# Sprints & roadmap ## Sprint map (sequenced; Sprint M slots after Sprint 4 per v1.1 §52-A) | Sprint | Goal | Epics | |---|---|---| | Sprint 0 | Architecture runway | E00, E01 | | Sprint 1 | First end-to-end publishing slice | E02, E03, E04, E05, E06, E07 | | Sprint 2 | Editable Home and site structure | E08, E09, E10 | | Sprint 3 | Extension runtime hardening | E11, E12, E13, E14 | | Sprint 4 | Theme platform proof | E15, E16 | | Sprint M | Media and rich content (v1.1) | E29, E30, E31 | | Sprint 5 | Visitor personalisation (deferred) | E17, E18 | | Sprint 6 | Installation, backup and upgrades | E19, E20, E21, E22 | | Sprint 7 | V1 hardening | E23, E24, E25, E26 | Story count is exactly **96**: Sprint 0 (6) · Sprint 1 (17) · Sprint 2 (12) · Sprint 3 (13) · Sprint 4 (6) · Sprint M (11) · Sprint 5 (7) · Sprint 6 (13) · Sprint 7 (11). ## Sprint goals - **Sprint 0:** a new engineer can clone, build, test and run EPPP; architectural boundaries are executable. - **Sprint 1:** an authenticated owner can create/publish a simple article and an anonymous visitor can read it in Amber. - **Sprint 2:** the owner controls visible identity, Home composition and navigation without source edits. - **Sprint 3:** a new non-core capability can be added without feature-specific core changes. - **Sprint 4:** prove Amber is one implementation of a stable theme contract. - **Sprint M:** an article with image/video/embed/native chart publishes with zero core hydration and no third-party request before interaction. - **Sprint 5:** (deferred until a second production theme exists) owner may expose multiple themes; anonymous visitors persist an explicit choice without becoming tracked identities. - **Sprint 6:** EPPP is easy to recover and upgrade, not merely easy to demo. - **Sprint 7:** security, accessibility, failure handling and performance are trusted for long-lived deployment and extension development. ## Resequenced implementation order (§72-A) 1–23 as v1.0 (workspace → Docker → PostgreSQL adapter → config → migration runner → Fastify shell → manifest loader → registries → site model → content/revisions → Blog → block registry → theme registry → Amber → React server renderer → auth → admin shell → post editor → Home composition → navigation → generic settings → extension lifecycle → second test theme). Then: 24 media pipeline (E29) → 25 hardened fetch/embeds (E30) → 26 charts/diagrams (E31) → 27 metadata/sitemap (34-A) → 28 operational hardening → 29 visitor preferences (deferred) → 30 Reading. ## Roadmap summary (§73) ``` Sprint 0 Architecture + Docker + DB + CI Sprint 1 Publish a real post in Amber Sprint 2 Editable Home/site/navigation Sprint 3 Extension API/lifecycle proof Sprint 4 Theme platform + second test theme Sprint M Media + embeds + charts (v1.1) Sprint 5 Visitor preferences/theme choice Sprint 6 Setup/backup/export/upgrade Sprint 7 Security/accessibility/performance hardening v0.2 Second production theme + RSS + lightweight features v0.3 Reading extension as full architecture proof ``` ## v0.1 release boundary (§54) **Included:** Docker Compose, PostgreSQL 18, admin auth, site identity editing, Home, posts, draft/publish, revision foundation, Amber theme, content-type/block/theme registries, extension manifest/registry baseline, page section registry, editable Home, editable navigation, responsive/a11y baseline, backup docs, health/readiness. **Excluded:** Reading, link-health, RSS, public theme selector (while only Amber ships), plugin marketplace, arbitrary runtime package upload, multi-site SaaS, multi-admin RBAC, collaborative editing, Redis, Elasticsearch, Kubernetes requirement, microservices. ## v0.2 / v0.3 (§55/§56) v0.2 (personalisation + lightweight extensions): second production theme (Ledger/Paper), visitor theme choice + preference persistence, RSS extension, Running/Now Home extension, static page content type, media improvements. v0.3: Reading (`org.eppp.reading`) owning bookmarks, imports, seam/half-life taxonomy, search/filter/grouping, link health, background link checker, archive fallback, admin, public route, Home contribution, settings, migrations — installable, configurable, disableable, upgradeable through public contracts. ## Decisions deliberately deferred (§69) rich-text editor; drag/reorder UI library; CI vendor; dependency update bot; SBOM/security scanner; metrics exporter; object-store provider; multi-admin RBAC; multi-site tenancy; external search engine; public extension marketplace. ## Risk register (§67, summary) Fastify v5 EOL unknown (M) · TS7 transition (M) · Kysely pre-1.0 (M) · arbitrary plugin code owns process (Critical if allowed) · theme overrides fragment semantics (M) · extension migrations corrupt data (H) · preference ID becomes tracking ID (M) · page builder scope explosion (H) · React public JS bloat (M) · dual DB complexity (M/H) · background infra proliferation (M) · Extension API freezes too early (M) · (v1.1) programme outlives builder attention before motivating features ship (H) · (v1.1) embed surface unspecified despite founding requirement (H) · (v1.1) dependency pins go stale (M).