Roadmap
What's built, what's next, and where tenantplane is headed.
tenantplane is in early development. This roadmap reflects the direction; it is not a commitment to dates or ordering.
Built today
- Custom resources:
TenantCluster,IsolationProfile,SyncPolicy,SyncDecision. - Controller that reconciles a shared-mode k3s control plane (StatefulSet +
headless Service) in a dedicated control-plane namespace, separate from
tenant workloads, so Pod Security is enforced at the profile’s real
declared level (including
restricted). - Isolation enforcement: default-deny NetworkPolicy, ResourceQuota, LimitRange, Pod Security Admission labels, and runtimeClassName/apiFairness enforced by both the sync engine and a ValidatingAdmissionPolicy backstop (Kubernetes 1.30+).
- Tenant kubeconfig extraction into a host Secret.
- Full sync engine:
toHost,fromHost, andbidirectionaldirections, all with orphan garbage collection;bidirectionalhonorsconflictPolicy(manual,tenant-wins,host-wins), and — whenexplain.recordDecisionsis set — tells a one-sided drift from a genuine two-sided conflict using a persisted convergence history, instead of only comparing current state. - Sync decisions recorded as Kubernetes Events and, when
explain.recordDecisionsis set, in a durable, queryableSyncDecisionobject per tenant (capped byexplain.retain). driftDetection.intervalsets the sync/reconcile cadence — every SyncPolicy setting is now honored end to end.- Controller RBAC narrowed to the namespaces it actually manages, with the same ValidatingAdmissionPolicy backstop pattern hardening it further.
kubernetesVersionselects an actual k3s image (v1.28-v1.33); anything else is rejected at admission rather than silently defaulted.- Multi-replica HA control planes (
replicas1-5) backed by a dedicated etcd StatefulSet per tenant. etcd members address each other by stable per-pod DNS rather than pod IPs, so a rescheduled replica rejoins instead of being permanently orphaned. - CLI: resource rendering and offline
explain-sync. - Managed Kubernetes support (EKS, AKS, GKE): storage class selection, LoadBalancer exposure with cloud annotations, extra TLS SANs.
Next
- External / shared datastores —
postgres, and pointing a tenant at an etcd cluster it does not own. - TLS between k3s and etcd — the per-tenant etcd currently listens on plain HTTP inside the tenant’s own control-plane namespace, relying on namespace isolation rather than transport encryption.
Later
- OpenTelemetry tracing and Prometheus metrics.
dedicatedandprivateisolation modes.- Migration workflows across isolation models without recreating tenant state.
- GitOps workflows and high-density ephemeral tenant provisioning.
- Tenant lifecycle: upgrades and safe teardown.
Get involved
Contributions are welcome across Kubernetes controllers, networking, security, observability, docs, and testing. Open an issue or a pull request on GitHub.
Found a gap? Open an issue or PR.