Project Roadmap
Public-safe architecture and progress snapshot generated from 17-state/current.yaml on 2026-08-09.
This page describes how the CGE projects fit together and where they are going. It intentionally does not mirror the full sprint board; raw issue hygiene belongs in the private task queue, not on the public roadmap.
Architecture Map
| Project lane | Role | Direction |
|---|---|---|
cge-hub |
Control plane, state ledger, architecture history | Keep state, roadmap, and generated public views synchronized from one canonical source. |
ai-bridge-runtime |
Agent tools, MCP servers, model routing, publication automation | Harden automation contracts and keep live actions gated by scope and approval. |
cge-go-agent |
Served agent runtime for grounded KG answers and bounty triage | Keep the Go/ADK agents behind stable envelopes, evidence outputs, and approval gates. |
saga-range |
Repeatable Active Directory purple-team range | Preserve reset capability, scenario switching, and evidence-backed validation. |
knowledge-rag-library |
Searchable knowledge base and graph layer | Keep writeups, techniques, entities, and embeddings aligned for agent retrieval. |
kryssar-public-site |
Sanitized public portfolio on kryssar.se |
Publish curated research, architecture, status, and roadmap views without leaking lab internals. |
homelab-experience-site |
Internal detailed experience site | Keep full-fidelity dashboards, graph views, and defender status inside the LAN. |
lab-deployments |
Service and container deployment manifests | Reduce broad mounts, keep services reproducible, and isolate risky runtime surfaces. |
security-audit |
Authorized research workspace | Keep bug-bounty hypotheses, scope records, Caido evidence, and report drafts gated and separate from the public site. |
Progress Snapshot
- Current phase:
phase-5-orchestration + post-compromise-hardening - Reset capability:
READY (BLUE-READY-BASELINE) - State timestamp:
2026-08-09T00:00:00Z - Open public-safe decision points:
2 - Recent completed work items in state ledger:
208
Roadmap Timeline
- Hardware and documentation vault
- Blue-team baseline and snapshots
- SAGA compromise campaign
- Purple-team loop and telemetry
- Range hardening and replayability
- Graph-RAG and knowledge graph
- MCP fleet and agent routing
- Go agent runtime and cge-agentd
- Sanitized public sync pipeline
- Public roadmap and architecture views
- Internal experience and graph views
- Security-audit workspace wiring
- Hostinger external-face experiment
- Inference mesh evaluation
- Scenario factory and learning loop
Where The Projects Are Going
- Keep the lab reproducible. Every range, service, and public artifact should be rebuildable from source-controlled inputs and explicit state.
- Separate public narrative from private operations. Public pages should explain architecture and progress; internal queues, credentials, hostnames, and raw execution logs stay out of the publication path.
- Use agents as bounded operators. MCP tools, model routes, and n8n workflows are useful only when their inputs, permissions, and evidence outputs are clear.
- Turn evidence into knowledge. Completed attacks, detections, writeups, and lessons should flow back into the knowledge graph and retrieval layer.
- Make advanced compute optional. The inference mesh is a capacity experiment; production workflows should keep safe local fallbacks and avoid coupling to one GPU layout.
Near-Term Themes
| Theme | Direction | Public-safe summary |
|---|---|---|
| Publication quality | Active | Keep kryssar.se focused on curated architecture, research, status, and roadmap views rather than raw sprint-board dumps. |
| Inference capacity | Experimental | Evaluate distributed local inference as optional capacity for heavy reasoning without making normal workflows depend on one hardware layout. |
| Served agents | Active | Use cge-go-agent for stable, grounded KG answers and scoped bounty-triage workflows with evidence envelopes. |
| External research face | Active | Keep Hostinger/VPS-facing bug-bounty tooling isolated from the home network and routed through approval-aware workflows. |
| Operational hygiene | Recurring | Keep automation credentials, service health, and generated state fresh through scheduled checks and explicit operator gates. |
| Scenario learning loop | Next | Convert validated lab activity into reusable knowledge, safer playbooks, and public writeups after sanitization. |