Roadmap
Every capability the project has, labelled with what it actually is. The point of publishing the whole list — including the parts that are only designed — is that a reader can tell the difference without asking.
What the status words mean
- stable
- Implemented, regression-tested, and exercised by a recorded live acceptance artifact.
- alpha
- Implemented and tested, but the proof is a test rather than a recorded live deployment, or the interface may still move before 1.0.
- experimental
- Implemented and deliberately not relied on. Read its caveat before using it.
- planned
- Designed and documented. Not implemented. Nothing on the website may present this as available.
Nothing on this site presents a planned capability as available. If you need something from the planned list, it is a design conversation, not a configuration change.
The inventory
stable
12
alpha
10
experimental
2
planned
3
| Capability | Status | Note and implementation evidence |
|---|---|---|
| Firecracker microVM sandboxes Isolation | stable | Forced by runtime policy for untrusted workloads. A tenant cannot request a weaker runtime to downgrade their own boundary. crates/aiec-runtime/src/lib.rs → FirecrackerRuntime; benchmarks/guard-core-acceptance.json |
| Docker sandbox runtime Isolation | alpha | Available for trusted self-hosted deployments, local development and operator tasks. Not offered to untrusted public workloads. crates/aiec-runtime/src/docker.rs |
| Bubblewrap development runtime Isolation | experimental | Local development. Workspace snapshots have been exercised by restoring into a distinct sandbox; it is not the untrusted-workload boundary. crates/aiec-runtime/src/lib.rs → BubblewrapRuntime |
| External hosted isolation provider Isolation | alpha | The isolation boundary would be owned by the provider, not by AIec, so this kind never runs on a managed worker node. NOT exercised against a real provider; no live evidence exists. crates/aiec-core/src/lib.rs → RuntimeKind::Hosted |
| Create, exec, files, pause, resume, destroy Sandboxes | stable | Workspace paths are confined and reject traversal and symlink escapes. Directory listings are bounded rather than truncated. crates/aiec-api/src/lib.rs; scripts/smoke.sh |
| Bounded CPU, memory, disk and wall clock Sandboxes | stable | Quotas are enforced in the same transaction as placement, under a per-tenant advisory lock. crates/aiec-core/src/lib.rs → QuotaLimits; enforcement in crates/aiec-storage |
| Runs: submit, results, events, artifacts, cancel Durability | stable | Events, attempts and artifacts for one run are bounded by construction, not by pagination. crates/aiec-api/src/runs.rs; scripts/firecracker-coding-dogfood.sh |
| Lease and generation fencing Durability | stable | A superseded worker cannot execute, write, stop, destroy or complete against a reassigned sandbox. crates/aiec-core/src/scheduler.rs; enforcement in crates/aiec-storage |
| Cross-worker recovery from a workspace archive Durability | alpha | PostgreSQL leases plus an S3-compatible workspace archive. Running VM memory is not the portable recovery unit, and multi-host recovery has not been validated by the recorded evidence. docs/DEPLOYMENT.md; benchmarks/snapshot-acceptance.json |
| Workspace snapshot, destroy source, restore into a new sandbox Snapshots | stable | This is the portable kind. benchmarks/snapshot-acceptance.json (12/12 against real S3 storage) |
| Full VM and memory-only Firecracker snapshots Snapshots | experimental | Worker-local recovery artifacts. Do not present them as portable workspace snapshots; compatible host and device-path portability is unproven. docs/SNAPSHOTS.md; crates/aiec-core/src/snapshots.rs |
| Guard: out-of-guest network, DNS and credential boundary Governance | stable | Default is no network. A sandbox asking for a network without selecting a policy is refused, not quietly filtered. benchmarks/guard-core-acceptance.json (48/48); docs/GUARD_THREAT_MODEL.md |
| Watchdog, dead-man switch and quarantine Governance | stable | Loss of the watchdog is fail-closed and latches. The guest is not destroyed, so a forensic capture is still possible. benchmarks/guard-phase2-acceptance.json (29/29) |
| Guard tool-approval proposals and operator decisions Governance | alpha | An agent can propose a policy change and cannot approve one. Proposal ownership is tenant-checked. benchmarks/guard-phase3-acceptance.json (47/47); benchmarks/guard-approval-acceptance.json |
| Per-VM identity, image trust and canaries Governance | alpha | Trusted host file APIs can observe reads; arbitrary in-guest exec reads are not observable through those APIs. benchmarks/guard-phase5-acceptance.json (37/37) |
| Durable lifetime reaper Governance | stable | The second run goes through the external-database relay. benchmarks/guard-reaper-acceptance.json (16/16); benchmarks/guard-reaper-external-db-acceptance.json (16/16) |
| Layer 7 visibility (method, path, tool) for governed traffic Governance | planned | Not implemented. Opaque TLS is not inspected. A CONNECT tunnel needing Layer 7 visibility is REFUSED rather than forwarded ungoverned, and TLS interception is not claimed as a validated deployment mode. docs/GUARD_THREAT_MODEL.md |
| Eval batch, repetitions and matrix Evaluation | stable | Every cell gets its own machine and is kept whole. A bounded request returns the runs. crates/aiec-api/src/evaluations.rs; sdk/python/agentforge/evals.py |
| Suite expansion and baseline-versus-candidate compare Evaluation | alpha | Counts and measurements over the same runs. No pass rate dressed up as a score, and no percentiles invented from a handful of samples. evaluations/omp-regression.json; sdk/python/agentforge/evals.py → Comparison |
| Run Capsules and trajectories Evaluation | planned | Not implemented. Do not advertise as shipped. docs/ROADMAP.md |
| Python SDK Interfaces | stable | Known gap: `run_cells` chunking is unimplemented because changing it breaks the `#[tool]` macro boundary. sdk/python/agentforge; scripts/check-sdk-contract.py |
| Rust client and CLI Interfaces | stable | JSON output, so anything pipes into jq. crates/aiec-client; crates/aiec-cli |
| Local MCP server Interfaces | alpha | Exposes the same lifecycle as tools. The owned-sandbox listing is bounded and prunes finished machines. docs/MCP.md; crates/aiec-mcp (a Rust binary, not part of the Python SDK) |
| `aiec doctor` Interfaces | alpha | Reports OS, runtime, bubblewrap, Docker, KVM, database configuration and the Firecracker binary, kernel, guest artifact and wire protocol. It REPORTS; it does not refuse to start. crates/aiec-cli/src/main.rs → doctor |
| Tenant-scoped API keys with scopes Tenancy | alpha | Keys are stored hashed and compared in constant time. Granting scopes and revoking keys both require the caller to hold the authority being granted or destroyed. API may change before 1.0. crates/aiec-api/src/lib.rs (the /v1/keys routes); crates/aiec-api/tests/routes.rs |
| Per-tenant usage accounting and Prometheus export Tenancy | alpha | Usage events are append-only and idempotent, so retries do not double-count. the GET /v1/usage route in crates/aiec-api/src/lib.rs; the Prometheus exporter in crates/aiec-api |
| Aggregate per-tenant snapshot and persistent-storage byte quotas Tenancy | planned | Per-request size ceilings exist. Aggregate byte quotas do not. docs/known-defects.md |
The evidence column names the file and symbol that implements each capability. If a row looks wrong, that file is where to check it.
Designed but not built
These are the capabilities whose status is planned. They are not available, not configurable, and not imminent. They are here so the design is reviewable before anyone depends on it.
- Aggregate byte quotas across snapshots and persistent storage. CPU and memory are enforced today. A storage ceiling is a design decision about retention, not a counter.
- Layer 7 governed traffic. Guard filters by destination at the network layer. Understanding an allowed HTTPS request is a different problem with a different failure mode.
- Run Capsules — the ability to capture a sandbox and resume it later in a materially different way.
Deliberately out of scope
A hosted AIec
There is no managed service and no sign-up. Capacity comes from the hosts you run. This is a self-hosted product and its distribution is the source code.
Moving your work to a cloud provider
When every local worker is at capacity, AIec refuses the placement. It does not quietly spill a workload somewhere else, because a silent change of isolation boundary and jurisdiction is not a reasonable default.