<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Roadmap: what's deferred and why]]></title><description><![CDATA[<p dir="auto">What's deferred and why. wpfy is beta software — some features are intentionally out of v1 and tracked here so the community knows what's coming and can weigh in.</p>
<p dir="auto">Post feature requests in this category. Search first to avoid duplicates; upvote existing requests instead of reposting.</p>
<h2>Currently deferred (tracked in the project's open questions)</h2>
<p dir="auto">These are documented in the repo's memory and decision log. They are <strong>not</strong> bugs — they are explicit deferrals pending validation or an architecture decision.</p>
<h3>Disposable-VPS validation</h3>
<p dir="auto">The validation harness exists (<code>scripts/vps-release-validation*.sh</code>) but the final disposable-VPS release run is pending. Until it completes, treat wpfy as beta for production.</p>
<h3>Traefik Docker socket risk reduction</h3>
<p dir="auto">Traefik reads the Docker socket for container discovery. A socket-proxy adoption decision is open. See <a href="https://github.com/wpfyorg/wpfy/blob/main/docs/SECURITY.md" rel="nofollow ugc">Security</a>.</p>
<h3>Supply-chain verification depth</h3>
<p dir="auto">How deeply upstream WordPress / WP-CLI artifacts are verified before provisioning is an open question. Currently pull-only.</p>
<h3>Non-root / read-only filesystem compatibility</h3>
<p dir="auto">PHP-FPM images currently run as root (<code>USER www-data</code> deferred — needs a volume-ownership strategy). Explicit non-root and read-only-filesystem compatibility is pending.</p>
<h3>External scanner runs</h3>
<p dir="auto"><a href="http://testssl.sh" rel="nofollow ugc">testssl.sh</a> and nuclei have not been run against a live wpfy host. Hardening probes (Nginx, security headers, ACME, reboot persistence) passed on the last validation VPS.</p>
<h2>How to request a feature</h2>
<ol>
<li><strong>Search</strong> this category first.</li>
<li>If no match, <strong>start a new topic</strong> with:
<ul>
<li>The problem you're trying to solve (not just the solution)</li>
<li>The <code>wpfy</code> command or workflow you wish existed</li>
<li>Whether you'd be willing to test a PR</li>
</ul>
</li>
<li>Upvote requests you want with a reply or reaction.</li>
</ol>
<h2>What belongs here vs. elsewhere</h2>
<ul>
<li><strong>Bug</strong> (something broken) → <a href="/category/10">Operations &amp; Troubleshooting</a>, with <code>wpfy debug</code> output.</li>
<li><strong>How do I…</strong> → the relevant category (Site Management, Stack, etc.).</li>
<li><strong>I wish wpfy could…</strong> → here.</li>
</ul>
<p dir="auto">The maintainer triages requests against the roadmap and the decision log. Not every request becomes v1.</p>
]]></description><link>https://forum.wpfy.org/topic/9/roadmap-what-s-deferred-and-why</link><generator>RSS for Node</generator><lastBuildDate>Fri, 21 Aug 2026 16:50:24 GMT</lastBuildDate><atom:link href="https://forum.wpfy.org/topic/9.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 25 Jun 2026 02:46:07 GMT</pubDate><ttl>60</ttl></channel></rss>