Future directions

Candidate capabilities and components beyond the current roadmap

OpenSASE is planned as two complementary halves:

  1. The SASE edge — a policy-driven TLS-inspection appliance for teams and servers (tracked on the Roadmap).
  2. The home appliance — installed at home like Pi-hole, with every device (phone, laptop, TV) routed through it. Above DNS blocking it adds: visibility (per-device activity), control (block/splice/bump per device and category), and malware + DLP verdicts on decrypted traffic.

Constraints for the second half: lightweight-first, containerized everything. Components must run on a Pi 5 / N100 mini-PC adjacent to the existing four containers; anything heavier is parked (GPU/ML section below). Modularity is a deployment property: compose profiles (#29) make the bare-minimum decrypt edge (dnsmasq + openvpn + mitmproxy) installable alone, with scanner, DNS-policy, agent-inspection, and chat modules as opt-ins.

Each section links its tracking issue; sequencing is dependency-driven (no dates), and the board carries Area/Target per card.

Home appliance: per-device policy + visibility

Devices are identified by their VPN client certificate CN; nix run .#vpn-getclient already produces per-device profiles — policy reads the CN. Passlist / bumplist decisions gain an optional device dimension: per-device category rules and schedules (e.g. a device restricted from selected categories during stated hours) while other devices splice by default. A dashboard rides the #16 metrics/export work: verdict counts per device, top domains, blocked events. The trust bootstrap (installing the appliance CA on client devices, with per-device splice-only opt-out) is specified as a documentation deliverable, not left implicit.

→ #19 · depends on #8 (arm64 images — the Pi 5 is arm64), #15, #16

Agent traffic: MCP as a policy category

Agents ride your VPN and call MCP servers. The protocol makes this inspectable: the remote transport is Streamable HTTP (JSON-RPC over HTTP POST, optional SSE), and spec drafts add request-metadata headers (Mcp-Method, Mcp-Name) so intermediaries can inspect without parsing payloads. So a tool call is just another HTTP category: passlist trusted servers (splice), bump untrusted ones and scan tool arguments and tool responses for prompt-injection shapes and credential leakage, logging every tools/call into the decision log with the tool name.

The OpenSASE angle: MCP gateways (ContextForge, agentgateway, ToolHive, Docker MCP Gateway — solid, containerized projects) enforce inside their deployment; an agent that bypasses its gateway still rides this network. Gateway + network-edge inspection are layers of one design, not competitors. Patterns seeded from the inspection proxies’ published taxonomies (MCPProxy’s schema quarantine, Pipelock’s 48-credential / 25-injection pattern reference). Limits stated plainly: stdio transports never touch the network; mTLS’d servers can be spliced or blocked, not read.

→ #20 · LLM provider egress (per-device authorization + counters, deliberately without a full AI gateway) is #21

QUIC / HTTP-3: keep decrypt-and-block honest

Browsers race to QUIC; an inspection edge that ignores UDP/443 leaks policy (same class of leak as IPv6 bypass, #13). Two stages: fail-closed first (block UDP/443, steer clients back to H2 via DNS HTTPS records — config-only), then real interception: mitmproxy 11 already ships full HTTP/3 support (aioquic-based), with the known caveat that Chrome distrusts private CAs for QUIC (bump path wants a publicly trusted cert; splice is unaffected).

→ #22

Short-lived device identity (step-ca)

The architectural answer to certificate renewal: step-ca (Smallstep, Apache-2.0, its own container) issues 24-hour device certs that renew themselves at two-thirds lifetime. Rotation stops being an event — the failure mode behind issue #3 largely disappears, revocation becomes expiration, phones re-enroll silently. Mixed-mode with the existing easy-rsa PKI documented; expiry checks become trivial.

→ #23 · complements #11

DNS-layer policy

Verdicts start at name resolution: dnsmasq (already in-stack) gains RPZ zones from the same category philosophy, per-device sinkholing, and DNS query logging joined into the decision log — device attribution begins before TLS. Feeds reuse the signed-feed design from #14.

→ #25

DLP verdicts: LEAK_BLOCK joins INFECTED

The malware verdict generalizes into a verdict family: the bump path scans egress for secret/credential patterns; positive verdict blocks and logs LEAK_BLOCK exactly like INFECTED. Detector rules from MIT-licensed gitleaks rule sets (rules-as-data); feeds slot into #14’s signed format.

→ #26

Chat on the edge: Prosody XMPP (limits stated)

The chat server runs on the appliance: Prosody (MIT, Lua, minimal runtime footprint). An inspection component attaches via XEP-0114 (external component protocol) and, where moderation requires it, XEP-0356 Privileged Entity: metadata logging, MUC (XEP-0045) moderation, and account-level spam filters — all emitted as decision-log verdicts.

The headline capability: file-transfer scanning. Attachments sent via the chat server’s http.upload (XEP-0363) traverse the same bump + ClamAV verdict path as any HTTPS egress — chat attachments receive INFECTED / LEAK_BLOCK verdicts under the same policy.

Hard limits, stated up front: OMEMO (XEP-0384) end-to-end encryption makes message content invisible to any server-side component by design — that is the spec’s own threat model. Observable: metadata (from/to, timestamps, MUC rooms), unencrypted fallback traffic, and file transfers — never OMEMO content. TLS-bumping third-party providers’ XMPP is operationally untenable (certificate trust) and out of scope.

→ #27

Deferred: identity-aware access (ZTNA-lite) and GPU/ML

Two directions deliberately trail the lightweight stack:

  • ZTNA-lite — publish internal services behind per-identity policy (the VPN client certificate is the identity; lean variant is a mitmproxy addon, full variant is Pomerium). Gated on the appliance basics (#19, #23). → #24
  • GPU/ML module — semantic DLP, prompt-injection classifiers, a local LLM verdict engine for suspicious payloads. Requires accelerator hardware and a licensing decision (the Python ML stack is Apache-2.0-heavy; in-process imports are GPLv2-incompatible — all model-backed components ship as separate containers). → #28

Post-quantum ciphers (scheduled last)

A deliberate sequencing choice: survey every crypto hop (OpenVPN control channel via TLS 1.3/OpenSSL ML-KEM hybrids, data-channel cipher posture, mitmproxy and QUIC TLS termination) and produce a position statement plus experiment plan. No implementation before the lightweight roadmap is stable.

→ #30

Licensing constraints (apply to all sections)

OpenSASE’s own code imports only MIT/BSD/LGPL/GPL-2-family code — Apache-2.0 is never imported in-process (GPLv2-incompatible). Apache-2.0, GPL-3, and AGPL components ship as separate containers, never vendored. The release pipeline’s SBOMs will carry per-component license fields (see the #7 acceptance criteria) so this stays auditable as the component list grows. Nix satisfies GPL source-offer structurally: every shipped binary builds from the public flake.