feat: reflect netOrk v0.5.0–v0.9.0 release notes across the site
Dashboards (configurable/shareable, 13 widgets, WYSIWYG grid editor) and the EOL Tracking plugin ship in v0.5.x, so both move from roadmap to shipped: Features, Plugins, NIS2 mapping, and a homepage screenshot row. v0.6.0–v0.9.0 add three more major capabilities, verified against code rather than the (partly stale) TODO.md: VM Provisioning (Cloud-Init VMs from a hypervisor's VMs tab), Ansible-based configuration automation (11 built-in roles, VM-provisioning integration), and Satellite deployments (a remote polling agent for sites Central can't reach directly, with its current limitations noted honestly). Wake-on-LAN and the audit log CSV/PDF export (previously a roadmap item) round out the update. Roadmap and the NIS2 coverage page are reconciled to match: shipped items removed from "planned"/"coming", Art. 21 (2d) and (2h) text updated. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
d8892c53ce
commit
d8fd9fe675
+97
-11
@@ -68,8 +68,21 @@ hardware and want operational visibility beyond what consumer dashboards offer.
|
||||
9. **NIS2 evidence foundation** — NIS2 Art. 21 mandates asset inventory, patch
|
||||
management, access control, and audit trails. netOrk produces all of these as
|
||||
day-to-day operational outputs: full device inventory, per-device update status,
|
||||
Wazuh CVE tracking, RBAC with MFA, Git-backed config snapshots with diff/restore,
|
||||
config drift detection, and a complete audit log.
|
||||
Wazuh CVE tracking, EOL firmware/OS flagging, RBAC with MFA, Git-backed config
|
||||
snapshots with diff/restore, config drift detection, and a complete audit log.
|
||||
|
||||
10. **Build your own view** — Configurable, shareable dashboards: pick from 13
|
||||
widgets, arrange them on a WYSIWYG grid, and share the result with colleagues
|
||||
who can subscribe to the live version or clone their own copy.
|
||||
|
||||
11. **From zero to managed in one flow** — Provision a Cloud-Init VM on a
|
||||
Proxmox hypervisor, assign Ansible roles to configure it, and netOrk
|
||||
auto-links it as a Device — no separate tools, no manual SSH-and-copy.
|
||||
|
||||
12. **Reach sites netOrk can't touch directly** — Deploy a lightweight
|
||||
Satellite agent to poll devices locally at a disconnected or firewalled
|
||||
site and sync results back over HTTPS; scheduled fixes route through it
|
||||
the same way they do for directly reachable devices.
|
||||
|
||||
---
|
||||
|
||||
@@ -89,6 +102,23 @@ hardware and want operational visibility beyond what consumer dashboards offer.
|
||||
- FQDN resolution (reverse DNS)
|
||||
- Manual adoption from scan results (no auto-create to avoid inventory noise)
|
||||
|
||||
### VM Provisioning
|
||||
- Cloud-Init based VM creation directly from a hypervisor's VMs tab — no
|
||||
manual template or VMID setup
|
||||
- Multi-distro image catalog: Debian 12, Ubuntu 22.04/24.04/26.04,
|
||||
Fedora 42/43/44, with Ubuntu and Fedora releases synced automatically as
|
||||
new versions ship
|
||||
- Pick a target VLAN and an IP from its subnet — netOrk creates the DHCP
|
||||
reservation automatically
|
||||
- Cloud-init provisions a real Linux user with an SSH key, plus configurable
|
||||
bootstrap toggles (SNMP, QEMU guest agent)
|
||||
- Reusable provisioning templates for repeatable bootstrap settings
|
||||
- The new VM is auto-linked as a netOrk Device and its hostname assigned to
|
||||
a DNS zone once bootstrap finishes
|
||||
- Deploy progress shown as a live step checklist in the UI
|
||||
- Delete a VM and its linked netOrk Device together, gated behind a
|
||||
name-confirmation prompt
|
||||
|
||||
### Supported Device Drivers
|
||||
Custom NAPALM drivers for all of the following:
|
||||
|
||||
@@ -127,11 +157,46 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
|
||||
- One-click config restore for OPNsense from any prior snapshot
|
||||
- Unauthorised configuration changes are surfaced as a device warning
|
||||
|
||||
### Configuration Automation (Ansible)
|
||||
- Reusable Ansible roles and playbooks stored and edited directly in
|
||||
netOrk — no separate git checkout
|
||||
- 11 built-in roles ready to assign: base, ubuntu, docker, adguard, zoraxy,
|
||||
portainer, watchtower, uptime-kuma, vaultwarden, wireguard, fail2ban
|
||||
- Automatic dependency resolution — assigning `docker` pulls in `base`
|
||||
automatically, no manual role ordering
|
||||
- Built-in roles can't be deleted but are fully editable; customizations
|
||||
survive upgrades, and only untouched files auto-heal on bugfixes
|
||||
- `ansible-doc`-backed autocomplete while writing roles and playbooks
|
||||
- Upload your own role as an archive
|
||||
- Device-level role assignment with a dedicated Ansible tab on the device
|
||||
detail page
|
||||
- Run history per device, snapshotting the exact role/playbook content
|
||||
that was executed
|
||||
- Wired into VM provisioning: assign roles at VM-creation time and they
|
||||
run automatically after boot
|
||||
|
||||
### Scheduled Operations
|
||||
- Scheduled reboots for OpenWRT APs with per-site concurrency lock
|
||||
- Failback cron script written to device for netOrk-unreachable scenarios
|
||||
- Scheduled config drift fixes with time-window enforcement
|
||||
- Package update scheduling and one-click apply
|
||||
- Wake-on-LAN via a firewall's driver (OPNsense today) — saved WOL targets
|
||||
with on-demand "Wake now" and recurring schedules; save a seen host as a
|
||||
target directly from the DHCP/ARP tabs
|
||||
|
||||
### Satellite Deployments
|
||||
- Lightweight Docker agent deployed at a site netOrk can't reach directly —
|
||||
polls devices locally and syncs results back to Central over HTTPS
|
||||
- Deployed in one flow via VM provisioning: pick a hypervisor and site,
|
||||
netOrk provisions the VM and installs the satellite container automatically
|
||||
- Central automatically skips direct polling for any device at a site with
|
||||
an online, heartbeating satellite — no manual per-site toggling
|
||||
- Scheduled/on-demand reboots and the SNMP auto-fix flow run through the
|
||||
same command channel whether a device is directly reachable or behind a
|
||||
satellite
|
||||
- Not yet satellite-covered: discovery scans and SNMP health-metric polling
|
||||
still run from Central, and WebSSH console access isn't available through
|
||||
a satellite
|
||||
|
||||
### Monitoring & Health
|
||||
- SNMP health metrics (CPU, memory, interface counters) via `get_health_metrics()`
|
||||
@@ -143,11 +208,27 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
|
||||
- Service status and start/stop/restart (systemd)
|
||||
- VM/container list with OS device cross-linking (Proxmox)
|
||||
|
||||
### Dashboards
|
||||
- Configurable, shareable dashboards — build your own from a widget picker
|
||||
instead of a fixed layout
|
||||
- WYSIWYG grid-layout editor: drag, resize, and arrange widgets on a canvas
|
||||
- 13 widget types: stats, device warnings, recently updated devices, network
|
||||
topology, EOL status, config drift summary, Wazuh security alerts, audit log
|
||||
activity, discovery jobs status, upcoming scheduled actions, DNS zones
|
||||
overview, site overview, config snapshot history
|
||||
- Multi-instance widgets with independent per-widget settings
|
||||
- Share a dashboard with specific users; recipients can subscribe to the
|
||||
owner's live version or clone it into their own editable copy
|
||||
- Favorite dashboards for quick access from the main menu; set any dashboard
|
||||
as your home view
|
||||
|
||||
### Security Integrations (plugins)
|
||||
- **Wazuh** — agent enrollment tracking, vulnerability counts (by severity),
|
||||
recent alert history, CIS benchmark scores, one-click agent install fix stream
|
||||
- **Graylog** — rsyslog forwarding status per device, one-click fix to write rule
|
||||
- **CrowdSec** — org-level decisions, remediation metrics, top attack scenarios
|
||||
- **EOL Tracking** — flags devices running end-of-life or soon-to-be-end-of-life
|
||||
firmware/OS via the endoflife.date API, checked daily
|
||||
|
||||
### DNS
|
||||
- DNS zone management with authoritative device assignment
|
||||
@@ -162,7 +243,8 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
|
||||
per role
|
||||
- RBAC with four built-in roles: viewer / operator / engineer / administrator
|
||||
- Custom roles with any permission combination
|
||||
- Full audit log of all orchestration actions
|
||||
- Full audit log of all orchestration actions, filterable by date range,
|
||||
user, action, or resource — export to CSV or PDF
|
||||
|
||||
### NetBox Sync
|
||||
- Pushes vendor, model, OS version, status to NetBox dcim.devices
|
||||
@@ -180,11 +262,15 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
|
||||
|
||||
## Architecture in One Paragraph
|
||||
|
||||
netOrk runs as five Docker containers: a FastAPI API server, two Celery worker
|
||||
pools (general + poll), a Celery Beat scheduler, and an nginx UI server. Redis
|
||||
is the broker. PostgreSQL stores all state. Device communication is always
|
||||
blocking I/O executed in Celery workers — FastAPI request handlers are
|
||||
async-only for DB and quick operations. Custom NAPALM drivers live in `vendor/`
|
||||
as editable packages and self-register via `@register_driver`. The plugin system
|
||||
(`netork/plugins/`) provides a hook bus, a plugin registry with enable/disable
|
||||
state in the DB, and a documented pattern for adding integrations.
|
||||
netOrk runs as a set of Docker containers: a FastAPI API server, three Celery
|
||||
worker pools (general, poll, and Ansible), a Celery Beat scheduler, and an
|
||||
nginx UI server. Redis is the broker. PostgreSQL stores all state. Device
|
||||
communication is always blocking I/O executed in Celery workers — FastAPI
|
||||
request handlers are async-only for DB and quick operations. Custom NAPALM
|
||||
drivers live in `vendor/` as editable packages and self-register via
|
||||
`@register_driver`. The plugin system (`netork/plugins/`) provides a hook bus,
|
||||
a plugin registry with enable/disable state in the DB, and a documented
|
||||
pattern for adding integrations. For sites Central can't reach directly, a
|
||||
separate Satellite container polls devices locally and syncs results back
|
||||
over HTTPS; Central dispatches actions (reboots, SNMP fixes) to it through a
|
||||
generic command channel, transparently to the UI.
|
||||
|
||||
Reference in New Issue
Block a user