Releases: fmind-ai/fgentic
Release list
v0.1.1
[0.1.1] - 2026-07-29
🚀 Features
- (mise) Add cluster:overrides task + document gate sequencing for agents
- (bridge) Add durable delegation recovery (#395)
- (federation) Add constrained laptop profile (#399)
- (postgres) Add permission-aware knowledge store (#413)
- (infra) Add vetted MCP catalog (#415)
- (bridge) Add actionable failure notices (#417)
- (bridge) Add in-room agent gallery (#422)
- (models) Add governed model catalog (#420)
- (bridge) Add plaintext command fallback (#428)
- (bridge) Add guided room welcome (#432)
- (infra) Scaffold governed agents (#433)
- (bridge) Stage model classification signal (#435)
- (matrix) Add finite retention policy pack (#441)
- (bridge) Record reply quality reactions (#440)
- (matrix) Define snapshot-backed media storage (#437)
- (matrix) Add opt-in Ketesa admin console (#444)
- (agents) Audit version in effect (#438)
- (agentgateway) Enforce MCP tool quotas (#445)
- (bridge) Add delayed task dead-man switch (#443)
- (knowledge) Add sovereign ingestion pipeline (#486)
- (federation) Sign cross-org usage receipts (#446)
- (knowledge) Add incremental Git/Markdown connector (#492)
- (federation) Add partner onboarding conformance preflight (#351) (#539)
- (models) Add sovereign embeddings + reranker runtime (#540)
- (bridge) Scan agent replies for leaked secrets before room post (#541)
- (eval) Add sovereign LLM-as-judge scoring lane (#547)
- (bridge) Persist interactive task controls (#577)
- (activitypub) Negotiate outbound signature profiles (#610)
- (bridge) Govern conversation memory (#723)
- (observability) Add opt-in synthetic delegation canary (#912)
- (observability) Opt-in sovereign alert delivery to Matrix (#456) (#914)
- (federation) Partner trust registry — single validated source of truth (#349) (#915)
- (federation) Cross-org break-glass containment + evidence pack + abuse intake (#350) (#916)
- (federation) Signed bilateral agreement as the enforcement source (#353) (#917)
- (federation) Time-bounded partner trust — review windows + expiry gate + alert (#463) (#918)
- (bridge) Multi-JWK AgentCard verification for zero-downtime key rotation (part of #352) (#920)
- (agents) Mise run agent:test — offline single-agent golden pre-PR loop (#372) (#921)
- (identity) Wire Keycloak→MAS OIDC backchannel logout (#278) (#922)
- (audit) Content-bounded Synapse/MAS audit projectors + closed schemas (Part of #418) (#930)
- (audit) Closed fgentic.admin_action.v1 record schema + contract (Part of #455) (#931)
- (audit) Cursor + dedup reconciliation for the audit collector (Part of #418) (#932)
- (audit) Read-only collector roles with column-level grants (Part of #418) (#933)
- (audit) Pinned source queries + collector orchestration (Part of #418) (#934)
- (audit) Crash-safe collector cycle orchestration (Part of #418) (#935)
- (bridge) Verify AgentCard overlap set + revocation in sign-agent-card tool (#939)
- (audit) Content-bounded admin-action projector + collector offline core (Part of #455) (#940)
- (federation) Model AgentCard key-rotation overlap + revocation in the trust registry (part of #352) (#941)
- (federation) Serve + prove AgentCard key-rotation overlap window in the fed lab (part of #352) (#942)
- (activitypub) Reconcile AP gateway on demo profile (offline infra; runtime interop proof pending) (#938)
- (bridge) Per-room token budgets with in-room feedback (#947)
- (group-sync) GitOps IdP-group to managed Matrix room reconciler (offline core) (#948)
- (scripts) Ownership-guarded agent-retire cleanup script (Part of #453) (#951)
- (identity) Break-glass administration offline core (Part of #467) (#952)
- (release) Adopter BOM + drift-verify gate, upgrade-notes convention, support statement (Part of #188) (#953)
- (airgap) BOM-driven artifact mirror + fully-qualified image refs + disconnected-install docs (Part of #457) (#954)
- (federation) Route pinned fediverse handles (#960)
- (bridge) Versioned ai.fgentic.a2a result metadata on terminal agent notices + joint-ops blueprint (Part of #167) (#965)
- (bridge) Bind agents to exact managed rooms (#693)
- (agentgateway) Classification-aware model residency enforcement, fail-closed (Part of #339) (#982)
- (evaluation) Citation-faithfulness check over the sovereign judge lane, fail-closed (Part of #358) (#992)
- (moderation) Opt-in Draupnir policy-list moderation component + docs (Part of #136) (#996)
- (knowledge) Add typed retrieval identity carrier (#1538)
- (knowledge) Add permission-aware retrieval service (#1545)
- (knowledge) Add retrieval identity projector (#1549)
- (knowledge) Add retrieval gateway boundary (#1550)
- (knowledge) Enforce retrieval delivery boundary (#1551)
- (identity) Add offboarding reconciler (#1552)
- (bridge) Gate consequential tools with room approval (#1553)
🐛 Bug Fixes
- (demo) Fit constrained laptop resources (#330)
- (k3d) Stop failed network policy reconciliation (#388)
- (ci) Serialize app toolchain installs (#394)
- (gke) Grant agentgateway Vertex access (#402)
- (a2a) Bind local clients to configured routes (#410)
- (docs) Remove stale roadmap ceiling (#421)
- (bridge) Avoid locking remote round trips (#424)
- (infra) Recover interrupted cluster teardown (#423)
- (tasks) Make check:terraform hermetic against a poisoned backend cache (#545)
- (models) Bind rollouts to snapshot pins (#555)
- (observability) Scrape sovereign model runtimes (#557)
- (identity) Fail-close Keycloak namespace (#564)
- (security) Fail-close admin namespace (#567)
- (observability) Scrape Keycloak metrics (#569)
- (observability) Order Keycloak after monitor CRDs (#572)
- (gateway) Restrict route namespace delegation (#574)
- (observability) Order OTel after monitor CRDs (#576)
- (observability) Order gateway after tracing backend (#582)
- (models) Restrict model scrape peers (#590)
- (kagent) Remove unused monitoring access (#593)
- (agentgateway) Bind metrics scrape peer (#597)
- (kagent) Restrict managed-agent egress peers (#600)
- (observability) Restrict OTLP producer peers (#602)
- (flux) Scope observability DAG edges by profile (#609)
- (observability) Restrict Grafana ingress (#619)
- (observability) Isolate metrics control APIs (#623)
- (activitypub) Block private federation fetches (#620)
- (observability) Restrict kube-state-metrics ingress (#626)
- (postgres) Restrict CNPG instance ingress (#630)
- (cert-manager) Isolate controller metrics ingress (#633)
- (gateway) Isolate Traefik internal ingress (#636)
- (cnpg) Isolate operator metrics ingress (#639)
- (scripts) Fail closed on validation producers (#642)
- (activitypub) Require fresh bound inbound signatures (#645)
- (cert-manager) Isolate webhook metrics (#644)
- (scripts) Fail closed on Trivy cleanup inventory (#646)
- (scripts) Validate check producer status (#650)
- (scripts) Validate federation producer status (#652)
- (scripts) Validate federation helper producers (#656)
- (scripts) Validate demo secret producers (#658)
- (flux) Bind metrics ingress to Prometheus (#657)
- (scripts) Validate demo federation producers (#660)
- (kagent) Bind ingress to exact callers (#661)
- (scripts) Validate demo cluster producers (#665)
- (terraform) Validate authorized IPv4 CIDRs (#667)
- (terraform) Compose admin console DNS (#670)
- (terraform) Validate GKE location (#672)
- (terraform) Scope Cloud DNS API (#676)
- (terraform) Order Cloud DNS setup (#679)
- (terraform) Grant GKE node role (#682)
- (terraform) Enforce backup retention horizon (#685)
- (terraform) Pin state recovery window (#688)
- (terraform) Enable managed-zone DNSSEC (#691)
- (terraform) Protect managed DNS zone (#695)
- (terraform) Enable bounded VPC flow logs (#698)
- (terraform) Validate GKE node count (#701)
- (terraform) Bound GKE authorized network ranges (#704)
- (docs) Reject navigation drift (#707)
- (terraform) Keep GKE workload logs local (#708)
- (terraform) Bound GKE authorized network list (#710)
- (terraform) Label GKE reference cluster (#713)
- (terraform) Validate GKE cluster names (#715)
- (terraform) Validate composed VPC names (#719)
- (terraform) Block service external IPs (#722)
- (ci) Include root integration contract (#726)
- (terraform) Keep workload metrics sovereign (#727)
- (terraform) Disable legacy GKE auth (#731)
- (terraform) Validate GCP project IDs (#734)
- (terraform) Validate bootstrap project IDs (#738)
- (terraform) Validate Cloud DNS zone names (#741)
- (terraform) Scope Cloud NAT egress (#744)
- (terraform) Protect backup bucket from destroy (#748)
- (flux) Protect CNPG cluster from prune (#752)
- (observability) Alert on unhealthy CNPG backups (#758)
- (observability) Alert on platform certificate health (#762)
- (observability) Monitor Flux reconciliation (#766)
- (observability) Alert on CNPG degradation (#770)
- (observability) Alert on sustained gateway 5xx (#774)
- (ci) Isolate workflow shell contexts (#778)
- (observability) Alert on sustained vLLM queueing (#779)
- (terraform) Validate GCS bucket names (#783)
- (terraform) Validate platform domain (#786)
- (terraform) Validate GCP locations (#790)
- (terraform) Protect recent backups (#797)
- (observability) Scope Flux error alert (#801)
- (terraform) Validate GKE machine type input (#804)
- (models) Bound demo request bodies (#809)
- (models) Bound demo body read time (#812)
- (models) Bound demo JSON parser errors (#815)
- (models) Enforce strict demo JSON (#818)
- (models) Narrow loader download egress (#822)
- (models) Bound demo request concurrency (#826)
- (ci) Prevent nested NetworkPolicy installs (#828)
- (security) Deny all service external IPs (#830)
- (docs) Update MkDocs Material to 9.7.7 (#846)
- (docs) Reject stale uv lock...
v0.1.0 — Sovereign Agentic Collaboration Platform
Fgentic v0.1.0 — the first public cut of a sovereign, open-standard platform where humans and AI agents share Matrix rooms and @mention to delegate tasks over A2A to Kubernetes-native kagent agents, governed by agentgateway and delivered by Flux GitOps. Self-hosted end-to-end, every layer swappable, with a per-cluster choice of model backend and Matrix federation as the cross-organization destination.
⚠️ Status: early / experimental (pre-1.0). Live end-to-end on the local reference cluster, but APIs, manifests, and docs still move between milestones — see the roadmap before depending on it.
What's in this cut
- The core interaction works end-to-end. A Matrix
@mentionin Element produces a real LLM-backed agent reply, through the custom Gomatrix-a2a-bridge→ agentgateway (no agent ever holds a model key) → kagent, with conversation threading, per-sender/per-room rate limits, and sanitized failure replies. - Governed by construction. Local LLM egress flows through a single agentgateway chokepoint with token metering and an LLM spend alert; kagent stays ClusterIP-only behind NetworkPolicy; fail-closed Kubernetes admission policies (approved agent references, no
:latest, PSS retention, service-exposure limits). - Remote & federation groundwork. An explicitly pinned remote agent round-trips only under a verified A2A v1.0 ES256 Signed AgentCard and fails closed after post-signature tampering. A provider-free federation lab (
mise run fed:up) proves cross-org delegation: an org-B client-credentials JWT invokes only org A's signed docs-qa route under anazp-scoped token reservation, with room-v12 policy, server ACLs, and a git-reloadable Synapse callback border. - Observability & supply chain. Prometheus/Grafana with bridge-delegation + GenAI-token metrics; a structurally optional, digest-pinned Trivy runtime-vulnerability layer; a multi-arch distroless bridge image built, scanned, keyless-cosign-signed, SBOM'd, and SLSA-attested by CD.
- Opt-in interop (disabled by default). Digest-pinned mautrix Slack/Telegram GitOps units and an experimental ActivityPub second-federation transport — each gated on explicit acceptance, not a compatibility claim.
Try it in 15 minutes
mise install
mise run demo:up # deterministic, credential-free, no prompt egressThen choose a model boundary (self-hosted vLLM, EU API, or hyperscaler) — see the provider contract.
Learn more
- Docs (specification by topic): architecture · design decisions D1–D16 · security · federation
- Contributing: CONTRIBUTING.md (issues, labels, DCO) — the milestones are the backlog.
License
Apache-2.0. The bridge embeds mautrix/go (MPL-2.0); attribution ships in NOTICE.