In this section
Product / explicit boundaries

Roadmap

The roadmap describes capability boundaries and acceptance targets, not delivery dates. A feature moves to available only when its contract, failure behavior, and relevant acceptance path are documented and tested.

Status definitions

StatusMeaning
AvailableUsable in the current alpha with a documented contract and acceptance path.
In developmentActively being hardened or expanded; expect compatibility work and contract review.
PlannedDirection accepted, but implementation has not started or is not committed.
DeferredIntentionally out of the current product boundary.

Available today

Current platform scope. The available implementation is Linux-only. macOS support is planned and is not part of the current contract.

In development

Track 01

Daemonless lifecycle

Expand signal and authorization acceptance beyond the available NixOS path across supported distributions.

Track 02

Proxy compatibility

The same real-eBPF suite covers current and Linux 6.6 LTS kernels. Expand it across distributions, libc behavior, socket APIs, and process-tree edge cases.

Track 03

Agent event evidence

Expand beyond the available bounded, recoverable, provenance-linked HTTP/1 evidence only where new parsers remain conservative and directly usable with Linux tools.

Track 04

TLS boundaries

Relay mode preserves ALPN and SNI, supports long-lived streams, and reports trust and upstream client-authentication failures without claiming pinning or client-certificate mTLS support.

Track 05

Performance and observability

Low-cardinality run summaries and repeatable current/6.6 LTS real-eBPF latency, RSS, event-integrity, 1/10/50 concurrency, and sustained TCP/UDP/capture throughput baselines are available. The distribution matrix remains active work.

Track 06

Release artifact hygiene and native ARM

Strip embedded eBPF DWARF and remapped build paths while preserving BTF, enforce binary-hygiene package gates, and add native aarch64 current/LTS real-eBPF acceptance.

Planned

Planned

macOS backend and fallback

Add a bounded proxy wrapper first, then a signed Network Extension path using NETransparentProxyProvider. Preserve explicit capability differences until command scope, DNS, UDP, QUIC, and TLS acceptance are proven.

Deferred boundaries

Heimdall is not a cluster controller, replacement VPN, desktop traffic dashboard, host-wide always-on system proxy, or universal TLS decryption layer. These are deliberate exclusions that keep the command wrapper reliable and inspectable.

How to influence the roadmap. Open an issue with a minimal command, configuration, kernel/runtime details, and the output of heimdall agent. Discuss the boundary and acceptance criteria before opening a pull request.