Files
git.stella-ops.org/docs/03_VISION.md

6.5 KiB
Raw Permalink Blame History

3 · ProductVision — StellaOps

(v1.3 — 12Jul2025 · supersedesv1.2; expanded with ecosystem integration, refined metrics, and alignment to emerging trends)


0Preamble

This Vision builds on the purpose and gap analysis defined in 01WHY.
It paints a threeyear “northstar” picture of success for the opensource project and sets the measurable guardrails that every roadmap item must serve, while fostering ecosystem growth and adaptability to trends like SBOM mandates, AIassisted security and transparent usage quotas.


1NorthStar Vision Statement (2027)

By mid2027, StellaOps is the fastest, mosttrusted selfhosted SBOM scanner. Developers expect vulnerability feedback in five seconds or less—even while the free tier enforces a transparent 333 scans/day limit with graceful waiting. The project thrives on a vibrant plugin marketplace, weekly community releases, transparent governance, and seamless integrations with major CI/CD ecosystems—while never breaking the fivesecond promise.


2Outcomes & Success Metrics

KPI (communitycentric) Baseline Jul2025 Target Q22026 NorthStar 2027
Gitea /GitHub stars 0 4000 10000
Weekly active Docker pulls 0 1500 4000
P95 SBOM scan time (alpine) 5s 5s 4s
Freetier scan satisfaction* n/a 90% 95%
Firsttimecontributor PRs /qtr 0 15 30

*Measured via anonymous telemetry optin only: ratio of successful scans to 429 QuotaExceeded errors.


3Strategic Pillars

  1. SpeedFirst preserve the sub5s P95 walltime; any feature that hurts it must ship behind a toggle or plugin. Quota throttling must apply a soft 5s delay first, so “speed first” remains true even at the limit.
  2. OfflinebyDesign every byte required to scan ships in public images; Internet access is optional.
  3. ModularForever capabilities land as hotload plugins; the monolith can split without rewrites.
  4. CommunityOwnership ADRs and governance decisions live in public; new maintainers elected by meritocracy.
  5. ZeroSurprise Upgrades & Limits SemVer discipline; main is always installable; minor upgrades never break CI YAML and freetier limits are clearly documented, with early UI warnings.
  6. Ecosystem Harmony Prioritise integrations with popular OSS tools (e.g., Trivy extensions, BuildKit hooks) to lower adoption barriers.

4Roadmap Themes (1824months)

Horizon Theme Example EPIC
Q32025 (3mo) Core Stability & UX Onecommand installer; darkmode UI; baseline SBOM scanning; Freetier Quota Service (333 scans/day, early banner, waitwall).
612mo Extensibility Scanservice microsplit PoC; community plugin marketplace beta.
1218mo Ecosystem Community plugin marketplace launch; integrations with Syft and Harbor.
1824mo Resilience & Scale Redis Cluster autosharding; AIassisted triage plugin framework.

*(Granular decomposition lives in 25_LEDGER.md.)


5Stakeholder Personas & Benefits

Persona Core Benefit
Solo OSS maintainer Laptop scans in 5s; zero cloud reliance.
CI Platform Engineer Singlebinary backend + Redis; stable YAML integrations.
Security Auditor AGPL code, traceable CVE sources, reproducible benchmarks.
Community Contributor Plugin hooks and goodfirst issues; meritbased maintainer path.
Budgetconscious Lead Clear 333 scans/day allowance before upgrades are required.

(See 01WHY §3 for detailed painpoints & evidence.)


6NonGoals (20252027)

  • Multitenant SaaS offering.
  • Automated “fix PR” generation.
  • Proprietary compliance certifications (left to downstream distros).
  • Windows container scanning (agents only).

7Review & Change Process

  • Cadence: product owner leads a public Vision review every 2 sprints (≈1quarter).
  • Amendments: material changes require PR labelled type:vision + two maintainer approvals.
  • Versioning: bump patch for typo, minor for KPI tweak, major if NorthStar statement shifts.
  • Community Feedback: Open GitHub Discussions for input; incorporate topvoted suggestions quarterly.

8·Change Log

Version Date Note (highlevel)
v1.4 14Jul2025 First public revision reflecting quarterly roadmap & KPI baseline.
v1.3 12Jul2025 Expanded ecosystem pillar, added metrics/integrations, refined non-goals, community persona/feedback.
v1.2 11Jul2025 Restructured to link with WHY; merged principles into StrategicPillars; added review §7
v1.1 11Jul2025 Original OSSonly vision
v1.0 09Jul2025 First public draft

(End of ProductVision v1.3)