Fourteen areas are complete, most recently change streams, verifiable tables, and legibility. Transport security with hybrid post-quantum key exchange on every connection is up next, and eleven further planned areas take Zyron from a replicated cluster to a sharded platform with its own apps, dashboards, and drivers. Everything ships in order, gated by hard performance budgets.
Roadmap
A replicated, upgradable, verifiable cluster today, transport security next
Each area ships with a validation checkpoint and hard performance budgets before the next begins. Fourteen are complete, with the five that built the single-node engine shown as one milestone here, and transport security with hybrid post-quantum key exchange on every connection is next.
Single-node engine
Complete
Storage, security, data operations, search, analytics, and lifecycle. Feature-complete, with hard performance budgets at every checkpoint.
ZyronLake table format
Complete
Immutable versioned .zyr on an append-only transaction log with branches, time travel, secondary indexes, clustering, constraint enforcement, change feed, and cross-format federation.
Consensus and replication
Complete
Raft groups per cluster, quorum-committed writes at one fsync per ack, every statement in the grammar replicated and proven on a live three-node group, linearizable follower reads through ReadIndex, learner promotion, whole-cluster snapshots, and cluster settings on the consensus log behind a version gate.
SQL surface, type system and media types
Complete
Range and multirange types, interval refinements, native media types, additional function coverage, and a silent-bug hardening pass across the engine.
Format agility and auto-upgrade
Complete
A versioned envelope on every persistent file, signature agility for JWTs, X.509 certificates, and custom artifacts, a catalog schema evolution registry, an AST-based user-object rewriter, and a deprecation lifecycle. Rolling upgrades over Raft are health-baselined with automatic rollback, federation-aware compat gating, journaled self-restart, and signed per-target releases.
Online heap DDL
Complete
A schema epoch in the tuple slot so a column change writes no row, publish-wait-scan-flip index builds, and an online shadow rewrite for an incompatible type change.
SQL surface completions
Complete
UNNEST, FLATTEN, UNPIVOT, PIVOT, ASOF JOIN, node-local temporary tables, schema-qualified names on every statement form, and a SQL reference generated from the grammar registry.
Change streams
Complete
CREATE CHANGE STREAM with the consumed position advanced in the consumer's own transaction, APPLY CHANGES as SCD type 1 or 2, pipelines triggered ON CHANGE DATA, per-branch feeds, lake tables as derived sources, and the feed written at the raft index on a group.
Verifiable tables
Complete
One SHA-256 chain entry per committing transaction over a table's stored bytes, linked at apply on every consensus member. VERIFY TABLE in full or sampled mode with a genesis set behind a transaction fence, anchored chain heads exportable outside the cluster, and the compliance log as a verified table on the same chain.
Legibility
Complete
One walk of the grammar writes both the reference pages and a dataset embedded in the binary. HELP in every form with docs_search over statements, functions, clauses and prose, VALIDATE for a statement without running it, a stable error code on every error across every transport, expected-token sets in parse errors naming the statement and where to read more, examples rewritten against the caller's schema, and plain-language recipes over the function registry.
Transport security and post-quantum cryptography
Up next
Hybrid X25519MLKEM768 key exchange required between Zyron components and offered first to third parties, 256-bit suites only with TLS 1.2 removed, a node listener with mutual TLS to a cluster CA the operator holds, and ML-DSA-65, SLH-DSA-SHA2-128s, and hybrid Ed25519+ML-DSA-65 signature schemes active per artifact kind. Release manifests are signed hybrid, and a key-exchange exposure report names every outbound connection that negotiated classical.
Memory governance
Planned
One accounted pool across the node, class floors, grants instead of caps, and spill on denial.
Sharding
Planned
A sharding core on heap tables with top-bit hash placement so a split is local, distributed query execution, cross-shard transactions with prepare in each participant's own Raft log, and split and rebalance.
Enterprise and distribution
Planned
Secret store and KMS with HYOK adapters, high availability and DR, observability and compliance, semantic views, schema registry, data contracts, data governance, multi-tenancy and cost tracking, migration tools and ecosystem connectors, external tables, Volumes, and enterprise type-system extensions.
Serverless mesh and autonomous operations
Planned
A base compute mesh, user meshes with compute reservations, workload-aware scheduling, continuous self-tuning and self-healing across every node in the mesh, query engine advances, and model monitoring.
Wire protocols, API and drivers
Planned
The ZWP native wire protocol alongside PostgreSQL wire compatibility, the Zyron API as a route registry that drives the router, OpenAPI, and generated reference docs with SQL at /api/sql, native drivers across every supported client language, and Zyron Embedded (libzyron) for in-process use.
Application and workflow hosting
Planned
Zyron Apps for container hosting on the mesh substrate, Workflows for task orchestration subsuming pipelines and schedules, Queues and Topics as heap tables through Raft with transactional enqueue, deployment artifacts, and SQL function library expansion.
Dashboards, workspace, and metrics
Planned
Zyron Dashboards with live query overlays and formatting with data, branch-native and time-travel-aware, Zyron Workspace with editors, language runtimes for Python, JS/TS, Java/Scala, Go, and Rust, data and discovery, ops and integrations, and a Zyron-native metric store.
Forms, Sheets, and Monitors
Planned
Forms as catalog objects whose controls derive from the target's columns, Sheets as a .zysheet workspace file that stores query, formulas, and typed cells but never rows, an EXPORT privilege enforced by an authorization token, and Monitors that read metadata only and learn their bands.
Enterprise identity, organization, cross-cluster and Git
Planned
Enterprise auth with OIDC, SAML, TOTP, WebAuthn, universal PATs, and tenant security policies, an organization directory with grantable units alongside groups, cross-cluster federation with mutual TLS and primary, secondary, and peer roles, and a shared Git backend registry per workspace with item versioning.
AI Gateway, AI-native assist, and AI-derived columns
Planned
A BYO-credentials gateway with prompt versioning and branching, semantic caching, continuous evaluation and cost tracking, opt-in per-workspace SQL, chart, and notebook assist that routes through the gateway, and columns whose values a model derives through the same gateway.
Zyron Web
Planned
A React, Vite, and Tailwind webapp shipping as a first-party static Zyron App, with path-based URLs and admin surfaces for every backend area above.
The full roadmap with scope details lives in the README.
Recently shipped
Five areas closed out since the upgrade orchestrator landed, and each one changed what a running deployment can do without stopping.
Complete
Online heap DDL
A schema epoch in the tuple slot lets a column change write no row, index builds publish, wait for in-flight writers, scan, and flip without blocking the table, and an incompatible type change runs as a shadow rewrite behind live traffic.
UNNEST, FLATTEN, UNPIVOT, PIVOT, ASOF JOIN, node-local temporary tables, schema-qualified names on every statement form, and a SQL reference generated from the grammar registry.
Every table carries a change log that a consumer reads and advances inside its own transaction, APPLY CHANGES lands it as SCD type 1 or 2, and on a group the feed is written at the raft index.
One SHA-256 chain entry per committing transaction, linked at apply on every consensus member, VERIFY TABLE in full or sampled mode, and anchored chain heads exportable outside the cluster.
One walk of the grammar writes both the reference pages and a dataset embedded in the binary, HELP and VALIDATE in every form, a stable error code on every error, and parse errors that name the statement and where to read more.
Each area ships with an optimization review and a validation checkpoint with hard performance budgets before the next begins. The budgets show up as the benchmark numbers on the performance page.
Optimization review
Every area closes with a dedicated optimization pass before work on the next area starts.
Validation checkpoint
A checkpoint with hard performance budgets sits between one area and the next.
The completed areas are covered in depth on the database and lake pages.
Planned
The planned areas, expanded
The timeline gives each area after transport security a sentence. This is the fuller scope of all eleven, taken from the roadmap table, in build order.
Planned
Memory governance
Memory across the node is accounted in one place rather than capped subsystem by subsystem.
One accounted poolClass floorsGrants instead of capsSpill on denial
Planned
Sharding
Heap tables split across nodes, with queries and transactions that span the shards.
Distributed query executionSplit and rebalance
Sharding coreHeap tables with top-bit hash placement, so a split is local.
Cross-shard transactionsPrepare lands in each participant's own Raft log.
Planned
Enterprise and distribution
What turns a cluster into one operable, governable system.
Secret store and KMS with HYOK adaptersHigh availability and DRObservability and complianceSemantic viewsSchema registryData contractsData governanceMulti-tenancy and cost trackingMigration tools and ecosystem connectorsExternal tablesVolumes, files as catalog objectsEnterprise type-system extensions
Planned
Serverless mesh and autonomous operations
A base compute mesh with user meshes on compute reservations, workload-aware scheduling, and continuous self-tuning and self-healing across every node, alongside query engine advances and model monitoring.
Planned
Wire protocols, API and drivers
Zyron's own ways in, alongside the PostgreSQL compatibility that works today.
Zyron APIA route registry that drives the router, OpenAPI, and generated reference docs, with SQL at /api/sql.
Native drivers and Zyron EmbeddedDrivers across every supported client language, and libzyron for in-process use.
Planned
Application and workflow hosting
Applications live where their data lives.
Zyron AppsContainer hosting on the mesh substrate.
WorkflowsTask orchestration, subsuming pipelines and schedules.
Queues and TopicsHeap tables through Raft, with transactional enqueue.
Deployment artifactsWith SQL function library expansion.
Planned
Dashboards, workspace, and metrics
First-party visualization, a place to work, and a metric store of Zyron's own, all aware of branches and time travel.
PythonJS/TSJava/ScalaGoRust
Zyron DashboardsLive query overlays and formatting with data, branch-native and time-travel-aware.
Zyron WorkspaceEditors, the language runtimes above, data and discovery, ops and integrations.
Metric storeA Zyron-native metric store.
Planned
Forms, Sheets, and Monitors
Input, spreadsheet, and watch surfaces that stay inside the catalog and never copy rows out.
FormsCatalog objects whose controls derive from the target's columns.
SheetsA .zysheet workspace file that stores query, formulas, and typed cells but never rows, with an EXPORT privilege enforced by an authorization token.
MonitorsRead metadata only and learn their bands.
Planned
Enterprise identity, organization, cross-cluster and Git
Identity that fits an enterprise, an organization directory, clusters that federate, and workspaces under version control.
Organization directoryGrantable units alongside groups.
Cross-cluster federationMutual TLS with primary, secondary, and peer roles.
GitA shared Git backend registry per workspace, with item versioning.
Planned
AI Gateway, AI-native assist, and AI-derived columns
A gateway for models under the operator's own credentials, with assist and derived columns built on top of it.
GatewayBring your own credentials, prompt versioning and branching, semantic caching, continuous evaluation, and cost tracking.
AssistOpt-in per-workspace SQL, chart, and notebook help routed through the gateway.
AI-derived columnsColumns whose values a model derives through the same gateway.
Planned
Zyron Web
The admin surface for everything above, shipping as a first-party static Zyron App.
ReactViteTailwindPath-based URLs
Up next: Transport security and post-quantum cryptography
Up next
Hybrid X25519MLKEM768 key exchange required between Zyron componentsOffered first to third parties, classical accepted and recordedOne stricter-only setting256-bit suites only, TLS 1.2 removedNode listener with mutual TLS to a cluster CA the operator holdsML-DSA-65SLH-DSA-SHA2-128sHybrid Ed25519+ML-DSA-65Signature schemes active per artifact kindRelease manifests signed hybridKey-exchange exposure report naming every outbound connection that negotiated classical
Consensus and mesh traffic become authenticated and encrypted under a CA the operator holds, and the three new signature schemes register through the per-artifact-kind signature agility the upgrade substrate already carries, built to take post-quantum additions without wire or code churn. The privileges, masking, and access control this wraps live on the security page.
Running in the next five minutes
Prebuilt binaries for Linux and Windows, no external dependencies, one command to a running server.