Lumic Control Center
Lumic 1.0

Feature matrix

What Lumic 1.0 implements and what remains deliberate expansion work.

AreaImplemented in 1.0Planned expansion / not implemented
Hostsx86_64 Debian 12/13, Ubuntu 22.04/24.04; clean-image install smokeaarch64 artifacts, other distributions
Install/updatestable/nightly channels; checksum-verified atomic install and self-update; backup and postflight restoreautomated external real-VPS lifecycle gate
Host operationstyped apt/systemd, accounts, UFW, filesystems, processes, timers, updates, logs, backups, remediationbroad provider/remediation catalog; generic shell is intentionally absent
Applicationsversioned strict lumic.toml schema v2 using shared catalog capabilities, typed configuration/resources, runtime extensions, processes, schedules, shared release paths, source/public paths, argv-only build/migrate hooks, health and deployment intent; legacy lumic.yaml schema v1 migration reads; application-scoped authenticated-encrypted environment values with masked MCP inspection, key-only diff, controlled set/rotate/delete and deployment-time injection; native Git push dispatch gated by the contract; immutable releases, deploy locks/cancellation, pinned retry/redeploy, commit metadata/log cursors, health-gated rollback, blue/green Node nginx handoff and drain, resource-bound Certbot/Let’s Encrypt TLSgeneric certificate mutation controls in every adapter, third-party PHP and Node repositories
Managed servicescatalog-driven CLI/UI/MCP discovery, schemas, install/lifecycle, inspection and bindings; MySQL, PostgreSQL and Redis data operations; Typesense and Meilisearch credential bindings; native drivers for Valkey, RabbitMQ, MinIO, OpenSearch, Memcached, MongoDB, ClickHouse, Prometheus, Grafana, and Loki; pinned verified Gitea and Gogs drivers; independently owned nginx singletonbackup/restore and provider child resources for newer drivers; broader live-host coverage
Recipescatalog-driven CLI/UI/MCP install, update and uninstall; versioned compiled static Git and checksum-pinned WordPress lifecycles; Laravel, Laravel + Typesense, Drupal, Symfony, Ghost and Matomo repository recipes; Forgejo catalog compositionexecutable Forgejo application driver; remote signed distribution
Infrastructurenamespaced group-shared managed bare Git repositories, external discovery/registration/adoption, explicit HTTPS/SSH remotes and credential references, fetch/push, authenticated Smart HTTP, Gitea/Gogs installers sharing the configured repository root, portable environment references, two-node identity/trust, signed deploy/rollback envelopes and restricted-SSH MCP accessfine-grained repository identities/grants; Forgejo managed driver and automatic forge metadata reconciliation; central fleet UI
Operationscorrelated timeline, signed webhooks, bounded retry, one typed restart rule, backup verificationnotification destinations, richer collectors and deterministic rules
IntelligenceLaravel fingerprint/config/dependency graph, laravel-redis@1, redacted incident context and advisory analysisother framework/service definitions and evidence providers
Attentioncanonical factual report and operations dashboard, six deterministic personalities, CLI/UI/MCP, application/service/deployment and CPU/RAM/disk facts, failed-service/security-update signals, certificate-expiry evidence, 24-hour backup-age policy, and recent incidents/eventsconfigurable certificate/backup thresholds, optional language renderer
UIauthenticated loopback Rust UI and confirmed safe actionspersistent/fine-grained identities, remote authentication, mobile polish
Software catalogUI/MCP status, plan and setup for the managed-service packages plus WordPress hosting prerequisites, PHP, nginx, Apache, Node.js and per-user NVM; full WordPress deployment through the separate recipe surfaceautomatic third-party repository enrollment
MCPinstalled lumic mcp serve stdio, restricted-SSH onboarding, optional bearer-authenticated loopback Streamable HTTP, process scopes and per-call approvalOAuth, per-identity grants and automated TLS proxy setup

Mechanism tests run in the workspace suite. Installation runs on every supported clean container image; MySQL/PostgreSQL/Redis, Laravel/Redis, and the idempotent WordPress lifecycle use live Ubuntu CI jobs. The source-tree acceptance scripts cover Epics A–G. A container image is not presented as a complete systemd VPS lifecycle: that external-host gate remains tracked nightly work.