From d57734767d24635a37a5e75c95e95d9eb2da21ea Mon Sep 17 00:00:00 2001 From: Christian Manivong Date: Fri, 17 Jul 2026 07:51:10 +0200 Subject: [PATCH] =?UTF-8?q?feat:=20reflect=20netOrk=20v0.10.0=E2=80=93v0.1?= =?UTF-8?q?1.0=20release=20notes?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Corrects a claim from the previous update: Satellite Phase 3 shipped, so discovery scans now run through satellite-covered sites too (only SNMP health-metric polling and WebSSH remain Central-only). New capabilities added to the feature list: per-device availability windows (suppress false OFFLINE warnings during expected downtime), per-SSID MAC access-control lists with a dedicated Wireless ACL tab, a new RADIUS Management section (global FreeRADIUS server/NAS/user management), and three OPNsense monitoring additions (BGP neighbors, TLS certificate/Trust-store monitoring, DDNS-down warning). Also notes that netOrk's own config pushes are now auto-recognized so they're never mistaken for an unauthorized change. Co-Authored-By: Claude Sonnet 5 --- docs/PAGES.md | 9 +++++---- docs/PRODUCT.md | 35 ++++++++++++++++++++++++++++++++--- src/i18n/translations.ts | 40 ++++++++++++++++++++++++++++++++++++++-- 3 files changed, 75 insertions(+), 9 deletions(-) diff --git a/docs/PAGES.md b/docs/PAGES.md index 646254a..996a65e 100644 --- a/docs/PAGES.md +++ b/docs/PAGES.md @@ -273,10 +273,11 @@ sticky section nav). One section per capability area. 11. Dashboards 12. Security Integrations 13. DNS Management -14. Access Control (RBAC) -15. NetBox Sync -16. Compliance & Audit (NIS2) -17. Developer Experience +14. RADIUS Management +15. Access Control (RBAC) +16. NetBox Sync +17. Compliance & Audit (NIS2) +18. Developer Experience Each section: `text-xl font-semibold text-slate-200` heading + feature items as a clean list with `text-slate-400` body. diff --git a/docs/PRODUCT.md b/docs/PRODUCT.md index 5232812..ab7f459 100644 --- a/docs/PRODUCT.md +++ b/docs/PRODUCT.md @@ -145,6 +145,13 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju - Subnet browser with interface-to-subnet assignments - VLAN list grouped by site; per-VLAN device membership view - SSID management with push to OpenWRT APs via UCI +- Per-SSID MAC access control lists (whitelist / blacklist) pushed to every + AP broadcasting the SSID, quick-add straight from the Connected Clients list +- MAC ACL state is a first-class drift item — covered by the same drift + detection, scheduled auto-fix, and warning aggregation as any other config + drift +- Dedicated Access Control Lists tab on the Wireless page listing every SSID + with its ACL editor inline ### Configuration Management - Config drift detection: desired state (DB) vs device state (poll snapshot) @@ -156,6 +163,9 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju between any two points in time - One-click config restore for OPNsense from any prior snapshot - Unauthorised configuration changes are surfaced as a device warning +- netOrk's own config pushes (drift fixes, ACL provisioning) are recognized + and auto-accepted as the new baseline — never mistaken for an unauthorized + change ### Configuration Automation (Ansible) - Reusable Ansible roles and playbooks stored and edited directly in @@ -194,9 +204,10 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju - Scheduled/on-demand reboots and the SNMP auto-fix flow run through the same command channel whether a device is directly reachable or behind a satellite -- Not yet satellite-covered: discovery scans and SNMP health-metric polling - still run from Central, and WebSSH console access isn't available through - a satellite +- Discovery jobs at a satellite-covered site scan locally through the same + command channel, instead of failing to reach the subnet from Central +- Not yet satellite-covered: SNMP health-metric polling still runs from + Central, and WebSSH console access isn't available through a satellite ### Monitoring & Health - SNMP health metrics (CPU, memory, interface counters) via `get_health_metrics()` @@ -207,6 +218,13 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju - Docker container and image status (Proxmox/Linux) - Service status and start/stop/restart (systemd) - VM/container list with OS device cross-linking (Proxmox) +- Per-device availability windows — suppress OFFLINE status and poll-failure + warnings during expected downtime (e.g. a nightly power-off); opt-in, + unconfigured devices are unaffected +- OPNsense: BGP neighbor status polling and display, with a peer-down warning +- OPNsense: TLS certificate monitoring for the Trust store, with + expiring-soon / expired warnings +- OPNsense: Dynamic DNS service-down warning (os-ddclient) ### Dashboards - Configurable, shareable dashboards — build your own from a widget picker @@ -236,6 +254,17 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju - PTR record provisioning to reverse zones - Pending job queue for zone changes when device is unreachable +### RADIUS Management +- Global FreeRADIUS server, NAS client, and user management — no site + scoping, usable from any site's SSIDs/APs +- Changes push to the device via the driver and are only stored after the + device confirms — avoids drift between netOrk's view and the actual + FreeRADIUS config +- Dedicated server list and detail page (NAS clients / users tabs) under + the Wireless section +- SSID 802.1X integration (auto-provisioning a NAS client from an SSID's + RADIUS server) is a deliberate follow-up, not included yet + ### Access Control - JWT authentication with remember-me (localStorage) or session-only (sessionStorage) - Two-factor authentication (MFA/TOTP) — authenticator app at login, backup diff --git a/src/i18n/translations.ts b/src/i18n/translations.ts index 2fab2bd..1c1ff70 100644 --- a/src/i18n/translations.ts +++ b/src/i18n/translations.ts @@ -156,6 +156,9 @@ const en = { 'Subnet browser with interface-to-subnet assignments', 'VLAN list grouped by site; per-VLAN device membership view', 'SSID management with push to OpenWRT APs via UCI', + 'Per-SSID MAC access control lists (whitelist / blacklist) pushed to every AP broadcasting the SSID, quick-add straight from the Connected Clients list', + 'MAC ACL state is a first-class drift item — covered by the same drift detection, scheduled auto-fix, and warning aggregation as any other config drift', + 'Dedicated Access Control Lists tab on the Wireless page listing every SSID with its ACL editor inline', ], }, { @@ -168,6 +171,7 @@ const en = { 'Configuration backup & versioning: every poll snapshots config into a local Git repo, with full history and a side-by-side diff viewer', 'One-click config restore for OPNsense from any prior snapshot', 'Unauthorized configuration changes are surfaced as a device warning', + 'netOrk\'s own config pushes (drift fixes, ACL provisioning) are recognized and auto-accepted as the new baseline — never mistaken for an unauthorized change', ], }, { @@ -201,7 +205,8 @@ const en = { 'Deployed in one flow via VM provisioning: pick a hypervisor and site, netOrk provisions the VM and installs the satellite container automatically', 'Central automatically skips direct polling for any device at a site with an online, heartbeating satellite — no manual per-site toggling', 'Scheduled/on-demand reboots and the SNMP auto-fix flow run through the same command channel whether a device is directly reachable or behind a satellite', - 'Not yet satellite-covered: discovery scans and SNMP health-metric polling still run from Central, and WebSSH console access isn\'t available through a satellite', + 'Discovery jobs at a satellite-covered site scan locally through the same command channel, instead of failing to reach the subnet from Central', + 'Not yet satellite-covered: SNMP health-metric polling still runs from Central, and WebSSH console access isn\'t available through a satellite', ], }, { @@ -213,6 +218,10 @@ const en = { 'Docker container and image status (Proxmox/Linux)', 'Service status and start/stop/restart (systemd)', 'VM/container list with OS device cross-linking (Proxmox)', + 'Per-device availability windows — suppress OFFLINE status and poll-failure warnings during expected downtime (e.g. a nightly power-off); opt-in, unconfigured devices are unaffected', + 'OPNsense: BGP neighbor status polling and display, with a peer-down warning', + 'OPNsense: TLS certificate monitoring for the Trust store, with expiring-soon / expired warnings', + 'OPNsense: Dynamic DNS service-down warning (os-ddclient)', ], }, { @@ -244,6 +253,15 @@ const en = { 'Pending job queue for zone changes when device is unreachable', ], }, + { + title: 'RADIUS Management', + items: [ + 'Global FreeRADIUS server, NAS client, and user management — no site scoping, usable from any site\'s SSIDs/APs', + 'Changes push to the device via the driver and are only stored after the device confirms — avoids drift between netOrk\'s view and the actual FreeRADIUS config', + 'Dedicated server list and detail page (NAS clients / users tabs) under the Wireless section', + 'SSID 802.1X integration (auto-provisioning a NAS client from an SSID\'s RADIUS server) is a deliberate follow-up, not included yet', + ], + }, { title: 'Access Control (RBAC)', items: [ @@ -516,6 +534,9 @@ const de: Translations = { 'Subnetz-Browser mit Schnittstellen-zu-Subnetz-Zuordnungen', 'VLAN-Liste gruppiert nach Standort; VLAN-Mitgliedsansicht pro Gerät', 'SSID-Verwaltung mit Push auf OpenWRT-APs via UCI', + 'MAC-Zugriffskontrolllisten pro SSID (Whitelist / Blacklist), gepusht auf jeden AP, der die SSID ausstrahlt — Schnell-Hinzufügen direkt aus der Liste der verbundenen Clients', + 'MAC-ACL-Zustand ist ein vollwertiges Drift-Item — abgedeckt von derselben Drift-Erkennung, geplanten Auto-Fixes und Warnungsaggregation wie jeder andere Config-Drift', + 'Eigener Access-Control-Lists-Tab auf der Wireless-Seite, listet jede SSID mit ihrem ACL-Editor inline', ], }, { @@ -528,6 +549,7 @@ const de: Translations = { 'Konfigurationsbackup & -versionierung: bei jedem Poll wird ein Snapshot in ein lokales Git-Repository geschrieben — vollständige Historie und Side-by-Side-Diff-Viewer', 'Ein-Klick-Konfigurations-Restore für OPNsense aus jedem früheren Snapshot', 'Nicht autorisierte Konfigurationsänderungen werden als Gerätewarnung angezeigt', + 'netOrks eigene Config-Pushes (Drift-Fixes, ACL-Provisioning) werden erkannt und automatisch als neue Baseline akzeptiert — nie mit einer nicht autorisierten Änderung verwechselt', ], }, { @@ -561,7 +583,8 @@ const de: Translations = { 'In einem Ablauf per VM-Provisioning deployt: Hypervisor und Standort auswählen, netOrk provisioniert die VM und installiert den Satellite-Container automatisch', 'Central überspringt automatisch das direkte Polling für jedes Gerät an einem Standort mit einem online, aktuell heartbeatenden Satellite — kein manuelles Umschalten pro Standort', 'Geplante/On-Demand-Neustarts und der SNMP-Auto-Fix laufen über denselben Command-Kanal, egal ob ein Gerät direkt erreichbar ist oder hinter einem Satellite liegt', - 'Noch nicht satellite-abgedeckt: Discovery-Scans und SNMP-Health-Metrik-Polling laufen weiterhin über Central, und WebSSH-Konsolenzugriff ist über einen Satellite nicht verfügbar', + 'Discovery-Jobs an einem satellite-abgedeckten Standort scannen lokal über denselben Command-Kanal, statt von Central aus erfolglos das Subnetz zu erreichen', + 'Noch nicht satellite-abgedeckt: SNMP-Health-Metrik-Polling läuft weiterhin über Central, und WebSSH-Konsolenzugriff ist über einen Satellite nicht verfügbar', ], }, { @@ -573,6 +596,10 @@ const de: Translations = { 'Docker-Container- und Image-Status (Proxmox/Linux)', 'Service-Status und Start/Stop/Neustart (systemd)', 'VM/Container-Liste mit OS-Geräteverknüpfung (Proxmox)', + 'Verfügbarkeitsfenster pro Gerät — unterdrückt OFFLINE-Status und Poll-Fehler-Warnungen während erwarteter Ausfallzeiten (z. B. nächtliches Abschalten); Opt-in, unkonfigurierte Geräte sind nicht betroffen', + 'OPNsense: BGP-Nachbarschaftsstatus-Polling und -Anzeige, mit Peer-Down-Warnung', + 'OPNsense: TLS-Zertifikatsüberwachung für den Trust Store, mit „läuft bald ab"/„abgelaufen"-Warnungen', + 'OPNsense: Dynamic-DNS-Service-Down-Warnung (os-ddclient)', ], }, { @@ -604,6 +631,15 @@ const de: Translations = { 'Ausstehende Job-Queue für Zonenänderungen bei nicht erreichbarem Gerät', ], }, + { + title: 'RADIUS-Verwaltung', + items: [ + 'Globale FreeRADIUS-Server-, NAS-Client- und Benutzerverwaltung — keine Standortbindung, nutzbar von SSIDs/APs jedes Standorts', + 'Änderungen werden über den Treiber auf das Gerät gepusht und erst gespeichert, nachdem das Gerät sie bestätigt hat — vermeidet Drift zwischen netOrks Sicht und der tatsächlichen FreeRADIUS-Konfiguration', + 'Eigene Server-Liste und Detailseite (Tabs für NAS-Clients / Benutzer) im Wireless-Bereich', + 'SSID-802.1X-Integration (automatisches Anlegen eines NAS-Clients aus dem RADIUS-Server einer SSID) ist ein bewusster Folgeschritt, noch nicht enthalten', + ], + }, { title: 'Zugangskontrolle (RBAC)', items: [