Skip to content

docs: reprioritize post-v1.0 roadmap by risk (security first, feature…#13

Merged
mikeappsec merged 1 commit into
mainfrom
roadmap-reprio
Apr 28, 2026
Merged

docs: reprioritize post-v1.0 roadmap by risk (security first, feature…#13
mikeappsec merged 1 commit into
mainfrom
roadmap-reprio

Conversation

@mikeappsec

Copy link
Copy Markdown
Owner

…s last)

Reorganize the post-v1.0 queue in DESIGN.md sec.7 and the v1.0-review.md follow-ups table into five tiers ordered by risk rather than by milestone number:

  • Tier S - security & correctness (next patch line, v1.0.x): SEC-PROXY-1 (proxy query/body fidelity + deny redaction, sibling repo), SEC-MTLS-1 (XFCC trust=true must require an anchor), TEST-RACE-1 (root-cause the configstream race flake).

  • Tier A - hardening (v1.1): F-PLUGIN-2, K-AUTHN-2, K-DOS-1, M10-PLUGIN-LIFECYCLE supervisor half, K-CRYPTO-2.

  • Tier B - quality / coverage (v1.1): M12-CONF-MATRIX, M12-BROKER-MW, DOC-OPENAPI-1.

  • Tier C - new features (v1.1+): M7-SPICEDB, DOC-COOKBOOK-1.

  • Tier X - experimental (no firm target): eBPF data plane, WASM plugins.

Original numeric IDs (16-27) preserved in parentheses so existing references resolve. Added a 'Prioritization rationale' subsection capturing the rule: never ship a new feature on top of a known security or correctness gap; tier C cannot be picked up while any tier-S item is open. The sibling repos (proxy, idp, plugins, ebpf) inherit this ordering.

…s last)

Reorganize the post-v1.0 queue in DESIGN.md sec.7 and the v1.0-review.md follow-ups table into five tiers ordered by risk rather than by milestone number:

* Tier S - security & correctness (next patch line, v1.0.x): SEC-PROXY-1 (proxy query/body fidelity + deny redaction, sibling repo), SEC-MTLS-1 (XFCC trust=true must require an anchor), TEST-RACE-1 (root-cause the configstream race flake).

* Tier A - hardening (v1.1): F-PLUGIN-2, K-AUTHN-2, K-DOS-1, M10-PLUGIN-LIFECYCLE supervisor half, K-CRYPTO-2.

* Tier B - quality / coverage (v1.1): M12-CONF-MATRIX, M12-BROKER-MW, DOC-OPENAPI-1.

* Tier C - new features (v1.1+): M7-SPICEDB, DOC-COOKBOOK-1.

* Tier X - experimental (no firm target): eBPF data plane, WASM plugins.

Original numeric IDs (16-27) preserved in parentheses so existing references resolve. Added a 'Prioritization rationale' subsection capturing the rule: never ship a new feature on top of a known security or correctness gap; tier C cannot be picked up while any tier-S item is open. The sibling repos (proxy, idp, plugins, ebpf) inherit this ordering.
@mikeappsec
mikeappsec merged commit 78194fb into main Apr 28, 2026
1 check failed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant