// SPDX-License-Identifier: CC-BY-SA-4.0
Goal: Convert container-haters into container-users through game-like UX and built-in security
Product Test: A reasonably IT-capable 12-year-old can help their parents build a secure container stack without prior container knowledge.
Target 1.0 Release: Q3 2026
Honest completion: ~87%
| Component | Status | Notes |
|---|---|---|
| UI (9 views, 51 modules) | Working | All render, navigate, TEA pattern solid |
| Pipeline Designer | Working | 3-panel node-graph editor, SVG canvas, bezier connections, minimap, 6 templates |
| URL-based routing | Working | AppRouter.res syncs tabs with browser URLs |
| Undo/redo system | Working | Snapshot-based, 50-depth cap, Ctrl+Z/Ctrl+Y |
| Auto-save | Working | 30-second interval with dirty tracking |
| Dark mode | Working | System detection + localStorage persistence |
| Import/Export | Working | File picker, JSON + compose files, real container images |
| Security UX (4 views) | Working | Port config (1165 LOC), security inspector (832), gap analysis (951), simulation (1622) |
| Backend (Phoenix REST + GraphQL) | Working | CRUD + validation via NativeBridge |
| Zig FFI shared library | Working | Real CRUD + validate + dispatch, SHA-256 + Ed25519 |
| Idris2 ABI | Working | 8 genuine proofs (no believe_me) |
| VeriSimDB integration | Working | Remote client with JSONL local fallback |
| Auth (JWT) | Partial | Plug module present, no token refresh/revocation/login UI |
| Simulation mode | Working | Packet sim, build sim, what-if, supply chain, async sessions |
| WebSocket | Partial | Socket.res exists, no live channel logic |
| VeriSimDB as primary store | Not started | Client exists for audit; needs stack/user/settings CRUD |
| miniKanren engine | Not started | Design complete |
| Post-quantum crypto | Not started | Module scaffolded only |
Architectural Decision (2026-03-23): All Stapeln data uses VeriSimDB, not PostgreSQL. Port 8093, volume stapeln-verisimdb-data. PostgreSQL container stopped; Ecto layer to be removed.
- ReScript-TEA architecture (Model, Msg, Update, View)
- Three-page UI design (Paragon, Cisco, Settings)
- WCAG 2.3 AAA accessibility specifications
- GraphQL schema with a11y metadata
- VeriSimDB integration spec (6 modalities)
- A2ML integration spec (attested documentation)
- K9-SVC integration spec (self-validating configs)
- miniKanren security reasoning engine design
- OWASP ModSecurity + firewall configuration spec
- Ephemeral pinhole design (auto-expiring firewall rules)
- UX Manifesto ("If you have to read the manual, we failed")
- Security stack audit (identified 47% -> 100% path)
- 14 Architecture Decision Records (ADRs)
- PortConfigPanel.res (1165 lines) — visual port state toggles, ephemeral duration, countdown, risk indicators
- SecurityInspector.res (832 lines) — score display, vulnerability list, quick checks, CVE display
- GapAnalysis.res (951 lines) — gap detection, severity prioritization, auto-fix buttons, provenance
- SimulationMode.res (1622 lines) — packet animation, multiple types, node rendering, stats, event log
- PipelineDesigner — 3-panel node-graph editor with SVG canvas, bezier connections, minimap, context menus, drag-drop, 6 templates, code generation preview
- App.res integration — 9 navigation views fully functional
- URL-based routing (AppRouter.res) with back/forward navigation
- Undo/redo system (snapshot-based, 50-depth cap)
- Auto-save (30-second interval with dirty tracking)
- Dark mode (system detection + localStorage persistence)
- Conversational errors (UX Manifesto Rule 4 pattern)
- Import/Export with file picker and error suggestions
- Phoenix REST endpoints for stacks and validation
- GraphQL API (Absinthe) at
/api/graphql - Shared API boundary (REST/GraphQL route through NativeBridge)
- Zig FFI shared library (real CRUD + validate + dispatch)
- Idris2 ABI with 8 genuine proofs
- Real SHA-256 + Ed25519 in crypto.zig
- VeriSimDB remote client with JSONL fallback
- Runtime boundary established (design plane vs Svalinn/Vordr lifecycle)
- Network packet flow simulation (SimulationEngine) — deterministic dry-run
- Container build simulation (BuildSimulator) — layer sizes, times, security
- What-if analysis engine (WhatIfEngine) — compare pipeline variants side-by-side
- Supply chain analyzer (SupplyChainAnalyzer) — SLSA levels, provenance, trust boundaries
- Simulation server (SimulationServer) — async session management GenServer
- Simulation REST API — 8 endpoints (/simulations/build, what-if, suggest, supply-chain, sessions CRUD)
- NativeBridge integration — build_simulate, what_if, supply_chain_analyze
- Scenario suggestion engine — auto-detects improvement opportunities
- VeriSimDB audit logging for all simulation types
- JWT + Plug module present
- Token refresh and revocation
- Session management
- Login UI screen
- PAM integration
- Extend VeriSimDB client for stack CRUD
- Extend for user and settings CRUD
- Remove Ecto/PostgreSQL layer
- Migrate existing GenServer state to VeriSimDB
- Guile Scheme + miniKanren library setup
- 10+ security rules (SSH exposure, root user, unencrypted traffic, etc.)
- CVE feed sync (NIST NVD API)
- OWASP Top 10 rules
- CIS Benchmark rules
- OWASP ModSecurity CRS (Svalinn gateway)
- firewalld/nftables integration
- Ephemeral pinhole scripts
- Port conflict detection with auto-fix
- Frontend-backend API wiring (data model alignment)
- WebSocket live channel push/receive
- miniKanren-Elixir IPC (S-expression parsing)
- VeriSimDB end-to-end (all 6 modalities)
- Firewall-UI sync
- Container-Hater Test (3-tier app in <30 min, no docs)
- Accessibility testing (screen reader, keyboard-only, braille, contrast)
- Performance testing (100+ container stacks)
- Security penetration testing
- Dilithium5-AES (ML-DSA-87) alongside Ed25519
- Kyber-1024 (ML-KEM-1024) for TLS key exchange
- SPHINCS+ as fallback option
- Dilithium5 as primary signer
- HTTP/3 + QUIC migration
- SHAKE3-512 hashing
- Argon2id passwords (512 MiB, 8 iterations)
- XChaCha20-Poly1305 bundle encryption
- All phases complete
- 100% test coverage (critical paths)
- WCAG 2.3 AAA verified
- Security audit passed
- Container-hater test passed
- Documentation complete
- Tutorial videos published
- Multi-user collaboration
- Stack templates marketplace
- AI-powered optimization suggestions (explanations only)
- Cost estimation (cloud deployment)
- Advanced simulation (chaos engineering)
- RBAC (Role-Based Access Control)
- SSO integration
- Compliance reporting
- Custom rule engine
- CI/CD integration
- Kubernetes YAML generation
- Helm charts and Operators
- Service mesh integration (Istio, Linkerd)
- GitOps (FluxCD, ArgoCD)
| Risk | Impact | Mitigation |
|---|---|---|
| VeriSimDB migration complexity | High | Keep JSONL fallback, migrate incrementally |
| miniKanren performance | Medium | Profile and cache; deterministic is the point |
| Container-hater test fails | Critical | Iterate on UX until pass |
| PQ crypto complexity | High | Hybrid mode first |
| Data model alignment (frontend/backend) | Medium | Shared schema via Zig FFI types |
Last Updated: 2026-03-29 Status: Phase 2 complete, Phase 3 ~75% (backend core + simulation engine done, auth/VeriSimDB primary/miniKanren/firewall pending)