Items moved out of TODO.md — useful polish, advanced ops, or longer-horizon bets that are not central to the indie-hacker mission of shipping real apps from a laptop to your own infra. Revisit when the P0 roadmap is done or a specific need surfaces.
- Env-specific scaling override file — override file for env-specific (
--env) scaling without duplicating the whole TOML. - Auto-add node on scale-up — parity with deploy’s auto-provision when
launch-pad scalepushes past current capacity (deploy auto-add already covers most cases).
- Auto-evacuate on destroy — inline auto-evacuate when
node destroywould orphan services (today: refuse +--force, or runnode evacuatefirst). - Cross-project evacuate-all — evacuate every project’s cluster-placed services off a node in one shot.
- Edge-routing drain for web services — evacuate/rebalance follow-up for edge-fronted web traffic during node drain.
- Whole-footprint rollback — roll back every service in a footprint to a prior deploy event (per-service
rollback+ deploy history already ship). - Canary / blue-green — beyond single-service rolling surge.
- External uptime check — synthetic HTTPS probe independent of the node (or integrated Route53 health check).
alerts checkon a schedule covers much of this today. - Continuous monitoring — always-on alerting (not just on-demand
alerts check). - Cert renewal failure alerts — detect Let's Encrypt / Caddy cert issuance or renewal failures.
- Node drift signals — alert when live node state diverges from desired (beyond heartbeat staleness).
- EBS volume attach — cross-node-failure durability for persistent data (named docker volumes survive container replace on the same node today).
- Cross-account clusters —
cluster create --role-arnis saved locally but explicitly “Phase 2 / not activated”. - Edge hardening options — rate limits, basic WAF (or deeper CDN/proxy integration), IP allowlists — none in product surface (many indies already front with a CDN/proxy).
- Live/hosted cost dashboard — on-demand CLI estimate ships; a hosted view is still future.
- Native AWS Budgets integration — CLI
--budgetgate ships; AWS Budgets wiring is still future.
- Multi-region — single project spanning regions (or documented “one cluster = one region” with failover story).
- Custom domains at scale — wildcard certs, apex + www, multiple domains per service without hand-editing Caddy.
- Static assets / CDN — S3+CloudFront or “static service” type for SPAs without a container (often solved with a CDN or a tiny nginx sidecar).
- Control-plane API — remote deploy triggers, team RBAC, audit (deliberately out of scope — declarative S3 contract, no vendor server).
- Init follow-ups — framework-specific health-check path scaffolding + a multi-service monorepo template (
initdetection already ships). - Doctor IAM probes — per-permission IAM dry-runs (EIP/IAM/SSM) and quota checks beyond today's pass/warn/fail checks.
- Stale
launchpad.yamlreference shapes —docs/overview.mdstill shows a single-service YAML example; real schema islaunch-pad.tomlinshared/src/config.ts(flagged in CLAUDE.md).