feat: reflect netOrk v0.4.0 features (MFA, config backup, ack warnings)
Moves MFA/TOTP and config backup & versioning from roadmap to shipped across the NIS2 coverage page, features list, and roadmap, and adds a homepage screenshot row for the new config snapshot/diff/restore UI. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
77a73030b4
commit
2f8cbf48af
+9
-2
@@ -147,6 +147,15 @@ Each badge uses the `Driver / Integration Badge` component from DESIGN.md.
|
||||
agent is missing. Graylog syslog forwarding status with auto-fix.`
|
||||
- Screenshot: SecurityTab inside DeviceDetailPage
|
||||
|
||||
**Row 4 — Right text, left screenshot**
|
||||
- Heading: `Configuration backup and versioning`
|
||||
- Copy: `Every poll captures a config snapshot into a local Git
|
||||
repository. The Config tab shows the full snapshot history, a
|
||||
side-by-side diff between any two points in time, and — for
|
||||
OPNsense — a Restore button. Unauthorized changes show up as a
|
||||
device warning.`
|
||||
- Screenshot: ConfigTab inside DeviceDetailPage
|
||||
|
||||
---
|
||||
|
||||
### Section 5b — NIS2
|
||||
@@ -330,7 +339,6 @@ address NIS2 Art. 21 technical baseline requirements.
|
||||
|
||||
**Planned items (NIS2-tagged):**
|
||||
- CVE tracking per device — NVD / OSV cross-reference
|
||||
- Configuration backup & versioning — git-backed snapshots, change detection
|
||||
- Compliance dashboard — per-site Art. 21 checklist view
|
||||
- Audit log export — PDF / CSV with filters
|
||||
|
||||
@@ -342,7 +350,6 @@ address NIS2 Art. 21 technical baseline requirements.
|
||||
**Under consideration (NIS2-tagged):**
|
||||
- Incident workflow — structured record + NIS2 Art. 23 Fristen-Tracker
|
||||
- EOL tracking — endoflife.date integration for firmware / OS
|
||||
- MFA (TOTP) — second factor for netOrk logins
|
||||
|
||||
**Under consideration (general):**
|
||||
- mDNS scanner — media device discovery
|
||||
|
||||
+13
-1
@@ -68,7 +68,8 @@ hardware and want operational visibility beyond what consumer dashboards offer.
|
||||
9. **NIS2 evidence foundation** — NIS2 Art. 21 mandates asset inventory, patch
|
||||
management, access control, and audit trails. netOrk produces all of these as
|
||||
day-to-day operational outputs: full device inventory, per-device update status,
|
||||
Wazuh CVE tracking, RBAC, config drift detection, and a complete audit log.
|
||||
Wazuh CVE tracking, RBAC with MFA, Git-backed config snapshots with diff/restore,
|
||||
config drift detection, and a complete audit log.
|
||||
|
||||
---
|
||||
|
||||
@@ -120,6 +121,11 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
|
||||
- One-click drift fix stream with live SSH output in the browser
|
||||
- UCI-based config push for OpenWRT (VLAN names, SSID settings, radio config)
|
||||
- AP profile system: country code, HT/VHT mode, 802.11r, NTP, syslog, SSH port
|
||||
- Configuration backup & versioning: every poll captures a config snapshot into
|
||||
a local Git repository, with full history and a side-by-side diff viewer
|
||||
between any two points in time
|
||||
- One-click config restore for OPNsense from any prior snapshot
|
||||
- Unauthorised configuration changes are surfaced as a device warning
|
||||
|
||||
### Scheduled Operations
|
||||
- Scheduled reboots for OpenWRT APs with per-site concurrency lock
|
||||
@@ -130,6 +136,9 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
|
||||
### Monitoring & Health
|
||||
- SNMP health metrics (CPU, memory, interface counters) via `get_health_metrics()`
|
||||
- Per-device warning system with severity levels (error / warning / info)
|
||||
- One-click Ack on any warning — clears it immediately and writes an audit log
|
||||
entry; for config-change warnings the current state is accepted as the new
|
||||
baseline
|
||||
- Docker container and image status (Proxmox/Linux)
|
||||
- Service status and start/stop/restart (systemd)
|
||||
- VM/container list with OS device cross-linking (Proxmox)
|
||||
@@ -148,6 +157,9 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
|
||||
|
||||
### Access Control
|
||||
- JWT authentication with remember-me (localStorage) or session-only (sessionStorage)
|
||||
- Two-factor authentication (MFA/TOTP) — authenticator app at login, backup
|
||||
codes for emergencies, session invalidation on TOTP changes, enforceable
|
||||
per role
|
||||
- RBAC with four built-in roles: viewer / operator / engineer / administrator
|
||||
- Custom roles with any permission combination
|
||||
- Full audit log of all orchestration actions
|
||||
|
||||
Reference in New Issue
Block a user