feat: reflect netOrk v0.10.0–v0.11.0 release notes
CI / TypeScript — type-check (push) Successful in 20s
CI / Publish — build & push image (push) Successful in 13s
CI / Deploy — pull & restart on host (push) Successful in 2s

Corrects a claim from the previous update: Satellite Phase 3 shipped, so
discovery scans now run through satellite-covered sites too (only SNMP
health-metric polling and WebSSH remain Central-only).

New capabilities added to the feature list: per-device availability
windows (suppress false OFFLINE warnings during expected downtime),
per-SSID MAC access-control lists with a dedicated Wireless ACL tab, a
new RADIUS Management section (global FreeRADIUS server/NAS/user
management), and three OPNsense monitoring additions (BGP neighbors, TLS
certificate/Trust-store monitoring, DDNS-down warning). Also notes that
netOrk's own config pushes are now auto-recognized so they're never
mistaken for an unauthorized change.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Christian Manivong
2026-07-17 07:51:10 +02:00
co-authored by Claude Sonnet 5
parent d8fd9fe675
commit d57734767d
3 changed files with 75 additions and 9 deletions
+5 -4
View File
@@ -273,10 +273,11 @@ sticky section nav). One section per capability area.
11. Dashboards 11. Dashboards
12. Security Integrations 12. Security Integrations
13. DNS Management 13. DNS Management
14. Access Control (RBAC) 14. RADIUS Management
15. NetBox Sync 15. Access Control (RBAC)
16. Compliance & Audit (NIS2) 16. NetBox Sync
17. Developer Experience 17. Compliance & Audit (NIS2)
18. Developer Experience
Each section: `text-xl font-semibold text-slate-200` heading + Each section: `text-xl font-semibold text-slate-200` heading +
feature items as a clean list with `text-slate-400` body. feature items as a clean list with `text-slate-400` body.
+32 -3
View File
@@ -145,6 +145,13 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
- Subnet browser with interface-to-subnet assignments - Subnet browser with interface-to-subnet assignments
- VLAN list grouped by site; per-VLAN device membership view - VLAN list grouped by site; per-VLAN device membership view
- SSID management with push to OpenWRT APs via UCI - SSID management with push to OpenWRT APs via UCI
- Per-SSID MAC access control lists (whitelist / blacklist) pushed to every
AP broadcasting the SSID, quick-add straight from the Connected Clients list
- MAC ACL state is a first-class drift item — covered by the same drift
detection, scheduled auto-fix, and warning aggregation as any other config
drift
- Dedicated Access Control Lists tab on the Wireless page listing every SSID
with its ACL editor inline
### Configuration Management ### Configuration Management
- Config drift detection: desired state (DB) vs device state (poll snapshot) - Config drift detection: desired state (DB) vs device state (poll snapshot)
@@ -156,6 +163,9 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
between any two points in time between any two points in time
- One-click config restore for OPNsense from any prior snapshot - One-click config restore for OPNsense from any prior snapshot
- Unauthorised configuration changes are surfaced as a device warning - Unauthorised configuration changes are surfaced as a device warning
- netOrk's own config pushes (drift fixes, ACL provisioning) are recognized
and auto-accepted as the new baseline — never mistaken for an unauthorized
change
### Configuration Automation (Ansible) ### Configuration Automation (Ansible)
- Reusable Ansible roles and playbooks stored and edited directly in - Reusable Ansible roles and playbooks stored and edited directly in
@@ -194,9 +204,10 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
- Scheduled/on-demand reboots and the SNMP auto-fix flow run through the - Scheduled/on-demand reboots and the SNMP auto-fix flow run through the
same command channel whether a device is directly reachable or behind a same command channel whether a device is directly reachable or behind a
satellite satellite
- Not yet satellite-covered: discovery scans and SNMP health-metric polling - Discovery jobs at a satellite-covered site scan locally through the same
still run from Central, and WebSSH console access isn't available through command channel, instead of failing to reach the subnet from Central
a satellite - Not yet satellite-covered: SNMP health-metric polling still runs from
Central, and WebSSH console access isn't available through a satellite
### Monitoring & Health ### Monitoring & Health
- SNMP health metrics (CPU, memory, interface counters) via `get_health_metrics()` - SNMP health metrics (CPU, memory, interface counters) via `get_health_metrics()`
@@ -207,6 +218,13 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
- Docker container and image status (Proxmox/Linux) - Docker container and image status (Proxmox/Linux)
- Service status and start/stop/restart (systemd) - Service status and start/stop/restart (systemd)
- VM/container list with OS device cross-linking (Proxmox) - VM/container list with OS device cross-linking (Proxmox)
- Per-device availability windows — suppress OFFLINE status and poll-failure
warnings during expected downtime (e.g. a nightly power-off); opt-in,
unconfigured devices are unaffected
- OPNsense: BGP neighbor status polling and display, with a peer-down warning
- OPNsense: TLS certificate monitoring for the Trust store, with
expiring-soon / expired warnings
- OPNsense: Dynamic DNS service-down warning (os-ddclient)
### Dashboards ### Dashboards
- Configurable, shareable dashboards — build your own from a widget picker - Configurable, shareable dashboards — build your own from a widget picker
@@ -236,6 +254,17 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
- PTR record provisioning to reverse zones - PTR record provisioning to reverse zones
- Pending job queue for zone changes when device is unreachable - Pending job queue for zone changes when device is unreachable
### RADIUS Management
- Global FreeRADIUS server, NAS client, and user management — no site
scoping, usable from any site's SSIDs/APs
- Changes push to the device via the driver and are only stored after the
device confirms — avoids drift between netOrk's view and the actual
FreeRADIUS config
- Dedicated server list and detail page (NAS clients / users tabs) under
the Wireless section
- SSID 802.1X integration (auto-provisioning a NAS client from an SSID's
RADIUS server) is a deliberate follow-up, not included yet
### Access Control ### Access Control
- JWT authentication with remember-me (localStorage) or session-only (sessionStorage) - JWT authentication with remember-me (localStorage) or session-only (sessionStorage)
- Two-factor authentication (MFA/TOTP) — authenticator app at login, backup - Two-factor authentication (MFA/TOTP) — authenticator app at login, backup
+38 -2
View File
@@ -156,6 +156,9 @@ const en = {
'Subnet browser with interface-to-subnet assignments', 'Subnet browser with interface-to-subnet assignments',
'VLAN list grouped by site; per-VLAN device membership view', 'VLAN list grouped by site; per-VLAN device membership view',
'SSID management with push to OpenWRT APs via UCI', 'SSID management with push to OpenWRT APs via UCI',
'Per-SSID MAC access control lists (whitelist / blacklist) pushed to every AP broadcasting the SSID, quick-add straight from the Connected Clients list',
'MAC ACL state is a first-class drift item — covered by the same drift detection, scheduled auto-fix, and warning aggregation as any other config drift',
'Dedicated Access Control Lists tab on the Wireless page listing every SSID with its ACL editor inline',
], ],
}, },
{ {
@@ -168,6 +171,7 @@ const en = {
'Configuration backup & versioning: every poll snapshots config into a local Git repo, with full history and a side-by-side diff viewer', 'Configuration backup & versioning: every poll snapshots config into a local Git repo, with full history and a side-by-side diff viewer',
'One-click config restore for OPNsense from any prior snapshot', 'One-click config restore for OPNsense from any prior snapshot',
'Unauthorized configuration changes are surfaced as a device warning', 'Unauthorized configuration changes are surfaced as a device warning',
'netOrk\'s own config pushes (drift fixes, ACL provisioning) are recognized and auto-accepted as the new baseline — never mistaken for an unauthorized change',
], ],
}, },
{ {
@@ -201,7 +205,8 @@ const en = {
'Deployed in one flow via VM provisioning: pick a hypervisor and site, netOrk provisions the VM and installs the satellite container automatically', 'Deployed in one flow via VM provisioning: pick a hypervisor and site, netOrk provisions the VM and installs the satellite container automatically',
'Central automatically skips direct polling for any device at a site with an online, heartbeating satellite — no manual per-site toggling', 'Central automatically skips direct polling for any device at a site with an online, heartbeating satellite — no manual per-site toggling',
'Scheduled/on-demand reboots and the SNMP auto-fix flow run through the same command channel whether a device is directly reachable or behind a satellite', 'Scheduled/on-demand reboots and the SNMP auto-fix flow run through the same command channel whether a device is directly reachable or behind a satellite',
'Not yet satellite-covered: discovery scans and SNMP health-metric polling still run from Central, and WebSSH console access isn\'t available through a satellite', 'Discovery jobs at a satellite-covered site scan locally through the same command channel, instead of failing to reach the subnet from Central',
'Not yet satellite-covered: SNMP health-metric polling still runs from Central, and WebSSH console access isn\'t available through a satellite',
], ],
}, },
{ {
@@ -213,6 +218,10 @@ const en = {
'Docker container and image status (Proxmox/Linux)', 'Docker container and image status (Proxmox/Linux)',
'Service status and start/stop/restart (systemd)', 'Service status and start/stop/restart (systemd)',
'VM/container list with OS device cross-linking (Proxmox)', 'VM/container list with OS device cross-linking (Proxmox)',
'Per-device availability windows — suppress OFFLINE status and poll-failure warnings during expected downtime (e.g. a nightly power-off); opt-in, unconfigured devices are unaffected',
'OPNsense: BGP neighbor status polling and display, with a peer-down warning',
'OPNsense: TLS certificate monitoring for the Trust store, with expiring-soon / expired warnings',
'OPNsense: Dynamic DNS service-down warning (os-ddclient)',
], ],
}, },
{ {
@@ -244,6 +253,15 @@ const en = {
'Pending job queue for zone changes when device is unreachable', 'Pending job queue for zone changes when device is unreachable',
], ],
}, },
{
title: 'RADIUS Management',
items: [
'Global FreeRADIUS server, NAS client, and user management — no site scoping, usable from any site\'s SSIDs/APs',
'Changes push to the device via the driver and are only stored after the device confirms — avoids drift between netOrk\'s view and the actual FreeRADIUS config',
'Dedicated server list and detail page (NAS clients / users tabs) under the Wireless section',
'SSID 802.1X integration (auto-provisioning a NAS client from an SSID\'s RADIUS server) is a deliberate follow-up, not included yet',
],
},
{ {
title: 'Access Control (RBAC)', title: 'Access Control (RBAC)',
items: [ items: [
@@ -516,6 +534,9 @@ const de: Translations = {
'Subnetz-Browser mit Schnittstellen-zu-Subnetz-Zuordnungen', 'Subnetz-Browser mit Schnittstellen-zu-Subnetz-Zuordnungen',
'VLAN-Liste gruppiert nach Standort; VLAN-Mitgliedsansicht pro Gerät', 'VLAN-Liste gruppiert nach Standort; VLAN-Mitgliedsansicht pro Gerät',
'SSID-Verwaltung mit Push auf OpenWRT-APs via UCI', 'SSID-Verwaltung mit Push auf OpenWRT-APs via UCI',
'MAC-Zugriffskontrolllisten pro SSID (Whitelist / Blacklist), gepusht auf jeden AP, der die SSID ausstrahlt — Schnell-Hinzufügen direkt aus der Liste der verbundenen Clients',
'MAC-ACL-Zustand ist ein vollwertiges Drift-Item — abgedeckt von derselben Drift-Erkennung, geplanten Auto-Fixes und Warnungsaggregation wie jeder andere Config-Drift',
'Eigener Access-Control-Lists-Tab auf der Wireless-Seite, listet jede SSID mit ihrem ACL-Editor inline',
], ],
}, },
{ {
@@ -528,6 +549,7 @@ const de: Translations = {
'Konfigurationsbackup & -versionierung: bei jedem Poll wird ein Snapshot in ein lokales Git-Repository geschrieben — vollständige Historie und Side-by-Side-Diff-Viewer', 'Konfigurationsbackup & -versionierung: bei jedem Poll wird ein Snapshot in ein lokales Git-Repository geschrieben — vollständige Historie und Side-by-Side-Diff-Viewer',
'Ein-Klick-Konfigurations-Restore für OPNsense aus jedem früheren Snapshot', 'Ein-Klick-Konfigurations-Restore für OPNsense aus jedem früheren Snapshot',
'Nicht autorisierte Konfigurationsänderungen werden als Gerätewarnung angezeigt', 'Nicht autorisierte Konfigurationsänderungen werden als Gerätewarnung angezeigt',
'netOrks eigene Config-Pushes (Drift-Fixes, ACL-Provisioning) werden erkannt und automatisch als neue Baseline akzeptiert — nie mit einer nicht autorisierten Änderung verwechselt',
], ],
}, },
{ {
@@ -561,7 +583,8 @@ const de: Translations = {
'In einem Ablauf per VM-Provisioning deployt: Hypervisor und Standort auswählen, netOrk provisioniert die VM und installiert den Satellite-Container automatisch', 'In einem Ablauf per VM-Provisioning deployt: Hypervisor und Standort auswählen, netOrk provisioniert die VM und installiert den Satellite-Container automatisch',
'Central überspringt automatisch das direkte Polling für jedes Gerät an einem Standort mit einem online, aktuell heartbeatenden Satellite — kein manuelles Umschalten pro Standort', 'Central überspringt automatisch das direkte Polling für jedes Gerät an einem Standort mit einem online, aktuell heartbeatenden Satellite — kein manuelles Umschalten pro Standort',
'Geplante/On-Demand-Neustarts und der SNMP-Auto-Fix laufen über denselben Command-Kanal, egal ob ein Gerät direkt erreichbar ist oder hinter einem Satellite liegt', 'Geplante/On-Demand-Neustarts und der SNMP-Auto-Fix laufen über denselben Command-Kanal, egal ob ein Gerät direkt erreichbar ist oder hinter einem Satellite liegt',
'Noch nicht satellite-abgedeckt: Discovery-Scans und SNMP-Health-Metrik-Polling laufen weiterhin über Central, und WebSSH-Konsolenzugriff ist über einen Satellite nicht verfügbar', 'Discovery-Jobs an einem satellite-abgedeckten Standort scannen lokal über denselben Command-Kanal, statt von Central aus erfolglos das Subnetz zu erreichen',
'Noch nicht satellite-abgedeckt: SNMP-Health-Metrik-Polling läuft weiterhin über Central, und WebSSH-Konsolenzugriff ist über einen Satellite nicht verfügbar',
], ],
}, },
{ {
@@ -573,6 +596,10 @@ const de: Translations = {
'Docker-Container- und Image-Status (Proxmox/Linux)', 'Docker-Container- und Image-Status (Proxmox/Linux)',
'Service-Status und Start/Stop/Neustart (systemd)', 'Service-Status und Start/Stop/Neustart (systemd)',
'VM/Container-Liste mit OS-Geräteverknüpfung (Proxmox)', 'VM/Container-Liste mit OS-Geräteverknüpfung (Proxmox)',
'Verfügbarkeitsfenster pro Gerät — unterdrückt OFFLINE-Status und Poll-Fehler-Warnungen während erwarteter Ausfallzeiten (z. B. nächtliches Abschalten); Opt-in, unkonfigurierte Geräte sind nicht betroffen',
'OPNsense: BGP-Nachbarschaftsstatus-Polling und -Anzeige, mit Peer-Down-Warnung',
'OPNsense: TLS-Zertifikatsüberwachung für den Trust Store, mit „läuft bald ab"/„abgelaufen"-Warnungen',
'OPNsense: Dynamic-DNS-Service-Down-Warnung (os-ddclient)',
], ],
}, },
{ {
@@ -604,6 +631,15 @@ const de: Translations = {
'Ausstehende Job-Queue für Zonenänderungen bei nicht erreichbarem Gerät', 'Ausstehende Job-Queue für Zonenänderungen bei nicht erreichbarem Gerät',
], ],
}, },
{
title: 'RADIUS-Verwaltung',
items: [
'Globale FreeRADIUS-Server-, NAS-Client- und Benutzerverwaltung — keine Standortbindung, nutzbar von SSIDs/APs jedes Standorts',
'Änderungen werden über den Treiber auf das Gerät gepusht und erst gespeichert, nachdem das Gerät sie bestätigt hat — vermeidet Drift zwischen netOrks Sicht und der tatsächlichen FreeRADIUS-Konfiguration',
'Eigene Server-Liste und Detailseite (Tabs für NAS-Clients / Benutzer) im Wireless-Bereich',
'SSID-802.1X-Integration (automatisches Anlegen eines NAS-Clients aus dem RADIUS-Server einer SSID) ist ein bewusster Folgeschritt, noch nicht enthalten',
],
},
{ {
title: 'Zugangskontrolle (RBAC)', title: 'Zugangskontrolle (RBAC)',
items: [ items: [