Skip to content

docs: expand roadmap — post-1.0 horizon, security workstream, diagnose tool - #14

Merged
TMHSDigital merged 1 commit into
mainfrom
docs/roadmap-expand
Jul 16, 2026
Merged

docs: expand roadmap — post-1.0 horizon, security workstream, diagnose tool#14
TMHSDigital merged 1 commit into
mainfrom
docs/roadmap-expand

Conversation

@TMHSDigital

Copy link
Copy Markdown
Owner

Summary

Expands the roadmap with the research layers not yet mapped:

  • v1.x post-1.0 horizon (exploratory): tailnet observability (device posture, audit logs), webhook management (with the consume-side honestly gated on the remote-deployment story), workload identity federation (a gap-table item no MCP server offers), Tailscale Services, declarative daemon config via reload-config, split-DNS writes. Each item states what promotes it into a numbered train.
  • Cross-cutting security-hardening workstream distilled from Tailscale's CVE history: args-arrays-only, adversarial-input tests with every tool, fixture sanitizer, no credentials in errors, TS-bulletin review.
  • Two v0.2 additions: an input-hardening pass — TS-2026-009 (leading-dash username injection in Tailscale SSH) is the exact shape of our generate_ssh_config user input, worth adversarial tests now — and a diagnose tool returning interpreted triage instead of three raw payloads.

No version bump: repo-docs only.

🤖 Generated with Claude Code

…m, diagnose tool

- v1.x exploratory horizon from unmapped research findings: observability
  (posture/audit logs), webhook management, workload identity federation,
  Tailscale Services, declarative daemon config, split-DNS writes
- standing cross-cutting security workstream from Tailscale CVE history
- v0.2 additions: input hardening pass (TS-2026-009 leading-dash lesson
  applies to generate_ssh_config user input) and a diagnose triage tool

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@TMHSDigital
TMHSDigital merged commit 6d52665 into main Jul 16, 2026
6 checks passed
@TMHSDigital
TMHSDigital deleted the docs/roadmap-expand branch July 16, 2026 01:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant