Roadmap
0.1 – Core (in progress)
Section titled “0.1 – Core (in progress)”- Control node: API (Fastify, OpenAPI 3.1), PostgreSQL, run queue, console (React), OIDC/LDAP sign-in, RBAC with six roles, API tokens.
- Agents as code:
agents.mdparser and validator, immutable published versions, pipelines of 1..n agents. - Events: signed webhooks, Kafka, cron, mail-in via webhook; Teams and Slack through generic webhooks.
- Guardrails: per-agent audit gate, global control agent, approvals, data classification.
- Audit: append-only SHA-256 hash chain with Ed25519-signed checkpoints and verification.
- Costs: per step and run, price table, budgets with hard stop.
- Providers: OpenAI-compatible, Ollama, AWS Bedrock (VPC endpoint, proxy, IRSA), Anthropic, simulated.
- MCP: client with per-agent allowlists, timeouts and result limits; the policy gate as an MCP proxy.
- Runners:
in-processandlocal(oaxCLI), with the interfaces for all later runners. - Observability: Prometheus metrics, OpenTelemetry traces, JSON logs, health endpoints.
- Tenants and access: tenants as the isolation boundary, roles per tenant and optionally per agent (details).
- Bring your own: provider keys by reference and a model catalog from a pinned models.dev snapshot (details); MCP servers per tenant.
- Cost attribution: per tenant, agent, use case and run, with CSV/JSON export.
- Delivery: Docker Compose, Helm chart for Kubernetes and EKS, this website and docs.
0.2 – Worker nodes
Section titled “0.2 – Worker nodes”containerrunner (Docker, Podman) andkubernetes-jobrunner (also EKS) that spawn one short-lived worker per run.- Toolbox images from a catalogue: minimal, non-root, read-only, pinned by digest, signed (cosign), with SBOM (syft) and vulnerability scans (trivy); egress allowlisted per toolbox.
- Per-run secret injection and revocation.
0.3 – Anywhere
Section titled “0.3 – Anywhere”aws-lambda,github-actionsandgitlab-cirunners with signed callbacks.- Optional external harnesses: Claude Code, OpenCode, Hermes, OpenClaw, all routed through the policy gate.
- Dedicated Teams and Slack adapters, IMAP polling for mail.
Later: planning, governance, factory
Section titled “Later: planning, governance, factory”- Agent Check and Agent Build: from a process described in plain language to a least-privilege agent plan and a scaffolded, tested agent.
- Governance: approval workflows, an MCP catalog, emergency security overrides.
- Change-gated schedules (details).
- Development guidelines and a global hardening agent (details).
- Dark software factory, opt-in and recommended for proof-of-concept work only (details).
- Air-gapped operation documented end to end (details).
The order within this list is not fixed; the platform repository tracks the current plan.
Towards 1.0
Section titled “Towards 1.0”- Stable
v1APIs andagents.mdschema (openagentix.io/v1). - Signed releases and images, documented upgrade paths.
- Chart repository and OCI publishing, public demo at
demo.openagentix.si.
Have an idea? Open an issue in the platform repository; larger changes start as an ADR.