Skip to content

Roadmap (formerly SPEC §13)

The forward roadmap is executable on GitHub milestones; this file keeps the phase history and the mapping.

  1. Phase 0 — Foundations. DONE (2026-07-10): repo scaffold, Apache-2.0 + NOTICE, all review fixes D1–D15 (including the bridge work originally scheduled for Phase 3), Terraform hardening (§11), CI/CD (D13), Fgentic naming.
  2. Phase 1 — Matrix layer. DONE locally (2026-07-10): per-cluster config layer (clusters/base + local/gcp overlays, flux post-build substitution), per-cluster SOPS secrets (scripts/gen-secrets.sh), local-CA TLS (ESS bakes https URLs — local runs real TLS on loopback 80/443), ESS 26.6.2 on shared CNPG (release name ess; MSC3861 compat paths routed to MAS), MAS login + room verified. Deploy-time fixes worth knowing: dependency-free namespaces layer (HelmRelease-in-missing-namespace + secrets⇄workload deadlocks), kagent charts via OCI-type HelmRepository (chartRef appends digest build-metadata into a label), and the then-tested Gateway API v1.4.0 experimental plus Traefik chart 39.x compatibility set — bump the coupled pins together. Still open: Synapse media store decision (D12 residue), GKE deployment.
  3. Phase 2 — Agent layer + observability. DONE locally (2026-07-10): agentgateway LLM chokepoint on Vertex AI Gemini (auth.gcp {} — Workload Identity on GKE, ADC-JSON Secret locally via scripts/local-adc.sh; model ids are publisher-prefixed google/...), kagent on shared CNPG with the default agent zoo disabled (only mapped agents run — D7), A2A verified through the gateway (AgentCard rewrite, SendMessage, GetTask), §9 metrics layer built + verified (GenAI metrics are prefixed agentgateway_gen_ai_*). Traces remain (§9.2).
  4. Phase 3 — Bridge live. DONE locally (2026-07-10): registration + DB secrets, invite auto-join (StateMember handler — Synapse only delivers room traffic once a namespaced user is a member), as.Ready readiness fix, failed-task sanitization (§6), Prometheus side-port metrics; verified live: @mention → A2A → Gemini reply, threading via kagent session memory, and dedup. The provider-free contract and isolated kind integration fixtures later completed §12.2–§12.3 under M4; M8 extends that same fixture with a signed remote round trip and post-signature tamper refusal.
  5. Forward roadmap (2026-07-11): GitHub milestones M0–M12. The remaining phases were re-sequenced sovereignty-first and moved to GitHub milestones, each with an epic tracker issue and issues labeled agent-ready (groomed for autonomous coding agents) or needs-human (decision/approval/account/spend): M0 hygiene & drift sweep → M1 sovereign model profiles (D16) → M2 enterprise identity & SSO (Keycloak/MAS OIDC) → M3 one-command evaluation install & demo → M4 test harness (§12.2–12.5) → M5 traces & audit (§9.2–9.3) → M6 security hardening (§7) → M7 interop bridges (absorbs old Phase 4) → M8 federation preview (absorbs old Phase 6 — §8 unchanged and binding; the two-participant closed-federation demo is the flagship artifact) → M9 production reference (GKE apply + cloud-agnostic sovereign profile; absorbs old Phase 5 hardening) → M10 community & foundation readiness (A2A listing → kagent ecosystem → CNCF Sandbox path per §1.3) → M11 sovereignty kit (reference architecture, requirements matrix, compliance annex, exit-strategy matrix) → M12 in-room collaboration and governance UX (approvals, governed delegation chains, budgets, memory controls, and proactive agents). The standing rule survives the re-sequencing: nothing merged before M8 may paint federation into a corner (D6 is why that rule exists).
  6. M8 federation preview progress (2026-07-11): the provider-free lab now proves closed Matrix federation policy and live policy reload; the bridge can invoke explicitly pinned remote A2A URLs only after A2A v1.0 Signed AgentCard verification, with per-target timeout and token budget. No production remote is configured. The inbound partner listener, credential lifecycle, and full cross-organization delegation proof remain milestone work.
  7. M8 cross-org delegation plane (2026-07-12): the lab's opt-in delegation/ Component now serves the exact public docs-qa route behind a dedicated agentgateway listener — ES256/JCS Signed AgentCard on the wire, org-B client-credentials JWT authorization, per-azp maxTokens admission reservations — reaching the deterministic model without exposing kagent (#196). This supersedes the previous entry's "remain milestone work" list; the outstanding M8 items live on the milestone.
  8. Extensibility wave (2026-07-12): milestones M13–M17. A research pass over the Matrix/A2A/MCP/payments/sandbox ecosystems added five thematic milestones — M13 rich interaction surfaces (artifacts, mid-task questions, polls, widgets, A2UI) → M14 self-service agents, skills & tools (chat-to-PR agent factory, SKILL.md library, governed MCP catalog) → M15 enterprise operations (admin console, moderation, retention/GDPR, compliance export) → M16 agent economy & cross-org discovery (signed receipts, quotes, bilateral credit ledger, AP2-shaped mandates) → M17 personal agent sandboxes (agent-sandbox + gVisor + goose behind A2A) — plus dated additions to the M2/M5/M6/M8/M9/M10/M12 epics (issues #114–#180).
  9. Roadmap cohesion pass (2026-07-12). An adversarial backlog audit and product review were applied: ADR 0012 (bridge surface budget — inbound surfaces become sibling apps) and ADR 0013 (the federation lab is the permanent acceptance rig, with an opt-in agents component, #185) proposed; docs/stability.md added as the public-surface registry; sequencing recorded in the epics — M15 enterprise operations outranks the M13/M14 flagship UX, M16 beyond receipts/quotes waits for the first production cross-org pilot, and M17 implementation is gated on its ADRs (#147, #192). The standing backlog rule is restored: no new issue waves until M0–M3 close from execution feedback.
  10. Reach, currency & governance waves (2026-07-14): milestones M18–M24. A further ecosystem pass added seven thematic milestones — M18 fediverse & ActivityPub interop (delivered, #212/#213; docs/fediverse.md, ADR 0014) → M19 command & interaction UX → M20 omnichannel reach → M21 voice & multimodal → M22 proactive, durable & discoverable agents → M23 agent identity, trust & protocol currency → M24 governed tools & self-operating platform. The GitHub milestones page remains the authoritative forward roadmap; this history log trails it.
  11. Definitive v1 cut line (2026-07-14): focus over breadth. An outside strategic review plus a verified competitor scan (Vertex AI Agent Engine, Gemini Enterprise, Claude Cowork, Copilot Studio, OpenAI AgentKit; OSS LibreChat/Dify/Lobe/Onyx; building blocks kagent, Matrix widgets, Synapse-Admin/Ketesa, kubernetes-sigs/agent-sandbox + gVisor) confirmed the roadmap already covers every proposed "big feature" — admin console → M15, agent builder → M14, artifacts/widgets → M13, per-user code sandbox → M17 — so the binding constraint is focus, not ambition (25 milestones / 160+ issues, solo maintainer + coding-agent fleet). The response is to draw a v1 cut line and freeze the rest as vision, encoded in the backlog with three labels — track/v1 (ship first), track/vision (groomed North Star, not picked up until v1 ships), focus/wedge (moat-critical) — behind a single Definitive v1 focus board (#316). v1 = foundations (M0–M6, largely done) + the wedge (M8 federation → M9 production reference) + enterprise-ops core (M15 admin/retention/moderation) + M11 sovereignty kit + M3/M10 adoption + in-room governance guardrails (#96 approvals, #99 budgets, #119 lost-task switch) + a new in-production agent-quality/eval trust signal (#315). The wedge is what no proprietary or OSS platform surveyed offers: cross-org Matrix federation + open A2A peer delegation + Kubernetes-native governed agents. Build-vs-reuse standing rule: reuse kagent, Matrix widgets, Synapse-Admin/Ketesa, Element Call/X, and agent-sandbox + gVisor — never rebuild them — and avoid the AGPL/restrictive-license traps (Dify, Lobe, Onyx-EE, Daytona). The autonomy line was tightened in the same pass: needs-human now marks only spend / external-account / external-counterparty / legal-sign-off / ADR-acceptance / hard-block gates; anything gated on internal review or local-cluster proof is agent-owned, and PR review is peer-agent-owned (maintainer reviews async).
  12. Taxonomy rationalization (2026-07-30): milestone = release, three axes, 51 → 19 labels. The backlog had accreted four overlapping ways to say whenscope/*, track/*, version/v1…v10, and the thematic M0M34 milestones — because the milestone field had been spent on theme instead of timing. version/vN was a 100% duplicate of the vN milestone, track/* was fully derivable from scope/*, and the M-milestones cut across scope (M9 alone held v1.0, v1.1, and vision issues), which is why pickup had needed the "scope labels, not milestone order" workaround. The fix: the milestone is the release ladder and the only "when" axisv1.0v1.1v2v10Backlog — unscheduled. All 249 open issues were migrated (157 moved), the 24 M0M34 milestones were closed with their closed-issue history intact, and their themes now live in the kind/epic trackers and area/* labels that already existed. Labels collapsed to three axesarea/* (what), priority/p0|p1|p2 (urgency within the milestone), milestone (when) — plus four flags: kind/epic, needs-human, needs-cluster (merging the retired lane/runtime + blocked/runtime), and status/in-progress, with good first issue reserved for human newcomers. Deleted: scope/*, track/*, version/*, all kind/* except epic, focus/wedge, agent-ready, and ten unadopted GitHub defaults. Autonomy is now the defaultagent-ready sat on 68% of open issues and therefore filtered nothing, so every issue is agent-workable unless it carries needs-human, which was itself narrowed from 53 issues to the 20 that are genuinely terminal (spend, cloud deploy, external account or counterparty, publication under the maintainer's name, legal sign-off). Standing rule: never add a label that restates the milestone.