Active engineering project
Show what works.
Name what does not.
Cix’s roadmap is a phase-by-phase engineering record, not a future-feature checklist. This page describes implemented engineering—not a production-support or general-availability promise.
Boundaries reviewed 15 September 2026
Source revision f4392c86
Evaluation posture Build and test from source
Current foundation
What shipped lives in one place.
The Cix roadmap records each phase as it lands, together with the verification that closed it.
This page does not restate that record. A second copy of a capability list drifts from the first, and a status table that has quietly gone stale is worse than no table: it is read as current. The roadmap carries exact parts, exceptions, and how each was proven.
Read what shipped, and how it was verifiedEvidence model
Four routes to technical truth.
Known boundaries
Read these before evaluating.
Material limits in the current source and operating model. This is not exhaustive; the roadmap and guides at the revision above remain authoritative.
- Authentication bootstrapWrites remain open until a configured admin group has a real member. Once active, POST, PUT, DELETE, and container-console access require an admin session; ordinary GET requests remain open by design. Recovery from lockout requires the installer media and physical or hypervisor console access.
- Fresh-install pathSigned, prebuilt install media is available from Cix Cache; Cix can also build and publish its own media. A seed is needed for an offline first container, and the installation guide records a current outbound-DNS limitation on fresh systems. Evaluate the exact guide before choosing hardware.
- Build-system integrationThe Cix Build System now compiles and parses a real recipe on a Cix host, but cixd does not invoke CBS and no recipe-format discriminator exists yet. Integration remains open in the source project.
- Multi-host coordinationIntentionally not designed yet. The current architecture avoids foreclosing it, but makes no cluster or distributed-systems promise.
- Wireless verificationA real 2.4 GHz access point now runs with its radio inside a container, but client association, over-air DHCP leases, and end-to-end wireless-to-wired traffic are not yet proven. 5 GHz remains dependent on an operator-confirmed country setting.
- Hardware verificationSome positive device paths—particularly real GPU, physical-NIC, and wireless-client scenarios—have narrower verification than emulated and software-only paths.
- Container isolation boundaryThese are Linux namespace containers, not virtual machines. Direct device grants do not provide a VFIO/IOMMU hypervisor isolation boundary.
- Approval gatesPublish, rolling, and host-deploy gates exist for changes that cross their normal blast radius, but default to off. A deployment can wait for its image to be built; this does not imply unattended production delivery.
- Rolling does not mean newestRolling describes the delivery model. It does not claim every component always tracks its latest upstream release.
Last word
Trust the record, not this summary.
The website explains Cix. The repository proves it.
Read the full roadmap