Project Roadmap

Public-safe architecture and progress snapshot generated from 17-state/current.yaml on 2026-08-09.

This page describes how the CGE projects fit together and where they are going. It intentionally does not mirror the full sprint board; raw issue hygiene belongs in the private task queue, not on the public roadmap.

Architecture Map

Project lane Role Direction
cge-hub Control plane, state ledger, architecture history Keep state, roadmap, and generated public views synchronized from one canonical source.
ai-bridge-runtime Agent tools, MCP servers, model routing, publication automation Harden automation contracts and keep live actions gated by scope and approval.
cge-go-agent Served agent runtime for grounded KG answers and bounty triage Keep the Go/ADK agents behind stable envelopes, evidence outputs, and approval gates.
saga-range Repeatable Active Directory purple-team range Preserve reset capability, scenario switching, and evidence-backed validation.
knowledge-rag-library Searchable knowledge base and graph layer Keep writeups, techniques, entities, and embeddings aligned for agent retrieval.
kryssar-public-site Sanitized public portfolio on kryssar.se Publish curated research, architecture, status, and roadmap views without leaking lab internals.
homelab-experience-site Internal detailed experience site Keep full-fidelity dashboards, graph views, and defender status inside the LAN.
lab-deployments Service and container deployment manifests Reduce broad mounts, keep services reproducible, and isolate risky runtime surfaces.
security-audit Authorized research workspace Keep bug-bounty hypotheses, scope records, Caido evidence, and report drafts gated and separate from the public site.

Progress Snapshot

  • Current phase: phase-5-orchestration + post-compromise-hardening
  • Reset capability: READY (BLUE-READY-BASELINE)
  • State timestamp: 2026-08-09T00:00:00Z
  • Open public-safe decision points: 2
  • Recent completed work items in state ledger: 208

Roadmap Timeline

May 04 - May 09Foundations
  • Hardware and documentation vault
  • Blue-team baseline and snapshots
May 10 - Jun 25Autonomous Lab
  • SAGA compromise campaign
  • Purple-team loop and telemetry
  • Range hardening and replayability
May 11 - Aug 31Agents and Knowledge
  • Graph-RAG and knowledge graph
  • MCP fleet and agent routing
  • Go agent runtime and cge-agentd
May 22 - Aug 31Sites and Publications
  • Sanitized public sync pipeline
  • Public roadmap and architecture views
  • Internal experience and graph views
Jun 22 - Aug 31Research Operations
  • Security-audit workspace wiring
  • Hostinger external-face experiment

Where The Projects Are Going

  1. Keep the lab reproducible. Every range, service, and public artifact should be rebuildable from source-controlled inputs and explicit state.
  2. Separate public narrative from private operations. Public pages should explain architecture and progress; internal queues, credentials, hostnames, and raw execution logs stay out of the publication path.
  3. Use agents as bounded operators. MCP tools, model routes, and n8n workflows are useful only when their inputs, permissions, and evidence outputs are clear.
  4. Turn evidence into knowledge. Completed attacks, detections, writeups, and lessons should flow back into the knowledge graph and retrieval layer.
  5. Make advanced compute optional. The inference mesh is a capacity experiment; production workflows should keep safe local fallbacks and avoid coupling to one GPU layout.

Near-Term Themes

Theme Direction Public-safe summary
Publication quality Active Keep kryssar.se focused on curated architecture, research, status, and roadmap views rather than raw sprint-board dumps.
Inference capacity Experimental Evaluate distributed local inference as optional capacity for heavy reasoning without making normal workflows depend on one hardware layout.
Served agents Active Use cge-go-agent for stable, grounded KG answers and scoped bounty-triage workflows with evidence envelopes.
External research face Active Keep Hostinger/VPS-facing bug-bounty tooling isolated from the home network and routed through approval-aware workflows.
Operational hygiene Recurring Keep automation credentials, service health, and generated state fresh through scheduled checks and explicit operator gates.
Scenario learning loop Next Convert validated lab activity into reusable knowledge, safer playbooks, and public writeups after sanitization.