MIRKO
Blockchain9 Min Read

Maintaining Aragon OSx: What It Takes to Keep DAO Infrastructure Secure and Upgradeable

Mirko is a maintainer of Aragon OSx, the modular framework behind thousands of on-chain organisations. Maintaining governance infrastructure is a different discipline from shipping a dApp: every change touches contracts that hold other people's treasuries. Here is how we approach it.

David Kukharchuk

By David Kukharchuk

Tech Lead at Mirko

Maintaining Aragon OSx: What It Takes to Keep DAO Infrastructure Secure and Upgradeable

Aragon OSx is a modular operating system for DAOs: a core DAO contract, a permission manager and a plugin framework that lets organisations compose their own governance from token voting, multisigs, optimistic proposals and custom plugins. Thousands of organisations run on it, which means the code is not ours to break. As maintainers, our job is to keep it secure, upgradeable and pleasant to build on, in that order.

Permissions are the product

Everything in OSx is a permission: who can execute actions on the DAO, who can install plugins, who can upgrade what. A governance bug is almost always a permission bug. We review every change against the permission model first and the feature second, and we maintain a test suite that asserts the complete permission matrix of a fresh DAO after every plugin installation, update and uninstallation.

What we check before a release

  • No new permission is granted to an address that did not hold it before, unless the proposal explicitly says so.
  • Plugin setup contracts prepare and apply permissions in two steps, so a DAO can review what will change before applying it.
  • Upgrades keep storage layouts compatible; we diff storage slots automatically in CI.
  • Every public function has an invariant test, and fuzzing runs on the permission manager and the executor.

Upgradeability without surprises

DAOs expect to upgrade without migrating treasuries. OSx uses proxy patterns and versioned plugin repositories, which gives flexibility and creates the single most dangerous moment in the lifecycle: the upgrade transaction. Our release process includes storage-layout diffs, a dry run of the upgrade against a mainnet fork, and a public changelog that explains in plain language what the DAO is agreeing to when it votes on the upgrade.

Plugins: the ecosystem's surface area

The plugin framework is why OSx scales: anyone can publish a governance plugin. It is also why maintainers spend most of their time on tooling. We maintain the developer kits, templates and documentation that make a correct plugin the easy path, including the setup pattern, the permission helpers and the test harness. Our Part 1 tutorial on creating an Aragon project is the on-ramp we point new teams to.

What this means for clients

Organisations that need on-chain governance, treasury management or tokenised decision rights get a team that maintains the framework they will run on. That shows up as fewer surprises in audits, faster plugin development and upgrade paths that do not lock a treasury. The same engineers build our zero-knowledge, tokenisation and marketplace projects, so governance is designed together with the product rather than bolted on.

You May Also Like

Let's BuildSomething ThatMatters

Have a project in mind or looking for the right technology partner? Tell us what you're working on, and our team will get back to you to explore how we can help bring it to life.