---
title: "Experimental & Roadmap"
description: "Features under development or not yet production-ready"
url: "https://tslink.md/docs/experimental-roadmap"
locale: "en"
product_version: "0.1.1"
source: "https://github.com/anydoor7/tslink/blob/v0.1.1/docs/roadmap.md"
---

> Documentation index: https://tslink.md/llms.txt · Installed binary is authoritative: `tslink manifest`.

The remaining areas below are roadmap directions, not runtime packages or registry settings that can be enabled. Use the CLI and optional tailnet-only scoped MCP for shipped management.

## Shipped access workflows and remaining plans

[Guest links](https://tslink.md/docs/guest-links.md), [per-host portal, requests and QR](https://tslink.md/docs/portal-requests.md), [MCP roles and receipts](https://tslink.md/docs/mcp-scopes.md), [access history](https://tslink.md/docs/access-history.md) and [flexible durations](https://tslink.md/docs/durations.md) are shipped. Multi-host inventory remains planned. Health/upload limits do not implement requests-per-second middleware.

## Middleware

### Overview

Configurable rate limiting, Basic Auth, IP allow lists, and CORS are not implemented. The `middleware` registry key has been removed. It is rejected with `unknown_config_key` even when its value is `{}`. The shipped HTTP `--allow` filter still applies to proxy/file services; raw TCP uses tailnet policy and target authentication.

### Registry Configuration

This is a rejected legacy example, kept to help identify configuration that needs migration. Remove the entire `middleware` key:

```json
{
  "middleware": {
    "rate_limit": 100
  }
}
```

Strict registry mutation commands reject the key. The daemon skips invalid service entries while continuing healthy entries; a reload that makes a public Funnel service invalid closes its public listener. Check `tslink registry check --json` and diagnostics before retrying.

## Docker Auto-Discovery

### Overview

Docker label discovery is not implemented, and the current TSLink has no Docker discovery package. Labels such as `tslink.enable` do not register services. Register container-backed services explicitly with `tslink add` using the backend's reachable host and port.

### FAQ

* **Does TSLink need access to the Docker socket?** No shipped flow uses it. A future discovery implementation would need its own access and authorization design.

## Cluster Support

### Overview

Cluster synchronization is not implemented. There is no cluster package, peer transport, membership model, or shared-registry protocol. Each installation manages its local registry; do not treat separate TSLink instances as a synchronized cluster.

### FAQ

* **Can I run multiple TSLink instances?** Separate installations can manage their own services, but cluster synchronization is roadmap/experimental. See the TSLink multi-machine documentation for local ownership limits.
* **What happens if a cluster node goes down?** No cluster failover contract exists in the current TSLink.

## Admin Dashboard & REST API

### Overview

No admin dashboard or REST handler is shipped. The optional tailnet-only MCP control plane (`tslink serve --mcp`) is the remote management surface and requires explicit owner entries or scoped bindings. Use the CLI with `--json` or [MCP](https://tslink.md/docs/mcp-server.md#remote-mcp-control-plane) for shipped automation.

### FAQ

* **Is there a web dashboard?** There is a shipped private per-host app portal with request forms. An admin management dashboard/REST API remains planned. TSLink Web is the documentation site.
* **Can I manage services via REST API?** No shipped admin REST API exists; dashboard/REST work remains roadmap/experimental.

## Custom Domains & ACME

### Overview

Custom-domain TLS and ACME are not implemented. There are no `--domain` / `--acme-email` flags or accepted `domain` / `acme_email` registry fields. CLI use fails as an unknown flag; old registry keys fail with `unknown_config_key`, even when empty. Delete those keys and use the default `<service>.<tailnet>.ts.net` hostname.

## Prometheus Metrics

### Overview

Prometheus support is not implemented. The current TSLink has neither HTTP metrics instrumentation nor a `/metrics` scrape endpoint. Use [daemon logs](https://tslink.md/docs/daemon.md#structured-logging) and CLI diagnostics for available evidence.

## Roadmap Configuration Fields

| Area                    | Status                                                                                    |
| ----------------------- | ----------------------------------------------------------------------------------------- |
| `middleware`            | Removed registry key; all values, including `{}`, are rejected with `unknown_config_key`. |
| Docker labels           | Not implemented; labels do not register services.                                         |
| Prometheus `/metrics`   | No instrumentation or scrape endpoint.                                                    |
| `domain` / `acme_email` | Removed registry keys; even empty values are rejected with `unknown_config_key`.          |

## Roadmap Commands

| Area                 | Status                                                                       |
| -------------------- | ---------------------------------------------------------------------------- |
| Middleware           | Not implemented; HTTP `--allow` remains available for proxy/file services.   |
| Docker Integration   | Not implemented; register container-backed services explicitly.              |
| Admin REST API       | No handler; use CLI `--json` or the optional tailnet-only MCP control plane. |
| Custom domain / ACME | Not implemented; no CLI flags or registry fields.                            |
| Cluster sync         | Not implemented; installations have separate local registries.               |
