This document outlines the planned future direction and engineering priorities for CloakDB.
- Nested JSON / JSONB Masking (
json_mask): Recursive dot-notation and wildcard path traversal (profile.contact.email,orders[*].card,metadata.*). - Multi-Core Chunk Streaming (
ParallelStreamParser): Bounded-queue parallel streaming with--workers N. - Extended SQL Dialects: MS SQL Server (T-SQL bracketed identifiers,
N'...'unicode literals,IDENTITY_INSERT,GO) and Oracle SQL (REM,PROMPT, quoted identifiers). - Safe AST Expression Evaluator: Elimination of arbitrary code execution vectors in conditional masking.
- Zero-Hardcoded Secrets & Dynamic Salt Generation: Complete elimination of static fallback salts and enforced cryptographically secure random salt initialization.
- Golden Integration Fixture Suite: End-to-end multi-table relational tests.
- Semantic Redaction in Free-Text (
text_redact): In-place unstructured entity redaction for customer notes, support tickets, and chat logs. - Mathematical Privacy Evaluator (
cloakdb evaluate): Formal$k$ -anonymity,$l$ -diversity, and re-identification risk metrics engine. - Referential Data Subsetting (
cloakdb subset): Relational foreign-key graph traversal for proportional staging dataset extraction. - GitHub Actions Step Summaries & PR Annotations: Native
$GITHUB_STEP_SUMMARYand workflow commands. - Pluggable KMS & Secret Vault Providers: Pluggable secret salt and FPE key providers (Env, HashiCorp Vault, AWS KMS).
- Ecosystem Connectors: Native DuckDB connector and Apache Airflow
CloakDBOperator.
- Set up automated GitHub Actions release workflow publishing wheels and sdist packages directly to PyPI with provenance attestations upon git tag creation.
- Native connectors for MongoDB collections and ClickHouse tables for live staging sanitization.