> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kguardian.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Planned Features & Roadmap

> Upcoming features and improvements for kguardian

## Release Roadmap

<Note>
  The project shifted to **component-based releases** via
  [release-please](https://github.com/kguardian-dev/kguardian/blob/main/RELEASES.md)
  — each component (controller, broker, frontend, advisor, evaluator,
  llm-bridge, chart) versions independently as features
  land. The release-cohort sections below are kept as a feature-set
  narrative; for the current versions of each component, see
  [`.release-please-manifest.json`](https://github.com/kguardian-dev/kguardian/blob/main/.release-please-manifest.json).
</Note>

<Steps>
  <Step title="Initial release">
    **Status:** ✅ Shipped

    * Kubernetes NetworkPolicy generation
    * Cilium NetworkPolicy support
    * Seccomp profile generation
    * eBPF-based observability (network + syscalls)
    * Web UI with network graph visualization
    * kubectl plugin CLI
    * PostgreSQL storage backend
  </Step>

  <Step title="Observability + retention pass">
    **Status:** ✅ Shipped

    * Prometheus metrics export at `/metrics` (broker exposes
      `broker_db_schema_ready`, `broker_db_reachable`,
      `broker_audit_enabled`, `broker_audit_inflight_available`,
      `broker_db_pool_idle`, `broker_db_pool_max`,
      `broker_uptime_seconds`) plus chart-side ServiceMonitor wiring.
    * `audit_verdicts` data-retention loop with batched DELETE
      (configurable via `AUDIT_VERDICTS_RETENTION_DAYS`,
      `AUDIT_VERDICTS_RETENTION_INTERVAL_SECS`,
      `AUDIT_VERDICTS_RETENTION_BATCH_SIZE`).

    **Still in development:**

    * Time-range filtering for policy generation
    * Policy diff/comparison tool
    * Improved UI with filtering and search

    **Still planned:**

    * L7 policy hints for Cilium (HTTP, gRPC)
    * CiliumClusterwideNetworkPolicy generation
    * Multi-cluster support (federated broker)
  </Step>

  <Step title="Audit mode + AI assistant">
    **Status:** ✅ Shipped

    * `AuditNetworkPolicy` + `AuditClusterNetworkPolicy` CRDs.
    * Evaluator component matching observed flows against audit
      policies (selectors + ports + named-port + ipBlock + CIDR).
    * Broker → evaluator forwarder with a bounded
      `AUDIT_INFLIGHT_PERMITS` semaphore.
    * Frontend "Would-Deny" view consuming
      [`GET /audit/verdicts`](/api-reference/endpoints/audit-verdicts).
    * `kguardian audit promote` and `audit promote-cluster` CLI
      helpers for promoting an audit policy to an enforced
      `networking.k8s.io/v1.NetworkPolicy`.
    * LLM Bridge — AI assistant tab in the UI brokers cluster
      questions through the broker's read endpoints (in-process
      tool calls; originally paired with a separate MCP server,
      since retired and folded into the bridge).
    * [MCP endpoint](/guides/mcp-endpoint) — the same in-process
      tools served to external MCP clients over HTTP from the
      bridge, off by default.

    **Still planned (was tied to this cohort):**

    * AppArmor profile generation
    * File access observation
    * Capability restrictions
    * Integration with Security Profiles Operator
    * Auto-apply via AppArmorProfile CRD
    * Enhanced Cilium FQDN rules
    * GitOps integration examples (ArgoCD, Flux)
  </Step>

  <Step title="SELinux profiles">
    **Status:** 💭 Concept

    **Major Feature: SELinux Policies**

    * Type enforcement rules
    * File context generation
    * Process domain transitions
    * udica integration

    **Additional:**

    * Historical policy versioning
    * Policy rollback mechanism
    * Compliance reporting (CIS, PCI-DSS)
  </Step>

  <Step title="Pod Security Standards">
    **Status:** 💡 Under Consideration

    **Major Feature: Pod Security Standards**

    * PSS compliance detection
    * Auto-labeling recommendations
    * Migration assistant from PSPs
    * Violation alerts

    **Additional:**

    * Resource quota recommendations
    * VPA integration for sizing
    * Cost optimization insights
  </Step>
</Steps>

***

## Feature Requests

Ideas under discussion include service-mesh AuthorizationPolicies (Istio/Linkerd), Falco rule generation, OPA/Gatekeeper admission policies, and an RBAC least-privilege analyzer. Want one of these — or something else? Open or upvote an issue on [GitHub](https://github.com/kguardian-dev/kguardian/issues).

***

## Long-Term Vision

### Automated Security Lifecycle

Our vision is a fully automated security lifecycle:

```mermaid theme={null}
graph LR
    A[Deploy App] --> B[Observe Behavior]
    B --> C[Generate Policies]
    C --> D[Test in Staging]
    D --> E[Auto-Apply]
    E --> F[Continuous Monitoring]
    F --> G{Drift Detected?}
    G -->|Yes| H[Alert + Suggest Update]
    G -->|No| F
    H --> B
```

### Multi-Cloud Support

* **AWS EKS** - Native integration with VPC CNI and Security Groups
* **GCP GKE** - GKE dataplane v2 (Cilium) optimizations
* **Azure AKS** - Azure Network Policies integration
* **On-Premises** - Optimized for Calico and Cilium

### Enterprise Features

For commercial licensees:

* **SAML/SSO Integration** - Enterprise authentication
* **Multi-Tenancy** - Isolated namespaces and data segregation
* **Advanced Analytics** - ML-based anomaly detection
* **Premium Support** - SLA-backed support and consulting

***

## Technology Improvements

### Performance

* **Scalability:** Support for 10,000+ pods
* **Efficiency:** Reduce controller CPU overhead to `<0.5%`
* **Storage:** TimescaleDB for time-series optimization

### Developer Experience

* **GitOps Templates** - Pre-built CI/CD integrations
* **Policy Testing Framework** - Unit tests for policies
* **Visual Policy Builder** - Drag-and-drop UI for custom rules

### Security

* **Broker Authentication** - OAuth2, mTLS, API keys
* **Encrypted Storage** - At-rest encryption for PostgreSQL
* **Audit Logging** - Comprehensive audit trail
* **SBOM Generation** - Software Bill of Materials for compliance

***

## How to Influence the Roadmap

<Steps>
  <Step title="Vote on GitHub Issues">
    Star or react to issues you care about: [github.com/kguardian-dev/kguardian/issues](https://github.com/kguardian-dev/kguardian/issues)
  </Step>

  <Step title="Join Discussions">
    Share your use cases and requirements: [github.com/kguardian-dev/kguardian/discussions](https://github.com/kguardian-dev/kguardian/discussions)
  </Step>

  <Step title="Contribute Code">
    Pick up an issue and submit a PR. We love community contributions!
  </Step>

  <Step title="Commercial Licensing">
    Enterprise customers get priority feature requests. Contact us for licensing options.
  </Step>
</Steps>

***

<CardGroup cols={2}>
  <Card title="Future Resources" icon="map" href="/roadmap/future-resources">
    See detailed plans for AppArmor, SELinux, and more
  </Card>

  <Card title="Contributing Guide" icon="code-pull-request" href="https://github.com/kguardian-dev/kguardian#contributing">
    Help build the future of kguardian
  </Card>

  <Card title="GitHub Roadmap" icon="github" href="https://github.com/kguardian-dev/kguardian/milestones">
    View milestones and progress
  </Card>

  <Card title="Release Notes" icon="tag" href="https://github.com/kguardian-dev/kguardian/releases">
    See what's been shipped
  </Card>
</CardGroup>
