleanupPlannedNot tracked in the status file yetH7TranscodingPlannedNot tracked in the status file yetH8Playback statisticsPlannedNot tracked in the status file yet
0.20.0PlannedSafely reachable — remote access and one accountThe features it carries
I1Remote access for the householdPlannedNot tracked in the status file yetI2Household identity & single sign-onPlannedNot tracked in the status file yet
0.21.0PlannedSee everything — metrics, dashboards, uptimeThe features it carries
B9Open notification back-endsPlannedNot tracked in the status file yetK1Metrics & dashboardsPlannedNot tracked in the status file yetK2Uptime monitoringPlannedNot tracked in the status file yet
0.22.0PlannedRuns without Docker — engine abstraction, Podman, nativeThe features it carries
J1Container-engine abstractionPlannedNot tracked in the status file yetJ2Running under PodmanPlannedNot tracked in the status file yetJ3Running natively, without containersPlannedNot tracked in the status file yet
1.0.0PlannedThe dashboard — a bare lemonfiber opens it. Everything specced is built, and the interfaces stop moving.The features it carries
B3Live dashboardBuilding12 of 15 requirements builtL1v1 release engineeringBuilding0 of 9 requirements built
Milestones
Section titled “Milestones”Milestones are the sequence the work is done in; versions are how it ships. One milestone can span several versions, and a version serves exactly one milestone.
Each milestone’s own mark is the one written beside its heading upstream. That can differ from the rows recorded beneath it, because a requirement is often recorded in the table of the milestone it grew out of rather than the one it belongs to — so a milestone whose recorded rows are all done can still be in progress. Where they differ, the heading is the milestone’s status and the rows are what has been written down here.
M0Specification
DoneIn the spec repo. Recorded here for context only.
Recorded in another repository
M0.5Governance in force
DoneCI, templates, and the citation-gated workflow are in force (DCO, CODEOWNERS, spec-references bot, labeler, SonarCloud gate, OpenSSF hardening).
Recorded in another repository
M1lemonfiber-media-stack standalone
In progressThe stack ships embedded as a submodule under assets/ and is read at build time; the manifest and compose fragments live there. The stack's own standalone CI lives in the lemonfiber-media-stack repo, where every form is resolved by docker compose config on each change.
Recorded in another repository
M2Core: manifest, compose driver, CLI
Done0.1.0, released. The parts everything else is built on: the manifest and its compile-time schema check, the compose driver, and the CLI they are reached through.
9 of 9 recorded deliverables done
What is recorded for it
- Workspace + cargo-dist scaffoldDone
- stack.toml parser + validation (compile-time schema check)Done
- Embedded assets (include_dir! + --stack-dir)Done
- Platform detection (macOS / Linux / Linux-Desktop / WSL2)Done
- Compose command builder (pure, golden-tested)Done
- Form closure + composition (B1-R4, B1-R5)Done
- up / down / restart / ps / logs / pullDone
- .env read/write (comment- and order-preserving)Done
- config get/set/show (with secret redaction)Done
M3Setup wizard + doctor
In progressThe product-thesis milestone, built partly ahead of order: the diagnostics harness and the first check landed before the wizard. Shipped as 0.2.0. The free-space projection was completed later, once the download-client read the dashboard work introduced made the queue reachable.
44 of 44 recorded deliverables done
What is recorded for it
- doctor — Check trait, remedy per findingDone
C1-R1 - Findings that share a cause say soDone
C1-R10 - Filesystem checks wait as long as a disk may takeDone
C1-R14 - Diagnostics — one check runnable by name, and how long a disruptive one lastsDone
C1-R5 - VPN leak test (exec gluetun + client, compare IPs)Done
- VPN egress verification — the comparison, and what it rests onDone
C2-R1 - Queue health — the assessmentDone
C7-R1 - Queue health — watching it across the servicesDone
C7-R9 - Queue health — reading the service's historyDone
C7-R4 - VPN port forwarding — the client, and keeping it alignedDone
C2-R4 - VPN egress, re-checked while traffic movesDone
C2-R9 - Storage — the consequence, and the services configured to matchDone
C5-R3 - The choices that are decisions, not faultsDone
C2-R13 - Storage — the single-mount ruleDone
C5-R5 - VPN killswitch, actually testedDone
C2-R7 - Preflight / Environment check (Docker present vs unreachable, Compose ≥ min)Done
A2-R9 - Empirical hardlink test (create / stat / inode + link-count)Done
C5-R1 - Storage-mode detection (fs type, network mount, exFAT, WSL2)Done
C5-R2 - Free-space check on the data rootDone
C5-R6 - Degraded-link detection (was linking, now not)Done
C5-R11 - Permission distinction (operator vs service PUID/PGID)Done
C5-R10 - Data-root availability supervisor (stop on loss, no auto-restart)Done
C5-R7 - Credential validation against live servicesDone
A3-R1 - A pasted key is taken as the key that was meantDone
A3-R5 - Credentials never reach an outcomeDone
A3-R6 - A wait that did not answer says how long it wasDone
A3-R7 - The tunnel's exit country is reportedDone
A3-R9 - One outage, said onceDone
A3-R11 - A certificate that was not trusted is namedDone
A3-R12 - Proceeding with an unvalidated credentialDone
A3-R13 - Every setup answer says what changing it costsDone
A4-R2 - A change is classified before it is made, and a consequential one is confirmedDone
A4-R3 - Nothing is written before the difference has been shownDone
A4-R4 - A replacement credential is proven before the working one is discardedDone
A4-R8 - A change that cannot be applied safely leaves the file alone and says whyDone
A4-R11 - Every setup answer is individually revisableDone
A4-R1 - Moving the data location carries the library or refusesDone
A4-R5 - Adding or dropping a way of downloadingDone
A4-R6 - A hand-edit to configuration is never overwritten silentlyDone
A4-R9 - A quality preset change affects future acquisitions onlyDone
A4-R12 - VPN port-forward validation + ProtonVPN NAT-PMP guidanceDone
A3-R8 - Prerequisites / account guidance (dependency map before credentials)Done
A1-R1..R13 - Wizard state machine (resumable, review-before-write, non-interactive guard)Done
A2-R1..R5 - Jellyfin native-mode + PUID/PGID offers (platform-aware)Done
A2-R6
- doctor — Check trait, remedy per findingDone
M4Seed & backup
In progressSpans 0.3.0 (backup & restore — the E3 rows below, complete) and 0.4.0 (auto-wiring & seed). Wiring services to each other and recording it so it can be undone. The lemonfiber seed command exists and wires the first edge — qBittorrent's web UI password (D1-R16): it reads the temporary password from the container's log, replaces it with a generated one through the client, and records the generated one in QBITTORRENT_PASSWORD where the forwarded-port push reads it. It also wires each media-filing *arr's root folders — one per media type, under /data/media — reading the application's key from its config and skipping an application that has not written one yet. It now also registers each *arr's download clients: SABnzbd where its generated key is on disk, qBittorrent where its password was minted this run — or, on a later run when nothing is minted, where the recorded password is read back from QBITTORRENT_PASSWORD, so an *arr that came up after the first seed still learns about qBittorrent. It now also runs Prowlarr's app sync in the other direction: each of those media-filing *arrs is registered back into Prowlarr as an application, so Prowlarr pushes it the shared indexers. And it makes Jellyfin the identity source for Seerr: Jellyfin has no key on disk, so lemonfiber mints its admin password by driving Jellyfin's own first-run setup, records it, and signs Seerr in through Jellyfin — never re-pointing an already-initialised Seerr, whose existing sign-ins are the household's.
18 of 19 recorded deliverables done
What is recorded for it
- service::Client port (Servarr shape)Done
- Servarr-shape adapter (identity, register client/root folder)Done
D1-R11 - Seed orchestration (skip-if-absent, preserve operator edits)Done
D1-R2..R6 - Download-client credentials (read own key / generate)Done
D1-R1 - Change journal (read-back + undo)In progress
E4-R1 - Backup & restore (quiesced capture, verify-before-replace, retention)Done
E3-R1..R4 - Drift detection & seed policy (baseline + three-way comparison)Done
C9-R1..R6 - Drift detection & seed policy (severity, re-baselining, full reset, stale update)Done
C9-R7 - Drift detection & seed policy (secrets withheld)Done
C9-R11 - Download-client / root-folder / Prowlarr / Jellyfin→Seerr wiringDone
D1-R7 - The book *arr is told where the indexers areDone
D1-R15 - Quality presets in plain languageDone
D2-R1..R12 - Pipeline trace — "where is my show?"Done
D9-R1..R7 - Pipeline trace — service disagreementDone
D9-R8 - Pipeline trace — honest about what it could not readDone
D9-R10 - Pipeline trace — history and the stuck-item landing pointDone
D9-R9 - Pipeline trace — series and season aggregationDone
D9-R13 - Pipeline trace — the household's own viewDone
D9-R12 - First-content walkthroughDone
D3-R1..R13
M5Trust checks
In progressThe P3 trust pillar made continuous, across three versions: 0.5.0 (how the product speaks — errors, notifications, health), 0.6.0 and 0.7.0. The VPN egress and killswitch proof, storage and hardlink verification, and queue health with its stuck-item categories shipped as 0.6.0; the provider checks, the support bundle and auto-remediation are 0.7.0. Those are recorded in the M3 table above, beside the setup-time checks they grew out of, rather than repeated here: a requirement named in two rows is one the release gate can read either way.
6 of 6 recorded deliverables done
What is recorded for it
- Provider health — what the accounts have leftDone
C8-R1 - Provider health — what the provider itself saysDone
C8-R2 - Indexer caps and when they resetDone
C8-R5 - Provider health in the no-downloads diagnosisDone
C8-R8 - Support bundleDone
C4-R1..R14 - Auto-remediationDone
C3-R1..R15
- Provider health — what the accounts have leftDone
M6Live TUI
In progressThe second surface over the same core (ratatui, per ADR-0003), spanning 0.8.0 (operating a running stack: forms, lifecycle, logs and the diagnostics that tie them together) and 1.0.0 (the interactive surfaces over it). The dashboard's read-only model shipped under 0.5.0 and its screen and refresh loop are built — the two rows below say so — so what remains of the dashboard is its layout polish and a *measured* idle cost rather than a renderer.
27 of 32 recorded deliverables done
What is recorded for it
- Live dashboard — the read-only modelDone
B3-R2 - Live dashboard — the surface, and the loop it refreshes inDone
B3-R1 - Idle cost — 1 Hz under 2% CPU, resident under 50 MBNot started
B3-R14 - Forms and profiles — what the manifest guaranteesDone
B1-R1 - Addressing an operationDone
B2-R4 - Starting, and what a service is doingDone
B2-R1 - Starting — narrated while it happensDone
B2-R2 - Operations say what they will affect firstDone
B2-R3 - Stopping — what is still coming downDone
B2-R13 - One lifecycle operation at a timeDone
B2-R14 - Stopping — what another running form still needsDone
B2-R7 - Stopping — the tunnel goes down lastDone
B2-R6 - Stopping and starting — asking twice is not an errorDone
B2-R5 - Forms — what one would start, said before it startsDone
B1-R3 - Forms — one service failing degrades, it does not roll backDone
B1-R11 - Forms — narrowing the active setDone
B1-R10 - Form switcher — interactive picker with closure previewNot started
- Logs — a container cannot rewrite the terminalDone
B4-R7 - Logs — severity read rather than guessedDone
B4-R6 - Logs — the evidence sits at the failureDone
B4-R5 - Logs — one account of what happenedDone
B4-R1 - Logs — read from the end, not from the beginningDone
B4-R13 - A shortened value still says which one it isDone
G3-R10 - One way out, and it renders for the terminal it hasDone
G3-R9 - Colour is never the only thing saying itDone
G1-R10 - Log viewer — exporting what is on screenDone
B4-R10 - Log viewer — a service restarting mid-viewDone
B4-R11 - Log viewer — filterable, with scrollbackDone
B4-R2 - Doctor view — interactive re-run, remedies inlineNot started
- Wizard in TUI — same state machine, richer presentationNot started
- Full-screen dashboard — narrow terminals, and lists too long to showDone
B3-R9 - Full-TUI layout polishNot started
B3-R10
- Live dashboard — the read-only modelDone
M7Web surface & UX
In progress0.9.0 and 0.10.0. A third surface — a web view over the same core — plus the cross-cutting UX (front door, health summary, error model, plain language, accessibility, privacy, web-security, support bundle). lemonfiber ui serves that surface: the read endpoints, the actions endpoint and the event stream, with the app served beside them where a build carries one. What the browser draws lives in lemonfiber-web. See the spec roadmap.
106 of 107 recorded deliverables done
What is recorded for it
- Error model — remedies, grouping, retryDone
G4-R1 - Error handling cannot cascadeDone
G4-R10 - Never the operator's fault, swept over every messageDone
G4-R5 - Health summary — one computation, from findingsDone
G7-R1..R13 - Plain language — the words, and a report that explains its ownDone
G2-R2 - Plain language — every surface explains its wordsDone
G2-R1 - Explanations can be put away, and turned offDone
G2-R7 - Numbers carry the consequence, where there is one to carryDone
G2-R4 - Plain language — the shapes a false picture takesDone
G2-R8 - Plain language — the rules that are now testsDone
G2-R3 - Plain language — the words it had not explainedDone
G2-R13 - A failure cannot drive the terminal, and explains its own wordsDone
G2-R10 - Every answer a script asked for is one it can parseDone
G1-R7 - Live state — the stream a browser holds openDone
ARCH-R49 - Redirected output — plain text, said onceDone
G3-R7 - Nothing is reachable by mouse aloneDone
G3-R4 - A question is asked without a clock on itDone
G3-R12 - Severity is a word, and the colour is a second copy of itDone
G3-R14 - A long wait says what it is waiting forDone
G3-R11 - The third surface starts, says what it is, and stopsDone
G1-R5 - The web API writes only what the command line canDone
ARCH-R48 - One envelope, and one rendering of itDone
ARCH-R46 - A refused read says which refusal it isDone
ARCH-R74 - What a request must carry before it is answeredDone
ARCH-R52 - The contract is generated, and a stale one fails the buildDone
ARCH-R56 - An SDK generates from the artefact and reaches nothing elseDone
ARCH-R58 - A client reads what it was handed, or refuses itDone
ARCH-R55 - The frontend is embedded, and serving it is not the core's businessDone
- Every admin service answers this machine and nothing elseDone
C6-R1 - What a cross-site request cannot sendDone
C6-R10 - Nothing is carried through to a service's own interfaceDone
C6-R12 - The password this surface asks for, kept as what proves itDone
C6-R8 - The second way in, and what ends itDone
C6-R9 - Guessing costs time, and is told how muchDone
C6-R11 - Offered to a network, or refusedDone
C6-R4 - The policy is one decision on both familiesDone
C6-R14 - No certificate it made for itselfDone
C6-R7 - What is actually listening, asked of the thing that is listeningDone
C6-R13 - The household tier is reachable, and narrows through one settingDone
C6-R2 - A rule you added does not decide, where it does notDone
C6-R16 - An exposure somebody agreed to is theirs, and still reportedDone
C6-R15 - An exit code says which kind of wrongDone
G1-R8 - The dashboard on a terminal that offers nothingDone
G1-R9 - One stack, one run at a time, whichever surface askedDone
G1-R12 - Setup is completable from the browser tooDone
G1-R14 - The third surface drives the same logic and adds none of its ownDone
G1-R2 - Every action reachable from every surfaceDone
G1-R1 - The web surface is swept at the level it owes, in every rendering a reader arrives inDone
G3-R3 - A reader who asks for stillness gets it, and something checks every screenDone
G3-R5 - Nothing repeats fast enough to flash, in either surfaceDone
G3-R6 - The type follows the reader's own size, and the palette answers the systemDone
G3-R13 - A bare run asks the screen, and says the whole of itDone
G1-R3 - A repair asks nobody who is not thereDone
G1-R4 - A narrow terminal is a terminal, not a smaller oneDone
G3-R8 - Text this product did not write cannot drive the terminal it is shown onDone
G3-R15 - Nothing reports on you, and something notices if it starts toDone
G8-R1 - A bundle, a backup and a log stay on the machine that made themDone
G8-R6 - The two references are generated, and a stale one fails the buildDone
ARCH-R68 - The household has one front door, and nothing stands in for itDone
G5-R1 - The front door's address, read now rather than rememberedDone
G5-R8 - What to do when it does not workDone
G6-R9 - The address as something to point a camera atDone
G6-R4 - Which app to watch on, and where the answer is to use something elseDone
G6-R1 - Who has never arrived, on the list everybody else is onDone
G6-R13 - What playback will struggle with, said before an app is chosenDone
G6-R6 - What the household is waiting on, without being askedDone
D4-R8 - Nobody in the house needs an account hereDone
D4-R9 - The person who asked hears backDone
D4-R2 - What the wiring graph still owesDone
D1-R18 - The arrs that fulfil what the household asks forDone
D1-R17 - Asking for part of a series, and only what you may ask forDone
D4-R11 - Something already here, and something not out yetDone
D4-R5 - Ready means the library has itDone
D4-R12 - A request that keeps failing is not failing quietlyDone
D4-R14 - Nothing at the quality you chose is its own answerDone
D4-R7 - Asking for something already asked forDone
D4-R10 - One way in, and it is the account somebody already hasDone
D4-R1 - A door that is down and a door with no way to it are two answersDone
G5-R13 - The door is chosen, and nothing beside it is a way inDone
G5-R10 - The address reaches the third place it was owed, which is an invitationDone
G5-R6 - An invitation is a link, and the same link as a codeDone
D6-R4 - What an invitation does not hand overDone
D6-R2 - The household list is a list of membersDone
D6-R7 - An invitation outlives a request service that is downDone
D6-R12 - Removal reaches both services, and says what it costs firstDone
D6-R8 - A reset is an invitation againDone
D6-R10 - An expired invitation keeps its accountDone
D6-R13 - Access is chosen when somebody is invitedDone
D6-R5 - A limit is said in the certificates the household already readsDone
D8-R1 - One setting, and both halves of what it meansDone
D8-R2 - What the media server does with a limit, once it has oneDone
D8-R8 - Every outbound request is enumerable, and each is switched off on its ownDone
G8-R3 - What is kept on this machine, and taking it offDone
G8-R7 - What actually left, written down as it wentDone
G8-R14 - Somebody being asked to join is told the operator can see what they watchDone
G8-R13 - What the privacy stance still owesNot started
G8-R4 - The app the browser is served, and the version it speaksDone
ARCH-R54 - The disk accounted for, and exhaustion seen comingDone
D5-R1 - Removing a torrent that is still seedingDone
D5-R6 - What a household may ask for, and what it may ask for nowDone
D7-R1 - What a thing costs, said where somebody is deciding what to ask forDone
D7-R3 - A limit stated before submission, and a period that says how it frees upDone
D7-R5 - A refusal that requires a reason, and the reason reaching the person who askedDone
D7-R7 - A reminder that is built, and an expiry the household agrees to in advanceDone
D7-R8 - A full disk that stops the asking, and says so on the page they ask fromDone
D7-R13 - The line accounted for, and the stack held to a share of itDone
D10-R1 - The quiet half of the household's day, and what happens at a capDone
D10-R3
- Error model — remedies, grouping, retryDone
M8Household & content
Not started0.11.0 and 0.12.0. The request flow, one-account identity, approval quotas, parental controls, disk-space and bandwidth management, client-app guidance. Not started. See the spec roadmap.
Recorded in another repository
M9Lifecycle & maintenance
In progress0.13.0, 0.14.0 and 0.15.0. Reconfiguration, migration, uninstall, notifications, remote control, autostart & boot persistence, stack and self updates, rollback, and the service catalogue. Notifications are in, and so is part of the change journal 0.14.0 locks — that is recorded in the M4 table above, beside the seeding it was built for. Uninstall is in, in the row below, and so now are the two families 0.13.0 carries: every setup answer is individually revisable, and a setup already on the machine can be surveyed, adopted, stood beside, stood in place of, or carried across. Of the rest, nothing is started: no command updates the stack or itself, rolls back, or lists a service catalogue, and the web surface is loopback-only by design rather than remote control. Autostart is the one to be careful about: setup asks the question and takes a --autostart flag, and the wizard says in as many words that the answer has no configuration home and is collected but not written. An answered question is not a boot-persistent stack, and nothing here brings the *stack* back after a reboot. This repository does now name launchd and systemd, and it is worth being exact about what for: they are reached to keep lemonfiber's own long-running commands going, which is B10 below and is a different subject from the stack coming back. Neither Docker Desktop's login item nor a container restart policy is touched by it. See the spec roadmap.
15 of 15 recorded deliverables done
What is recorded for it
- The refresh loop as the driver — and in-app deliveryDone
B5-R4 - Notifications & alertingDone
B5-R1 - Critical alerts bypass quiet hoursDone
B5-R11 - A read-only survey of what is already on this machineDone
A5-R1 - What no migration carries across, and what an import left behindDone
A5-R8 - An existing *arr database is never opened by an older binaryDone
A5-R6 - Four modes, adopt already chosen and replace neverDone
A5-R3 - A migration never touches the media it foundDone
A5-R4 - An existing layout that breaks hardlinks, costed and left aloneDone
A5-R10 - Clean uninstall — four removals, each explicitly chosenDone
A6-R1 - One inventory of every credential, showing none of themDone
A7-R1 - Rotation that validates before it destroys, and reports every consumerDone
A7-R4 - Credential files owner-only, and a finding when they are notDone
A7-R8 - The credential lemonfiber mints because the service offers nothing durableDone
A7-R14 - Long-running commands hosted by the machineDone
B10-R1..R16
- The refresh loop as the driver — and in-app deliveryDone
M10Release engineering
In progressSigned, multi-platform release automation and the install paths a non-contributor follows. The cargo-dist pipeline runs on every tag and, from v0.3.0 onwards, each release carries attested archives for both macOS targets and both Linux targets, their checksums, and a shell installer. Windows and the tap are what the install paths still want.
0 of 7 recorded deliverables done
What is recorded for it
- CI hardening — DCO, CODEOWNERS, SonarCloud gate, OpenSSFIn progress
- cargo-dist release workflow — mac (arm64/x86_64), Linux (gnu/musl), WindowsIn progress
L1-R1 - homebrew-tap — auto-published by CINot started
L1-R3 - Shell + PowerShell one-line installersIn progress
L1-R4 - Real Windows + Linux testing — beyond "it compiles"Not started
L1-R6 - Docs site — generated from the specIn progress
L1-R7 - Epoch completeness — every v1 feature Accepted and done before 1.0.0Not started
OPS-R54
Where this comes from
Section titled “Where this comes from”- What is built — the status file itself, rendered whole
- The version train — how a release is staged and gated
- The roadmap in the specification — the narrative behind the sequence
- The feature board — every feature, its area and how far it is built
- The version manifests — the contract each file above obeys
Read from the revisions this site pins:lemonfiber/spec at 1d10402, 2026-09-09 · lemonfiber/lemonfiber at a2ac9bf, 2026-09-09