Synced from Hive. This page is pulled from kubestellar/hive@v4 during the docs build. Edit the canonical source in the Hive repository.

Hive public roadmap

Directional, not a promise. This roadmap reflects the public v4 direction as of 2026-09-03. It is maintained by pull request and can change as issues, security reviews, and operator feedback change the order of work.

The umbrella issues this page grew out of — #2812 (catch-up epic) and #2811 (docs catch-up) — were both closed on 2026-08-08. They are cited below as the origin of a line of work, not as live trackers: a closed umbrella says nothing about whether any particular item under it shipped, so each row states its own status.

Hive’s roadmap is organized as Now / Next / Later: near-term work already in flight, likely follow-ups, and longer-horizon bets. Items are listed in planning order, not priority rank.

Now

WorkOutcomeTracking
Prompt-injection defense-in-depthCanary-token checks, output redaction, fail-closed scanning, and the optional model-based semantic classifier build on deterministic ioscan kick-path redaction.#2805, security threat model, ADR-0008
Intent verificationTier-based change authorization is in the merge-gate path; trajectory-integrated intent-alignment review remains the next slice.#2803, intent verification
Review fan-outStructured review reports and deterministic aggregation are in place; scheduler fan-out to parallel review perspectives is the deferred wiring.#2807, review swarm
Credential-free sandbox kick pathMove agent execution toward no live token and no direct network in the sandbox, with trusted host-side post-steps retaining the MITM proxy as an outer layer.#2804, security threat model
Spoke-based lite enrollmentKeep hivectl enroll OWNER/REPO as a zero-secret on-ramp by adding repos to an existing spoke or provisioning a hosted lite spoke; the hub tracks spokes.#2808, lite enrollment
Multi-spoke constellation foundationsAccepted for v5 phase 1 after production evidence from tunaos.org (self-hosted hub, two ACMM L5/L6 spokes, 43 repos). The first slice, repo-claim overlap detection, shipped in #5705; remaining slices add spoke charters, fleet headroom, GitHub App budget visibility, shared-credential guidance, and route recommendations without turning the hub into a hard control plane.#5691, RFC #5691, #5705, #5796
Backend capacity, model inventory, and placementAccepted for v5 phase 1 because multi-spoke fleets are constrained by shared provider quota, model availability, and policy, not by repo ownership. The work standardizes capacity readings, inventory authority, tier floors, scoped limits, and opt-in placement / pacing before scheduler behaviour depends on them.#5698, RFC #5698, #5784
Hosted Hive Hub positioningAnchor the hosted hub (hive.hivecommons.dev) as the evaluation-grade, best-effort on-ramp: OAuth/OIDC accounts, admin-granted hosted quota, per-user and per-cluster capacity controls, /data/saas records, bounded usage/timeline history, hosted-vs-self-hosted guidance, and early exercise of the v5 constellation/capacity workstreams.#6017, ROADMAP.md, hosted-hub
Retrospective learning laneBuild from deterministic post-completion advisory beads toward LLM-assisted retro summaries and knowledge extraction.#2809, retro lane
ADR back-fill for remaining subsystemsDone. Back-filled accepted ADRs capture the knowledge system, skill registry, CEL/channel triggers, and hub/spoke mechanics, so architecture decisions stay auditable.ADR-0011, ADR-0012, ADR-0013, ADR-0014
HiveCommons org migrationMake the kubestellar-to-hivecommons migration auditable before package or repository defaults change, including image mirror phases, docs sweeps, v5 edge coverage, and operator communications.migration tracker, #5686
v4 stable soak gateDone. CI now keeps candidate moving on every green v4 image build and promotes stable later by digest after the soak, evidence, blocker, smoke, and monotonic guards pass.stable soak policy, #5974

Next

WorkOutcomeTracking
Docs site publicationLive, not deferred. The org already runs docs site — kubestellar/docs (Next.js on Netlify) — and pulls a growing subset of src/docs/ straight from this repo’s v4 branch on every build, publishing at kubestellar.io/docs/hive with links rewritten to site routes. There is deliberately no second site generator in this tree (a per-repo MkDocs/Docusaurus config would duplicate that pipeline); hive.hivecommons.dev serves the product/dashboard landing page, not docs, with hive.kubestellar.io retained as a legacy redirect during the cutover. This repo’s job is keeping src/docs/ a correct source for that sync — see Docs Link Check, which gates relative links and heading anchors on every PR touching src/docs/. Remaining follow-up, tracked separately: expanding the sync manifest (kubestellar/docs:scripts/sync-hive-docs.ts) to cover the ~65 pages not yet on it is a change to that repo, not this.docs index, origin: #2811 (closed), tracker: #5258
GitLab through pkg/forgepkg/forge ships GitHub, GitLab, and Gitea/Forgejo adapters with the read path and core write path implemented and tested; Merge is left an explicit interface TODO because merge semantics diverge across forges. First production caller landed: the governor’s escalation writes (evidence comment + needs-human label) are now typed against the forge.IssueWriter seam, with the adapter selected from project.forge — so that key is no longer display-only. A GitHub hive is unchanged, still on *github.Client. Those writes are not yet reached on a non-GitHub hive, because the read path is still GitHub-shaped: EnumerateActionable feeds the whole governor cycle and owns hold-label filtering, issue filters and SLA tracking inside pkg/github. Neutralizing enumeration — lifting that policy above the forge boundary, and adding a bulk list method so an N-repo hive does not enumerate N times — is what remains.ADR-0005, #5259, origin: #2812 (closed)

Later

WorkOutcomeTracking
Cross-forge orchestrationCoordinate issues, merge requests, policy, and evidence across GitHub, GitLab, and Forgejo/Gitea-style forges.ADR-0005
Memory and learning maturationTurn retro findings and curated knowledge into durable, testable priming without hidden or unauditable agent memory.knowledge design, retro lane
Kubernetes-native agent sandboxesGraduate from tmux/container execution toward k8s-native, policy-isolated agent workloads where that complexity is justified.architecture, security threat model

Reading this roadmap

  • Now does not mean all work is complete; it means active phase-2 work or freshly merged foundations with known wiring still in progress.
  • Next items are expected follow-ups, not release commitments.
  • Later items are strategic directions that may split into narrower issues before implementation.