-
Notifications
You must be signed in to change notification settings - Fork 0
Roadmap
Milestones are intentionally scoped so each one ships working, testable software on its own. See ROADMAP.md in the repository for the authoritative version with full milestone details.
v1.6.0 is released and stable. All milestones v0.1 through v1.6.0 are shipped — including the four-phase post-v1.5 hardening effort (code review fixes, token optimisation, usage skill, docs overhaul) that shipped as v1.6.0.
Stdio transport, circuit breaker, retry engine, structured logging, correlation IDs.
Tools: get_system_status, list_interfaces, create_vlan, manage_ip_address.
HTTP/SSE transport. Tools: list_dhcp_leases, list_routes, manage_route, list_firewall_rules, manage_firewall_rule.
SSH adapter. Tools: run_command, ping, traceroute, torch, get_log, get_system_clock, set_system_clock, reboot.
Bridge, WiFi/Wireless, WireGuard, DNS tools. Infrastructure fixes: boolean normalization, ZodError mapping, circuit breaker scope, YAML config validation.
Tools: list_mangle_rules, manage_mangle_rule, list_address_list_entries, manage_address_list_entry, list_routing_rules, manage_routing_rule, list_routing_tables, manage_routing_table, list_bgp_peers, list_ospf_neighbors.
Tools: list_scripts, manage_script, run_script, list_scheduled_jobs, manage_scheduled_job, list_packages, manage_package, list_files, get_file_content, upload_file, list_containers, manage_container.
HTTP bearer token auth (bcrypt), RBAC per-identity allowedRouters / allowedToolPatterns, dual-sink audit log (pino + NDJSON), two-step HMAC confirmation gate for destructive tools, SSH/FTP credential encapsulation.
Snapshot engine, before/after diff normalization, append-only write journal, maintenance-window guardrails.
Tools: plan_changes, apply_plan, rollback_change.
IPSec, Certificates, Users, DHCP Servers & Pools, Queues/QoS, VRRP, SNMP, NTP, Netwatch, Discovery & ARP.
Tools: check_router_health, bulk_execute.
mikromcp init setup wizard, mikromcp doctor health checker, mikromcp update self-update, npm package, multi-arch Docker images and standalone binaries, Streamable HTTP transport, stability policy, security docs.
Retry engine honours MikroMCPError.recoverability; circuit breaker half-open single-probe gate; apply_plan real duration + circuit breaker for sub-steps.
Security: secret redaction in audit/journal, rate-limiter memory fix, REST client eviction on auth failure, dotenv audit-path fix.
Operability: /healthz probe, /metrics Prometheus endpoint, snapshot retention pruning, async file I/O.
Orchestration: fleet-confirmed destructive bulk_execute, expanded rollback semantic keys, bulk_execute audit trail.
Config: version from package.json, mikromcp init allow-all fix, pagination config removed.
New tools: manage_vlan (full VLAN lifecycle, replaces create_vlan), list_ip_pools/manage_ip_pool (renamed from list_dhcp_pools/manage_dhcp_pool), manage_dhcp_lease (make-static / remove, MAC-keyed idempotency), list_dhcp_clients/manage_dhcp_client (DHCP client configuration per interface), list_ip_services/manage_ip_service (view and toggle RouterOS IP services without port changes).
Improvements: list_dhcp_leases gains leaseType filter; list_dhcp_servers gains offset pagination parameter.
list_pppoe_clients, manage_pppoe_client — PPPoE client management (add/update/remove, idempotent, no_change guard on update).
list_ovpn_clients, manage_ovpn_client — OpenVPN client management (add/update/remove, idempotent, certificate references).
get_ovpn_server, manage_ovpn_server — OpenVPN server singleton (read config; enable/disable/set; idempotent).
list_user_groups, manage_user_group — local user group management with policy bitmask.
get_upgrade_status, manage_upgrade — RouterOS upgrade check and install.
create_backup, export_config — binary backup and text config export.
list_log_rules, manage_log_rule, list_log_actions, manage_log_action — system logging configuration.
manage_ntp_client — NTP client configuration (complements get_ntp_settings).
get_container_config, manage_container_config — global container settings (registry, RAM, veth).
list_container_envs, manage_container_env — container environment variables.
list_container_mounts, manage_container_mount — container volume mounts.
bandwidth_test, fetch_url, list_connections — network diagnostic tools.
list_interface_lists, manage_interface_list, manage_interface_list_member — interface list management.
list_ppp_profiles, manage_ppp_profile — PPP profile management.
delete_file — delete router filesystem files.
manage_dns_settings — write DNS upstream servers, cache TTL, and allow-remote-requests.
manage_ipsec_policy, manage_wireguard_interface — IPSec policy and WireGuard interface management.
A focused four-phase effort completed after v1.5 and released as v1.6.0:
Phase 1 — Code Review Hardening: Three bug fixes (audit redaction recursion, firewall idempotency address/protocol comparison, bulk_execute snapshot/journal on dry-run paths) and three refactors (shared paginate and toolError helpers; side-effect-free circuit breaker state getter).
Phase 2 — Token & UX Optimisation: Tool manifest trimmed ~14% in token count; routerId made optional when MIKROMCP_DEFAULT_ROUTER is set or only one router is configured; list tools deduplicate output by .id.
Phase 3 — MikroMCP Usage Skill: skills/mikromcp/ — a Claude Code skill that guides LLMs in tool selection and safe workflows (dry-run → confirm → apply). mikromcp init and mikromcp doctor register the skill automatically. MCP server instructions field populated for clients that surface server hints.
Phase 4 — Docs & Wiki Accuracy/Consistency Overhaul: Full audit of all wiki pages against the live tool set (117 tools, v1.5.0). Stale counts and version strings corrected; ROADMAP.md milestone ordering fixed; cross-file consistency enforced across README, wiki, and CHANGELOG.
- Each milestone ships working tools. No half-finished features held open across versions.
- Idempotency first. Every write tool checks existing state before acting.
- Dry-run on all write tools. No exception.
- Read-only before write. New subsystems get list/read tools in one version, write tools in the next if needed.
-
run_commandis a last resort. Dedicated tools are always preferred;run_commandexists for gaps, not for replacing proper tool coverage.