Roadmap & next steps¶
This page lists work for the next AryaOS contributor. Items appear in priority order within each group. Update this living document as items land. See Agent handoff for the build/merge state and architecture invariants.
Context
A large July 2026 sweep shipped the multi-domain COP model and Cockpit
administration cards. It also shipped gdlcot, the shared Cockpit library,
SBOMs, storage tuning, lifecycle tools, and offline documentation. The items below are
what remains.
Start here - hardware burn-in¶
Several shipped features are verified only by shellcheck, ansible
--syntax-check, mkdocs --strict, and verify-image.sh static asserts. They
have not been exercised on real hardware. Flash the latest dev image and
run through them before relying on any of it in the field.
- Destructive lifecycle paths. On a throwaway box: a
backup > restore round-trip, then
aryaos-factory-reset, thenaryaos-zeroize(confirm it reboots clean and the box stays usable). Watch The free-space overwrite duration. See Factory reset and Zeroize. - The Cockpit cards. Exercise all AryaOS Site cards on hardware: support bundle, Node-RED password, Radios (RTL-SDR re-serial), device role, hotspot password, Tailscale join, backup/restore, factory reset, zeroize.
- Expired-password first-login flow. Confirm the Cockpit login handles
The first-boot
chage -d 0 piexpiry cleanly - this is the prerequisite for The first-login wizard below. - Media longevity. Confirm zram swap activates (
swapon --showshows a/dev/zram0),fstrim.timeris enabled, and logs are in RAM as expected. - Offline docs. Confirm
https://<host>/docs/serves and the portal QR resolves. - Fold the above into
scripts/aryaos-test/tests/09-security.sh(and a new10-lifecycle.sh) so future images regression-test them.
Security follow-ups¶
- Stronger zeroize guarantees. The shipped
aryaos-zeroizeis best-effort by design (see Zeroize) - on wear-leveled flash, overwrite/TRIM cannot guarantee erasure. Two stronger options were deferred:- Opt-in full-disk encryption (LUKS) > true crypto-erase. The only hard guarantee on flash. Requires boot/initramfs work and a key-management story. makes zeroize an instant key-destroy.
- Scorched-earth zeroize mode. A second mode that also wipes the rootfs/boot so a captured box reveals nothing and will not boot (requires reflash to reuse).
- Dependabot backlog. ~19 bot PRs across
aryaos,cockpit-aiscot, andcockpit-lincot(dependency bumps, some majors - TypeScript, PatternFly, A Cockpit-lib refresh). Triage: merge safe patch/minor bumps, review majors.
Platform & features¶
- amd64 support (#129).
The pipeline is arm64-only pi-gen. Recommended first step: an
install-aryaos.shfor any Debian 13 host - the signed apt repo + overlay deb already carry almost everything. Then a debos/bdebstrap amd64 image and A VM appliance. - First-login setup wizard. A guided first-login flow (change password > set callsign > import TAK data package / set COT_URL > pick device role). All the pieces exist. Blocked on the expired-password verification above.
- Unified COP map on the portal.
tar1090shows only ADS-B. A portal map fusing ADS-B + AIS + drones + own position + Mesh SA neighbors (/run/aryaos/neighbors.jsonalready exists) can make a device a self-contained COP for a browser-only user. - Track record & replay (#8, #9). Cleanest design: a COTBridge recorder lane (it already sees all local CoT) writing rotating logs, with a portal page to download and replay - directly useful for wildland-fire after-action review.
- SDR gain / PPM tuning UI. The Radios card enumerates and re-serials dongles. Gain and PPM are still file-only. Add them to the card.
-
cockpit-gdlcotpage and a live ForeFlight/EFB validation for the new GDL90 gateway. - CoT over BLE (#7) - blocked On BLE advertising being broken image-wide on the trixie kernel / BCM4345C0 (#117).
Documentation¶
- PyTAK / API reference via
mkdocstringsfor the gateway internals. - Per-gateway deep-dive pages and a recipes/cookbook section.
- Versioned docs (
mike) once releases are cut from the docs. - Polish: AryaOS branding CSS, social preview cards, rendered screenshots.
Housekeeping¶
- Close resolved issues. #21 (SDR web UI - done via the Radios card), #51 (SBOM - done), and the image half of #43 (ForeFlight/gdlcot) are shipped and can be closed.
- Current bugs. #93 (ADSBCOT Cockpit tab wrong header - quick fix) and #94 (AIS-catcher serial port).
-
python-networkmanager>python-sdbus-networkmanager(#54) - live tech debt instage-aryaos. - Chroot vs Ansible stage drift. Each stage exists twice (pi-gen
00-run.sh+ Ansibletasks/) and can diverge. Add a CI job that provisions a rootfs via Ansible and diffs it against the chroot result.