OSVauco/project/roadmap.md

1.6 KiB

OSVx Project Roadmap

This document tracks the high-level goals and future development milestones for the OSVx platform.

Phase 0: TYR Policy Engine

  • Scaffold TYR repo structure.
  • Commit & deploy initial default-deny policy bundle.

Phase 1: TYR Service Identity (SPIFFE/SVID)

  • Deploy step-ca
  • Bootstrap SPIRE
  • Establish Binary Authorization Infrastructure

Phase 2: Network Hardening & Perimeter Defense

  • Establish GCP VPC Service Controls (VPC-SC) perimeter.
  • Configure Private Service Connect (PSC) for all Google APIs.
  • Deploy Cloud Armor WAF policy.
  • Enforce IAP-only SSH and restrict Cloud Run ingress.

Phase 3: Runtime Enforcers & Workload Security

  • Draft Gatekeeper container security policy.
  • Secure Ollama model inference behind mTLS via SPIRE SVIDs.
  • Audit and sandbox execution environments using eBPF/Falco.

Phase 4: Data, Secret & CMEK Governance

  • Transition secrets to GCP Secret Manager
  • Enforce Customer-Managed Encryption Keys (CMEK) for Artifact Registry, Storage Buckets, and Cloud Run.
  • Configure BigQuery real-time audit log streaming and setup query_tyr_audit MCP tool.

Phase 5: OISSU Loop & Custom MCP Security Tools

  • Build OISSU forecast and anomaly detection tools.
  • Build eval_tyr_identity and get_tyr_user_risk tools.
  • Build attest_tyr_supply_chain tool.
  • Build run_tyr_response tool for automated threat containment.

Phase 6: Continuous Integration & Deployment Security Gates

  • Add cloudbuild security gate configuration.