# Roadmap Where demarkus has been and where it's going. ## Phase 1: MVP (Read-Only) — COMPLETE Everything shipped: - QUIC server serving markdown files - FETCH, LIST, VERSIONS verbs - TUI client with Bubble Tea + Glamour - Link following, navigation history - Document graph visualization - CLI client with all verbs - MCP integration for LLM agent access - Docker multi-arch images - GoReleaser CI/CD with per-module versioning - Conditional fetch (if-none-match, if-modified-since) - SIGHUP certificate reload ## Phase 2: Publish Operations — COMPLETE Done: - PUBLISH verb with version creation - ARCHIVE verb - APPEND verb — sends only new content, server handles concatenation - Capability-based auth (token generation, SHA-256 hashes, path/op scoping) - Versioned store with symlinks and hash chain - Document editing via $EDITOR - Client-side token management - Conflict resolution (optimistic concurrency with expected-version) - No-op on duplicate content - Structured logging with slog (replaced console logging) - Protocol-level size limits (1 MiB body, 64KB frontmatter) - Audit logging with token_label on all write operations - Usability audit: documentation accuracy, CLI help, install script cleanup, CI lint Phase 2 is fully complete. No remaining items. ## Phase 3: Agent-Native & Advanced Features — COMPLETE Done: - Agent manifest discovery (`/.well-known/agent-manifest.md`) - Bookmarks/favorites - MCP `mark_append` auto-resolve `expected_version` - Content-addressed fetch - Federation via MCP tools ## Phase 4: The Information Graph — COMPLETE Done: - The Demarkus Hub pattern - Persistent graph store - Backlinks - Graph as content (export/import) - Graph-aware navigation (TUI) - Agent discovery ## Phase 5: The Demarkus Agent & Private Networks — IN PROGRESS ### Read Auth for Private Networks — DONE Per-path read token enforcement. Server-side and client-side shipped. ### Security Hardening — DONE See [plan](/plans/security-hardening.md) for full details. - **Systemd hardening** — install script generates units with ProtectSystem=strict, ReadWritePaths, NoNewPrivileges, etc. Conditional ProtectHome. Update path detects insecure config and prompts to harden with rollback. - **`-read-only` mode** — `DEMARKUS_READ_ONLY` env var / `-read-only` flag. Handler rejects PUBLISH/APPEND/ARCHIVE with `not-permitted`. Zero write access needed. - **`demarkus-publish`** — CLI tool that writes directly to the versioned store on disk. Enables local publishing when server runs read-only. Shares `store.Write()` with the server. - **Read-only chroot install** — `install-readonly.sh`. Chrooted server with ReadOnlyPaths=/, BindReadOnlyPaths=/dev/urandom. Maximum lockdown — Gemini-level security with full versioning. - **Security documentation** — attack surface analysis, threat model, comparison table, hardening guide. ### Core Loop: Crawl & Index 1. **Seed** — start from configured servers (hub, known peers) 2. **Crawl** — follow `mark://` links, discover new servers and documents 3. **Hash** — collect content hashes from every document 4. **Index** — publish updated hash indexes to configured hubs 5. **Repeat** — on a configurable schedule, with conditional fetch (if-none-match) to be polite ### Server-to-Server Sync Rsync for the Mark Protocol. Replicate content between servers using content hashes as the diff mechanism. **How it works:** 1. **LIST** both source and destination servers 2. **Compare** content hashes — skip documents that match 3. **FETCH** changed/new documents from source 4. **PUBLISH** to destination with the fetched content 5. Optionally handle deletions (ARCHIVE on destination for docs removed from source) **Sync modes:** - **Mirror** — destination becomes an exact copy of source (one-way) - **Selective** — sync specific paths or glob patterns (e.g., `/docs/*` only) - **Multi-source** — aggregate content from multiple servers into one destination ### Key Design Points - **Go binary, not an LLM agent** — mechanical work, not reasoning - **Polite crawling** — conditional fetch, configurable rate limits - **Hub-aware** — reads and updates hub index documents - **Daemon or cron** — continuous or triggered - **Auth-aware** — passes read and write tokens for private servers ### Implementation Sketch - New module: `cmd/demarkus-agent` (or standalone repo) - Reuses: `fetch.Client`, `graphstore`, `client/internal/index`, `graph.Crawl` - CLI: `demarkus-agent crawl`, `demarkus-agent sync source dest`, `demarkus-agent daemon` ## Verb Set — Complete 6 verbs: FETCH, LIST, VERSIONS, PUBLISH, APPEND, ARCHIVE. ## Distribution & Package Management — PLANNED Homebrew tap for easier installation on macOS and Linux. ## Build Targets Supported platforms: macOS, Linux, Windows (WSL only). ## Plugins — IN PROGRESS ### Obsidian Plugin — v0.1.0 RELEASED Standalone repo: `latebit-io/obsidian-demarkus`. Source in `plugins/obsidian/`. ## TUI Polish — PLANNED ### External Links (Phase 1) — PLANNED See [plan](/plans/external-links.md). Open http/https/gemini/mailto links in the user's default handler via `open`/`xdg-open`/`rundll32`. Scheme allowlist, URL passed as argv only, no shell. Closes part of [issue #75](https://github.com/latebit-io/demarkus/issues/75). Phase 2 (same-server non-markdown files like images) deferred — needs content-type frontmatter and tempfile plumbing. ## Features Not Prioritized — Backlog - WebSub-style Subscriptions (removed from spec) - Offline Mode (deferred) - Full-Text Search (removed from spec, external tool) - Diff / Changelog Between Versions (noted, not implemented) - Blind Append with Content Deduplication (rejected)