docs: consolidate product roadmap and source docs

This commit is contained in:
a.tolmachev
2026-05-03 15:40:10 +00:00
parent 0f3ad2991e
commit c7b33930db
15 changed files with 1138 additions and 3077 deletions
+314 -17
View File
@@ -2,30 +2,327 @@
## Current
### `feat/agent-scoped-machine-auth`
### `feat/community-agent-key-cutover`
Status: in_progress
Goal:
- довести открытую редакцию до продуктово завершенного машинного доступа через ключ AI-агента.
Main code areas:
- `crates/crank-core/src/agent.rs`
- `crates/crank-core/src/auth.rs`
- `crates/crank-registry/src/postgres/agent.rs`
- `crates/crank-registry/src/postgres/api_key.rs`
- `apps/admin-api/src/service.rs`
- `apps/admin-api/src/app.rs`
- `apps/mcp-server/src/app.rs`
- `apps/ui/js/agents.js`
- `apps/ui/js/api-keys.js`
- `apps/ui/html/agents.html`
- `apps/ui/html/api-keys.html`
- `apps/ui/js/i18n.js`
Implementation slices:
1. Закрыть remaining workspace/platform-key assumptions в `admin-api` и `mcp-server`.
2. Нормализовать list/create/revoke/delete flow для agent keys.
3. Привести UI страницы `Agents` и `API Keys` к одной модели agent-scoped machine access.
4. Явно ограничить `Community` на `security_level = standard`.
Progress:
- done: `mcp-server` принимает ключ только по `(workspace_slug, agent_slug, secret_hash)`;
- done: `admin-api` уже отдает и принимает agent-scoped key routes;
- done: UI `API Keys` переведен на agent-scoped machine access;
- done: removed legacy workspace-key routes, demo/bootstrap assumptions, and per-agent key count bug.
DoD:
- ключ создается и принадлежит конкретному AI-агенту;
- UI объясняет назначение ключа без ссылок на старую workspace-key модель;
- `mcp-server` принимает Community machine access только по agent key;
- Community flow не требует short-lived token service.
Verification:
- backend unit and integration tests for key lifecycle;
- MCP tool-call tests through agent endpoint;
- e2e smoke for agent key create/reveal/revoke.
## Next
### `feat/edition-capability-model`
Status: ready
DoD:
- AI agent can receive its own long-lived agent key from the admin UI
- operation has an explicit security level: `standard`, `elevated`, or `strict`
- machine calls to MCP can use short-lived agent tokens for elevated operations
- one-time token mode is defined for strict operations
- transition path from workspace-wide keys is explicit in docs and implementation slices
Goal:
- ввести capability model по редакциям и перестать смешивать Community и premium surface.
## Next
Main code areas:
- `crates/crank-core/src/*`
- `apps/admin-api/src/service.rs`
- `apps/admin-api/src/app.rs`
- `apps/ui/js/*`
- `apps/ui/html/*`
- `docs/product-editions.md`
- `docs/frontend-roadmap.md`
Implementation slices:
1. Ввести серверную модель capabilities:
- protocols
- auth modes
- security levels
- workspace/user/agent limits
2. Отдавать capability flags в `admin-api`.
3. Привести UI к capability gating вместо скрытых продуктовых допущений.
4. Зафиксировать Community defaults в docs и runtime config.
DoD:
- UI знает, какие функции входят в текущую редакцию;
- Community не показывает рабочие controls для premium-only features;
- capability checks существуют не только в UI, но и на сервере.
Verification:
- API tests for capability payloads;
- frontend smoke for hidden/locked states;
- manual verification on Community build.
### `feat/private-token-service-seam`
Status: ready
Goal:
- подготовить public codebase к private реализации короткоживущих и одноразовых токенов.
Main code areas:
- `crates/crank-core/src/auth.rs`
- `crates/crank-core/src/agent.rs`
- `apps/admin-api/src/app.rs`
- `apps/admin-api/src/service.rs`
- `apps/mcp-server/src/app.rs`
- `docs/agent-auth-model.md`
- `docs/admin-api.md`
- `docs/mcp-interface.md`
Implementation slices:
1. Определить stable contracts для:
- `POST /mcp-auth/v1/token`
- `POST /mcp-auth/v1/token/one-time`
2. Ввести abstraction для token verification в `mcp-server`.
3. Подготовить capability-gated UI/API surface без private implementation в Community.
4. Отделить Community `standard` flow от commercial `elevated/strict`.
DoD:
- public contracts зафиксированы и тестируемы;
- Community продолжает работать без private token service;
- premium auth paths не размазываются по Community logic.
Verification:
- contract tests for auth payload shapes;
- unit tests for credential-kind enforcement;
- docs sync check.
### `feat/community-surface-trim`
Status: ready
Goal:
- привести открытую редакцию к честному product surface и убрать расхождение между текущим кодом и edition policy.
Main code areas:
- `apps/ui/js/wizard.js`
- `apps/ui/js/wizard-model.js`
- `apps/ui/js/agents.js`
- `apps/ui/js/settings.js`
- `apps/ui/js/i18n.js`
- `docs/product-editions.md`
- `docs/architecture.md`
- `docs/mcp-interface.md`
Implementation slices:
1. Скрыть или честно заблокировать:
- `WebSocket`
- `SOAP`
- `gRPC streaming`
- streaming execution modes
- `elevated/strict` security levels
в Community.
2. Привести copy и feature affordances к open-core границе.
3. Добавить edition-aware explanation в wizard и agents UI.
DoD:
- Community UX не создает ложного ожидания наличия premium functionality;
- protocol set и security levels совпадают в docs, UI и runtime contracts.
Verification:
- e2e checks for wizard protocol list;
- manual Community smoke;
- localized copy review.
## Planned
### `feat/frontend-commercial-polish`
Status: ready
Goal:
- закрыть оставшиеся UI/UX дефекты, мешающие коммерческой демонстрации и продажной версии продукта.
Main code areas:
- `apps/ui/js/api-keys.js`
- `apps/ui/js/agents.js`
- `apps/ui/js/secrets.js`
- `apps/ui/js/usage.js`
- `apps/ui/js/settings.js`
- `apps/ui/js/workspace-setup.js`
- `apps/ui/js/auth.js`
- `apps/ui/css/*`
- `docs/frontend-roadmap.md`
Implementation slices:
1. Перевести mobile tables в card layouts для:
- `API Keys`
- `Secrets`
- `Usage`
2. Доделать `Agents` page и modal:
- объяснение отдельных agent endpoints
- empty states
- slug hints
3. Добить `Settings` and workspace flows:
- terminology cleanup
- navigation spacing
- notifications honesty
- mobile sticky bug
4. Довести agent-key UX на `API Keys` page.
DoD:
- mobile UI не требует обязательного горизонтального скролла для primary actions;
- terminology и product copy согласованы;
- коммерческая демонстрация проходит без UI contradictions.
Verification:
- targeted Playwright coverage;
- manual mobile checks at 375px width;
- EN/RU copy audit.
### `feat/open-core-repo-boundary`
Status: ready
Goal:
- закрепить техническую границу между public Community repo и private commercial delivery.
Main code areas:
- `docs/commercial-boundaries.md`
- `docs/module-decomposition.md`
- `docs/development-rules.md`
- `docs/implementation-plan.md`
- release scripts / Docker manifests / future packaging files
Implementation slices:
1. Определить extension seams в public code.
2. Подготовить отдельные delivery manifests для Community.
3. Убрать из public repo assumptions о размещении private code рядом с Community logic.
4. Подготовить naming и packaging strategy для private repositories.
DoD:
- можно объяснить, что именно публикуется как OSS, а что уходит в private delivery;
- Community release path отделен от commercial release path;
- документация не ссылается на удаленные review files.
Verification:
- docs consistency pass;
- release checklist review.
### `feat/enterprise-access-governance`
Status: ready
Goal:
- реализовать enterprise access layer вне Community scope.
Main code areas:
- private `enterprise` services and crates
- public contracts in:
- `docs/admin-api.md`
- `docs/agent-auth-model.md`
- `docs/product-editions.md`
Implementation slices:
1. `SSO`
2. `2FA`
3. extended `RBAC`
4. `audit log`
5. enterprise admin flows in UI through capability gating
DoD:
- governance features не живут как полумеры в Community;
- enterprise access model согласован с public contracts.
### `feat/cloud-metering-control-plane`
Status: ready
Goal:
- подготовить hosted-редакцию как отдельный продуктовый контур.
Main code areas:
- private cloud services
- usage/metering integration points
- `docs/product-editions.md`
- `docs/commercial-boundaries.md`
Implementation slices:
1. usage metering by workspace / agent / token;
2. billing integration;
3. hosted tenant controls;
4. cloud operational tooling.
DoD:
- Cloud edition не зависит от ручного учета usage;
- hosted product surface согласован с feature matrix.
### `feat/release-protection-distribution`
Status: ready
Goal:
- подготовить безопасную поставку Community и коммерческих редакций.
Main code areas:
- CI workflows
- Dockerfiles
- deployment manifests
- release docs
Implementation slices:
1. public GitHub release flow for Community;
2. private registry flow for Enterprise;
3. signed artifacts and provenance;
4. release checklist for edition-specific packaging.
DoD:
- Community публикуется из public repo;
- Enterprise и Cloud используют private delivery path;
- коммерческий код не требуется публиковать в open source ради поставки.
### `feat/live-authenticated-staging-entry`
Status: ready
Goal:
- держать реальный staging/demo контур в состоянии, пригодном для демонстрации и регрессии.
Main code areas:
- `docs/demo-runbook.md`
- `docs/deploy-and-staging-smoke.md`
- `docs/authenticated-staging-pass.md`
- deployment workflows
Implementation slices:
1. актуализировать demo user flow;
2. прогнать authenticated staging pass;
3. зафиксировать regressions и manual checks;
4. синхронизировать deploy docs с реальным окружением.
DoD:
- authenticated staging flow runs against the real deployed environment
- operator docs match the current deploy/runtime model
- staging validation is captured without relying on local fixtures
## Completed
- `feat/websocket-test-run-polish`
- `feat/frontend-wizard-modularization`
- `feat/distributed-mcp-session-store`
- staging validation не зависит от локальных фикстур;
- documentation matches deployed behavior;
- demo flow reproducible on real environment.