PluginManager supports loading extensions from {dataDir}/plugins/ that can register: - Custom service types with health-check hooks - Custom notification providers - Custom workflow action types - Dashboard widgets (via manifest) - Pre/post container deploy hooks - Config validation hooks Security: plugins declare permissions in manifest.json, admin must approve. Currently runs in-process (no sandbox). Plugin directory auto-created on first run. 14 tests, 1618 total pass. Example manifest.json: { "name": "my-plugin", "version": "1.0.0", "serviceType": "custom-app", "permissions": ["docker:read", "notifications:send"] }