Docs · Status
Current limitations
WP-A01-WP-A18 establish a locally tested Linux development candidate. They do not authorize a public production-readiness claim. The Verification and hardening page records exactly what has been exercised.
LocalPassed
Normal, race, vet, build and recovery gates.
ScaleBounded
500-post query proof, not full browser dogfood.
ExternalRequired
Security and assistive-technology review.
ReleaseNot yet
No production support claim or public tag.
- Watchpost Agent supports Linux amd64/arm64 runtime; macOS and Windows monitoring are not supported.
- HTTP, TCP, TLS, DNS and ICMP are durably scheduled. SNMPv3 authPriv polling is also durable and read-only; polling credentials are stored encrypted at rest under an installation master key supplied outside the database, and metadata-only profiles remain usable without a key.
- SNMP is read-only. Cameras, arbitrary consumer IoT, PLC writes, and building-control commands remain future research. PLC writes and building-control commands must never be presented as safety control.
- The built-in investigation provider does not infer causality; production model-provider configuration and evaluation remain unfinished.
- Fleet federation lacks sustained two-node partition and reconciliation evidence.
- Online backups are verified with
watchpost backup/watchpost restoreand can be scheduled withWATCHPOST_BACKUP_DIR/WATCHPOST_BACKUP_SCHEDULE; remote and retention-managed backup automation is not implemented. - The 500-post test proves a server query bound, not production browser hierarchy. A bounded retention-enabled soak proves flat database growth under continuous ingestion, but no multi-day soak, external security assessment, screen-reader audit, or assistive-technology audit has been completed.
- Ordinary-user dogfooding, dense multi-post survey, real-network remote agent administration, and production TLS, proxy, and operational-security validation are proposed checkpoints, not completed work.
Authority boundary
Watchpost is not a safety system, SCADA/HMI, or autonomous remediation engine. Missing evidence is never healthy evidence, and model output is never authorization.