Where it’s going — and what stays free.
A public pre-launch roadmap, kept honest the same way as the code: nothing is claimed before it exists.
Already real
Measured, not asserted.
The engine is public-in-progress on main, and the numbers are the CI’s, not marketing’s: 74 Go packages, 166 reflex tests, contract schemas pinning every wire payload, and a hermetic ladder — build, vet, dead-code, secrets, and smoke against a live NATS stack — on every PR.
Already landed and in daily use:
- Agentgateway by default — all tool traffic transits the gateway with per-run attribution; credentials are minted when the run starts and revoked when it ends.
- Reflex on the tool path — the gate judges every tool call pre-flight (allow/deny/hold); a risky action is refused at the wire, and allow/hold precision is measured per tool on the gate-quality page.
- The operator console — compose → watch → govern → learn: task-plane composer with typed forms, live run detail, approvals with your words on the log, fleet and project views over the directory read model.
- The knowledge plane — a fleet wiki with scoped read tools and provenance on every page.
- Forge signals — GitHub webhooks and GitHub/GitLab polling feeding one ingress, with freshness loudly recorded.
- Economics — per-run token usage, per-agent attribution, and a usage rollup over the run projection.
Next
What's being built now.
The resident agent runtime
Always-on agents with a strict rule: initiative is resident, execution
stays governed. A platform manager watches drift and files proposals
for human approval; a console assistant answers within its declared
knowledge scopes and prepares — never fires — gated dispatches. Designed
in the open: the ADR is published, rejected alternatives included.
Implementation slices come next: the runtime spine, then the manager
persona, then the assistant persona.
Forge-native crews
Deeper than signals: issues become governed tasks with
intent: and
acceptance:, review loops open PRs and MRs through the gateway, and the
fleet directory converges registration from the repo.Durable timers + A2A depth
Retry timers that survive restarts, and A2A multi-turn with cancel and
message dedup — the assistant’s wire-depth upgrade.
The Kubernetes driver — the main goal
v1 runs agents as subprocesses and Docker containers; the platform
profiles ADR already names the destination: one container contract,
served by a Kubernetes driver — worker as Deployment, sidecars as
in-pod processes or ephemeral pods, workspaces on PVC, no
Docker-in-Docker. This is the headline of the beta.
More battle-tested harnesses
Wired already: Codex, Kimi, local models (Qwen, Gemma), any HTTP LLM.
Each gets its smoke suite and CI qualification before it is called
proven — harnesses are added by evidence.
Not there yet — said out loud
Ships in the public beta.
The honest gap list, named rather than buried. Each of these is designed or contracted already; none is silently implied by what’s live today:
Kubernetes driver
The deployment target for real fleets: pods, PVC-backed workspaces,
per-run service composition mapped natively — the container contract’s
second driver.
Durable timers + A2A depth
Retry timers that survive restarts; A2A cancel, multi-turn, and message
dedup — the assistant’s wire-depth upgrade.
Per-intent auto-dispatch
Proposal-first today, by policy. The per-intent gate unlocks named
proposal types for auto-dispatch behind the gate — never before it.
The skills registry — tracked, not shipped
Agents declare tools today; the skills registry makes skills
first-class: a typed catalog of capabilities — procedures, adapters,
workflows — with hierarchical assignment across the fleet: fleet
defaults, project overrides, manifest-declared opt-ins, every entry
contract-pinned and swept like every other registry entity. It rides the
same GitOps spine: declared in git, reviewed like code, enforced at the
boundary. On the tracker now; landing after the beta’s headline items.
Licensing
AGPL core, commercial boundary — stated plainly.
Free forever — AGPL-3.0 core
The engine, the reflex gate, manifests, workflows, A2A, sidecar isolation,
the CLI, the console, and observability. Self-hosted, source-available,
yours. The premium boundary stays outside the repo by design.
Commercial, when available
Announced in the repo NOTICE: SAML/SSO, user teams, analytics, evals, and
multi-project tasks will ship separately under a commercial license,
plugging into the open core through documented extension points.
Public release soon.
Source and docs publish with the release — or write and say you want to be notified, and you’ll get one email when it ships.