feat: reflect netOrk v0.5.0–v0.9.0 release notes across the site
Dashboards (configurable/shareable, 13 widgets, WYSIWYG grid editor) and the EOL Tracking plugin ship in v0.5.x, so both move from roadmap to shipped: Features, Plugins, NIS2 mapping, and a homepage screenshot row. v0.6.0–v0.9.0 add three more major capabilities, verified against code rather than the (partly stale) TODO.md: VM Provisioning (Cloud-Init VMs from a hypervisor's VMs tab), Ansible-based configuration automation (11 built-in roles, VM-provisioning integration), and Satellite deployments (a remote polling agent for sites Central can't reach directly, with its current limitations noted honestly). Wake-on-LAN and the audit log CSV/PDF export (previously a roadmap item) round out the update. Roadmap and the NIS2 coverage page are reconciled to match: shipped items removed from "planned"/"coming", Art. 21 (2d) and (2h) text updated. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
d8892c53ce
commit
d8fd9fe675
+23
-12
@@ -156,6 +156,14 @@ Each badge uses the `Driver / Integration Badge` component from DESIGN.md.
|
|||||||
device warning.`
|
device warning.`
|
||||||
- Screenshot: ConfigTab inside DeviceDetailPage
|
- Screenshot: ConfigTab inside DeviceDetailPage
|
||||||
|
|
||||||
|
**Row 5 — Left text, right screenshot**
|
||||||
|
- Heading: `Dashboards you actually build`
|
||||||
|
- Copy: `Pick from 13 widgets and arrange them on a WYSIWYG grid — no
|
||||||
|
more fixed layout. Share a dashboard with a colleague, let them
|
||||||
|
subscribe to your live version or clone it into their own, and pin
|
||||||
|
favorites to the main menu.`
|
||||||
|
- Screenshot: DashboardDetailPage (edit mode)
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
### Section 5b — NIS2
|
### Section 5b — NIS2
|
||||||
@@ -254,16 +262,21 @@ sticky section nav). One section per capability area.
|
|||||||
**Sections** (map directly to feature list in `docs/PRODUCT.md`):
|
**Sections** (map directly to feature list in `docs/PRODUCT.md`):
|
||||||
1. Device Management
|
1. Device Management
|
||||||
2. Discovery
|
2. Discovery
|
||||||
3. Supported Drivers (full table)
|
3. VM Provisioning
|
||||||
4. Networking & Inventory
|
4. Supported Drivers (full table)
|
||||||
5. Configuration Management & Drift
|
5. Networking & Inventory
|
||||||
6. Scheduled Operations
|
6. Configuration Management & Drift
|
||||||
7. Monitoring & Health
|
7. Configuration Automation (Ansible)
|
||||||
8. Security Integrations
|
8. Scheduled Operations
|
||||||
9. DNS Management
|
9. Satellite Deployments
|
||||||
10. Access Control (RBAC)
|
10. Monitoring & Health
|
||||||
11. NetBox Sync
|
11. Dashboards
|
||||||
12. Developer Experience
|
12. Security Integrations
|
||||||
|
13. DNS Management
|
||||||
|
14. Access Control (RBAC)
|
||||||
|
15. NetBox Sync
|
||||||
|
16. Compliance & Audit (NIS2)
|
||||||
|
17. Developer Experience
|
||||||
|
|
||||||
Each section: `text-xl font-semibold text-slate-200` heading +
|
Each section: `text-xl font-semibold text-slate-200` heading +
|
||||||
feature items as a clean list with `text-slate-400` body.
|
feature items as a clean list with `text-slate-400` body.
|
||||||
@@ -340,7 +353,6 @@ address NIS2 Art. 21 technical baseline requirements.
|
|||||||
**Planned items (NIS2-tagged):**
|
**Planned items (NIS2-tagged):**
|
||||||
- CVE tracking per device — NVD / OSV cross-reference
|
- CVE tracking per device — NVD / OSV cross-reference
|
||||||
- Compliance dashboard — per-site Art. 21 checklist view
|
- Compliance dashboard — per-site Art. 21 checklist view
|
||||||
- Audit log export — PDF / CSV with filters
|
|
||||||
|
|
||||||
**Planned items (general):**
|
**Planned items (general):**
|
||||||
- Webhook engine — outbound events with HMAC signing
|
- Webhook engine — outbound events with HMAC signing
|
||||||
@@ -349,7 +361,6 @@ address NIS2 Art. 21 technical baseline requirements.
|
|||||||
|
|
||||||
**Under consideration (NIS2-tagged):**
|
**Under consideration (NIS2-tagged):**
|
||||||
- Incident workflow — structured record + NIS2 Art. 23 Fristen-Tracker
|
- Incident workflow — structured record + NIS2 Art. 23 Fristen-Tracker
|
||||||
- EOL tracking — endoflife.date integration for firmware / OS
|
|
||||||
|
|
||||||
**Under consideration (general):**
|
**Under consideration (general):**
|
||||||
- mDNS scanner — media device discovery
|
- mDNS scanner — media device discovery
|
||||||
|
|||||||
+97
-11
@@ -68,8 +68,21 @@ hardware and want operational visibility beyond what consumer dashboards offer.
|
|||||||
9. **NIS2 evidence foundation** — NIS2 Art. 21 mandates asset inventory, patch
|
9. **NIS2 evidence foundation** — NIS2 Art. 21 mandates asset inventory, patch
|
||||||
management, access control, and audit trails. netOrk produces all of these as
|
management, access control, and audit trails. netOrk produces all of these as
|
||||||
day-to-day operational outputs: full device inventory, per-device update status,
|
day-to-day operational outputs: full device inventory, per-device update status,
|
||||||
Wazuh CVE tracking, RBAC with MFA, Git-backed config snapshots with diff/restore,
|
Wazuh CVE tracking, EOL firmware/OS flagging, RBAC with MFA, Git-backed config
|
||||||
config drift detection, and a complete audit log.
|
snapshots with diff/restore, config drift detection, and a complete audit log.
|
||||||
|
|
||||||
|
10. **Build your own view** — Configurable, shareable dashboards: pick from 13
|
||||||
|
widgets, arrange them on a WYSIWYG grid, and share the result with colleagues
|
||||||
|
who can subscribe to the live version or clone their own copy.
|
||||||
|
|
||||||
|
11. **From zero to managed in one flow** — Provision a Cloud-Init VM on a
|
||||||
|
Proxmox hypervisor, assign Ansible roles to configure it, and netOrk
|
||||||
|
auto-links it as a Device — no separate tools, no manual SSH-and-copy.
|
||||||
|
|
||||||
|
12. **Reach sites netOrk can't touch directly** — Deploy a lightweight
|
||||||
|
Satellite agent to poll devices locally at a disconnected or firewalled
|
||||||
|
site and sync results back over HTTPS; scheduled fixes route through it
|
||||||
|
the same way they do for directly reachable devices.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -89,6 +102,23 @@ hardware and want operational visibility beyond what consumer dashboards offer.
|
|||||||
- FQDN resolution (reverse DNS)
|
- FQDN resolution (reverse DNS)
|
||||||
- Manual adoption from scan results (no auto-create to avoid inventory noise)
|
- Manual adoption from scan results (no auto-create to avoid inventory noise)
|
||||||
|
|
||||||
|
### VM Provisioning
|
||||||
|
- Cloud-Init based VM creation directly from a hypervisor's VMs tab — no
|
||||||
|
manual template or VMID setup
|
||||||
|
- Multi-distro image catalog: Debian 12, Ubuntu 22.04/24.04/26.04,
|
||||||
|
Fedora 42/43/44, with Ubuntu and Fedora releases synced automatically as
|
||||||
|
new versions ship
|
||||||
|
- Pick a target VLAN and an IP from its subnet — netOrk creates the DHCP
|
||||||
|
reservation automatically
|
||||||
|
- Cloud-init provisions a real Linux user with an SSH key, plus configurable
|
||||||
|
bootstrap toggles (SNMP, QEMU guest agent)
|
||||||
|
- Reusable provisioning templates for repeatable bootstrap settings
|
||||||
|
- The new VM is auto-linked as a netOrk Device and its hostname assigned to
|
||||||
|
a DNS zone once bootstrap finishes
|
||||||
|
- Deploy progress shown as a live step checklist in the UI
|
||||||
|
- Delete a VM and its linked netOrk Device together, gated behind a
|
||||||
|
name-confirmation prompt
|
||||||
|
|
||||||
### Supported Device Drivers
|
### Supported Device Drivers
|
||||||
Custom NAPALM drivers for all of the following:
|
Custom NAPALM drivers for all of the following:
|
||||||
|
|
||||||
@@ -127,11 +157,46 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
|
|||||||
- One-click config restore for OPNsense from any prior snapshot
|
- One-click config restore for OPNsense from any prior snapshot
|
||||||
- Unauthorised configuration changes are surfaced as a device warning
|
- Unauthorised configuration changes are surfaced as a device warning
|
||||||
|
|
||||||
|
### Configuration Automation (Ansible)
|
||||||
|
- Reusable Ansible roles and playbooks stored and edited directly in
|
||||||
|
netOrk — no separate git checkout
|
||||||
|
- 11 built-in roles ready to assign: base, ubuntu, docker, adguard, zoraxy,
|
||||||
|
portainer, watchtower, uptime-kuma, vaultwarden, wireguard, fail2ban
|
||||||
|
- Automatic dependency resolution — assigning `docker` pulls in `base`
|
||||||
|
automatically, no manual role ordering
|
||||||
|
- Built-in roles can't be deleted but are fully editable; customizations
|
||||||
|
survive upgrades, and only untouched files auto-heal on bugfixes
|
||||||
|
- `ansible-doc`-backed autocomplete while writing roles and playbooks
|
||||||
|
- Upload your own role as an archive
|
||||||
|
- Device-level role assignment with a dedicated Ansible tab on the device
|
||||||
|
detail page
|
||||||
|
- Run history per device, snapshotting the exact role/playbook content
|
||||||
|
that was executed
|
||||||
|
- Wired into VM provisioning: assign roles at VM-creation time and they
|
||||||
|
run automatically after boot
|
||||||
|
|
||||||
### Scheduled Operations
|
### Scheduled Operations
|
||||||
- Scheduled reboots for OpenWRT APs with per-site concurrency lock
|
- Scheduled reboots for OpenWRT APs with per-site concurrency lock
|
||||||
- Failback cron script written to device for netOrk-unreachable scenarios
|
- Failback cron script written to device for netOrk-unreachable scenarios
|
||||||
- Scheduled config drift fixes with time-window enforcement
|
- Scheduled config drift fixes with time-window enforcement
|
||||||
- Package update scheduling and one-click apply
|
- Package update scheduling and one-click apply
|
||||||
|
- Wake-on-LAN via a firewall's driver (OPNsense today) — saved WOL targets
|
||||||
|
with on-demand "Wake now" and recurring schedules; save a seen host as a
|
||||||
|
target directly from the DHCP/ARP tabs
|
||||||
|
|
||||||
|
### Satellite Deployments
|
||||||
|
- Lightweight Docker agent deployed at a site netOrk can't reach directly —
|
||||||
|
polls devices locally and syncs results back to Central over HTTPS
|
||||||
|
- Deployed in one flow via VM provisioning: pick a hypervisor and site,
|
||||||
|
netOrk provisions the VM and installs the satellite container automatically
|
||||||
|
- Central automatically skips direct polling for any device at a site with
|
||||||
|
an online, heartbeating satellite — no manual per-site toggling
|
||||||
|
- Scheduled/on-demand reboots and the SNMP auto-fix flow run through the
|
||||||
|
same command channel whether a device is directly reachable or behind a
|
||||||
|
satellite
|
||||||
|
- Not yet satellite-covered: discovery scans and SNMP health-metric polling
|
||||||
|
still run from Central, and WebSSH console access isn't available through
|
||||||
|
a satellite
|
||||||
|
|
||||||
### Monitoring & Health
|
### Monitoring & Health
|
||||||
- SNMP health metrics (CPU, memory, interface counters) via `get_health_metrics()`
|
- SNMP health metrics (CPU, memory, interface counters) via `get_health_metrics()`
|
||||||
@@ -143,11 +208,27 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
|
|||||||
- Service status and start/stop/restart (systemd)
|
- Service status and start/stop/restart (systemd)
|
||||||
- VM/container list with OS device cross-linking (Proxmox)
|
- VM/container list with OS device cross-linking (Proxmox)
|
||||||
|
|
||||||
|
### Dashboards
|
||||||
|
- Configurable, shareable dashboards — build your own from a widget picker
|
||||||
|
instead of a fixed layout
|
||||||
|
- WYSIWYG grid-layout editor: drag, resize, and arrange widgets on a canvas
|
||||||
|
- 13 widget types: stats, device warnings, recently updated devices, network
|
||||||
|
topology, EOL status, config drift summary, Wazuh security alerts, audit log
|
||||||
|
activity, discovery jobs status, upcoming scheduled actions, DNS zones
|
||||||
|
overview, site overview, config snapshot history
|
||||||
|
- Multi-instance widgets with independent per-widget settings
|
||||||
|
- Share a dashboard with specific users; recipients can subscribe to the
|
||||||
|
owner's live version or clone it into their own editable copy
|
||||||
|
- Favorite dashboards for quick access from the main menu; set any dashboard
|
||||||
|
as your home view
|
||||||
|
|
||||||
### Security Integrations (plugins)
|
### Security Integrations (plugins)
|
||||||
- **Wazuh** — agent enrollment tracking, vulnerability counts (by severity),
|
- **Wazuh** — agent enrollment tracking, vulnerability counts (by severity),
|
||||||
recent alert history, CIS benchmark scores, one-click agent install fix stream
|
recent alert history, CIS benchmark scores, one-click agent install fix stream
|
||||||
- **Graylog** — rsyslog forwarding status per device, one-click fix to write rule
|
- **Graylog** — rsyslog forwarding status per device, one-click fix to write rule
|
||||||
- **CrowdSec** — org-level decisions, remediation metrics, top attack scenarios
|
- **CrowdSec** — org-level decisions, remediation metrics, top attack scenarios
|
||||||
|
- **EOL Tracking** — flags devices running end-of-life or soon-to-be-end-of-life
|
||||||
|
firmware/OS via the endoflife.date API, checked daily
|
||||||
|
|
||||||
### DNS
|
### DNS
|
||||||
- DNS zone management with authoritative device assignment
|
- DNS zone management with authoritative device assignment
|
||||||
@@ -162,7 +243,8 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
|
|||||||
per role
|
per role
|
||||||
- RBAC with four built-in roles: viewer / operator / engineer / administrator
|
- RBAC with four built-in roles: viewer / operator / engineer / administrator
|
||||||
- Custom roles with any permission combination
|
- Custom roles with any permission combination
|
||||||
- Full audit log of all orchestration actions
|
- Full audit log of all orchestration actions, filterable by date range,
|
||||||
|
user, action, or resource — export to CSV or PDF
|
||||||
|
|
||||||
### NetBox Sync
|
### NetBox Sync
|
||||||
- Pushes vendor, model, OS version, status to NetBox dcim.devices
|
- Pushes vendor, model, OS version, status to NetBox dcim.devices
|
||||||
@@ -180,11 +262,15 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
|
|||||||
|
|
||||||
## Architecture in One Paragraph
|
## Architecture in One Paragraph
|
||||||
|
|
||||||
netOrk runs as five Docker containers: a FastAPI API server, two Celery worker
|
netOrk runs as a set of Docker containers: a FastAPI API server, three Celery
|
||||||
pools (general + poll), a Celery Beat scheduler, and an nginx UI server. Redis
|
worker pools (general, poll, and Ansible), a Celery Beat scheduler, and an
|
||||||
is the broker. PostgreSQL stores all state. Device communication is always
|
nginx UI server. Redis is the broker. PostgreSQL stores all state. Device
|
||||||
blocking I/O executed in Celery workers — FastAPI request handlers are
|
communication is always blocking I/O executed in Celery workers — FastAPI
|
||||||
async-only for DB and quick operations. Custom NAPALM drivers live in `vendor/`
|
request handlers are async-only for DB and quick operations. Custom NAPALM
|
||||||
as editable packages and self-register via `@register_driver`. The plugin system
|
drivers live in `vendor/` as editable packages and self-register via
|
||||||
(`netork/plugins/`) provides a hook bus, a plugin registry with enable/disable
|
`@register_driver`. The plugin system (`netork/plugins/`) provides a hook bus,
|
||||||
state in the DB, and a documented pattern for adding integrations.
|
a plugin registry with enable/disable state in the DB, and a documented
|
||||||
|
pattern for adding integrations. For sites Central can't reach directly, a
|
||||||
|
separate Satellite container polls devices locally and syncs results back
|
||||||
|
over HTTPS; Central dispatches actions (reboots, SNMP fixes) to it through a
|
||||||
|
generic command channel, transparently to the UI.
|
||||||
|
|||||||
+118
-8
@@ -69,6 +69,10 @@ const en = {
|
|||||||
heading: 'Configuration backup and versioning',
|
heading: 'Configuration backup and versioning',
|
||||||
body: 'Every poll captures a config snapshot into a local Git repository. The Config tab shows the full snapshot history, a side-by-side diff between any two points in time, and — for OPNsense — a Restore button. Unauthorized changes show up as a device warning.',
|
body: 'Every poll captures a config snapshot into a local Git repository. The Config tab shows the full snapshot history, a side-by-side diff between any two points in time, and — for OPNsense — a Restore button. Unauthorized changes show up as a device warning.',
|
||||||
},
|
},
|
||||||
|
screenshot5: {
|
||||||
|
heading: 'Dashboards you actually build',
|
||||||
|
body: 'Pick from 13 widgets and arrange them on a WYSIWYG grid — no more fixed layout. Share a dashboard with a colleague, let them subscribe to your live version or clone it into their own, and pin favorites to the main menu.',
|
||||||
|
},
|
||||||
nis2Label: 'NIS2 · Art. 21',
|
nis2Label: 'NIS2 · Art. 21',
|
||||||
nis2Heading: 'Evidence, not paperwork.',
|
nis2Heading: 'Evidence, not paperwork.',
|
||||||
nis2Body: "NIS2 Art. 21 mandates asset inventory, patch management, access control, and audit trails as baseline technical measures. netOrk doesn't bolt on a compliance layer — these are its day-to-day outputs.",
|
nis2Body: "NIS2 Art. 21 mandates asset inventory, patch management, access control, and audit trails as baseline technical measures. netOrk doesn't bolt on a compliance layer — these are its day-to-day outputs.",
|
||||||
@@ -80,7 +84,7 @@ const en = {
|
|||||||
{ art: 'Art. 21 (2b)', label: 'Incident detection', detail: 'Wazuh alert history, CrowdSec decisions, Graylog syslog per device' },
|
{ art: 'Art. 21 (2b)', label: 'Incident detection', detail: 'Wazuh alert history, CrowdSec decisions, Graylog syslog per device' },
|
||||||
],
|
],
|
||||||
pluginsHeading: 'Built to extend',
|
pluginsHeading: 'Built to extend',
|
||||||
pluginsBody: 'Integrations (Wazuh, Graylog, CrowdSec, apt-cacher-ng) are plugins that register into the plugin system — they can be enabled or disabled per deployment without code changes. Adding a new integration follows a documented pattern with a hook bus, typed metadata, and a plugin registry.',
|
pluginsBody: 'Integrations (Wazuh, Graylog, CrowdSec, apt-cacher-ng, EOL Tracking) are plugins that register into the plugin system — they can be enabled or disabled per deployment without code changes. Adding a new integration follows a documented pattern with a hook bus, typed metadata, and a plugin registry.',
|
||||||
pluginsLink: 'Plugin system docs →',
|
pluginsLink: 'Plugin system docs →',
|
||||||
deployHeading: 'Self-hosted. One command.',
|
deployHeading: 'Self-hosted. One command.',
|
||||||
deployBody: 'netOrk runs in Docker Compose. Five containers: API, two worker pools, a Beat scheduler, and an nginx UI server. No external dependencies beyond Redis and PostgreSQL.',
|
deployBody: 'netOrk runs in Docker Compose. Five containers: API, two worker pools, a Beat scheduler, and an nginx UI server. No external dependencies beyond Redis and PostgreSQL.',
|
||||||
@@ -113,6 +117,19 @@ const en = {
|
|||||||
'Manual adoption from scan results — no auto-create to avoid inventory noise',
|
'Manual adoption from scan results — no auto-create to avoid inventory noise',
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
title: 'VM Provisioning',
|
||||||
|
items: [
|
||||||
|
'Cloud-Init based VM creation directly from a hypervisor\'s VMs tab — no manual template or VMID setup',
|
||||||
|
'Multi-distro image catalog: Debian 12, Ubuntu 22.04/24.04/26.04, Fedora 42/43/44, with Ubuntu and Fedora releases synced automatically as new versions ship',
|
||||||
|
'Pick a target VLAN and an IP from its subnet — netOrk creates the DHCP reservation automatically',
|
||||||
|
'Cloud-init provisions a real Linux user with an SSH key, plus configurable bootstrap toggles (SNMP, QEMU guest agent)',
|
||||||
|
'Reusable provisioning templates for repeatable bootstrap settings',
|
||||||
|
'The new VM is auto-linked as a netOrk Device and its hostname assigned to a DNS zone once bootstrap finishes',
|
||||||
|
'Deploy progress shown as a live step checklist in the UI',
|
||||||
|
'Delete a VM and its linked netOrk Device together, gated behind a name-confirmation prompt',
|
||||||
|
],
|
||||||
|
},
|
||||||
{
|
{
|
||||||
title: 'Supported Drivers',
|
title: 'Supported Drivers',
|
||||||
items: [
|
items: [
|
||||||
@@ -153,6 +170,20 @@ const en = {
|
|||||||
'Unauthorized configuration changes are surfaced as a device warning',
|
'Unauthorized configuration changes are surfaced as a device warning',
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
title: 'Configuration Automation (Ansible)',
|
||||||
|
items: [
|
||||||
|
'Reusable Ansible roles and playbooks stored and edited directly in netOrk — no separate git checkout',
|
||||||
|
'11 built-in roles ready to assign: base, ubuntu, docker, adguard, zoraxy, portainer, watchtower, uptime-kuma, vaultwarden, wireguard, fail2ban',
|
||||||
|
'Automatic dependency resolution — assigning docker pulls in base automatically, no manual role ordering',
|
||||||
|
'Built-in roles can\'t be deleted but are fully editable; customizations survive upgrades, and only untouched files auto-heal on bugfixes',
|
||||||
|
'ansible-doc-backed autocomplete while writing roles and playbooks',
|
||||||
|
'Upload your own role as an archive',
|
||||||
|
'Device-level role assignment with a dedicated Ansible tab on the device detail page',
|
||||||
|
'Run history per device, snapshotting the exact role/playbook content that was executed',
|
||||||
|
'Wired into VM provisioning: assign roles at VM-creation time and they run automatically after boot',
|
||||||
|
],
|
||||||
|
},
|
||||||
{
|
{
|
||||||
title: 'Scheduled Operations',
|
title: 'Scheduled Operations',
|
||||||
items: [
|
items: [
|
||||||
@@ -160,6 +191,17 @@ const en = {
|
|||||||
'Failback cron script written to device for netOrk-unreachable scenarios',
|
'Failback cron script written to device for netOrk-unreachable scenarios',
|
||||||
'Scheduled config drift fixes with time-window enforcement',
|
'Scheduled config drift fixes with time-window enforcement',
|
||||||
'Package update scheduling and one-click apply',
|
'Package update scheduling and one-click apply',
|
||||||
|
'Wake-on-LAN via a firewall\'s driver (OPNsense today) — saved WOL targets with on-demand "Wake now" and recurring schedules; save a seen host as a target directly from the DHCP/ARP tabs',
|
||||||
|
],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
title: 'Satellite Deployments',
|
||||||
|
items: [
|
||||||
|
'Lightweight Docker agent deployed at a site netOrk can\'t reach directly — polls devices locally and syncs results back to Central over HTTPS',
|
||||||
|
'Deployed in one flow via VM provisioning: pick a hypervisor and site, netOrk provisions the VM and installs the satellite container automatically',
|
||||||
|
'Central automatically skips direct polling for any device at a site with an online, heartbeating satellite — no manual per-site toggling',
|
||||||
|
'Scheduled/on-demand reboots and the SNMP auto-fix flow run through the same command channel whether a device is directly reachable or behind a satellite',
|
||||||
|
'Not yet satellite-covered: discovery scans and SNMP health-metric polling still run from Central, and WebSSH console access isn\'t available through a satellite',
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
@@ -173,12 +215,24 @@ const en = {
|
|||||||
'VM/container list with OS device cross-linking (Proxmox)',
|
'VM/container list with OS device cross-linking (Proxmox)',
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
title: 'Dashboards',
|
||||||
|
items: [
|
||||||
|
'Configurable, shareable dashboards — build your own from a widget picker instead of a fixed layout',
|
||||||
|
'WYSIWYG grid-layout editor: drag, resize, and arrange widgets on a canvas',
|
||||||
|
'13 widget types: stats, device warnings, recently updated devices, network topology, EOL status, config drift summary, Wazuh security alerts, audit log activity, discovery jobs status, upcoming scheduled actions, DNS zones overview, site overview, config snapshot history',
|
||||||
|
'Multi-instance widgets with independent per-widget settings, e.g. two warnings widgets scoped to different sites',
|
||||||
|
'Share a dashboard with specific users; recipients can subscribe to always see the owner\'s live version, or clone it into their own editable copy',
|
||||||
|
'Favorite dashboards for quick access from the main menu; set any dashboard as your home view',
|
||||||
|
],
|
||||||
|
},
|
||||||
{
|
{
|
||||||
title: 'Security Integrations',
|
title: 'Security Integrations',
|
||||||
items: [
|
items: [
|
||||||
'Wazuh — agent enrollment tracking, vulnerability counts by severity, recent alert history, CIS benchmark scores, one-click agent install fix stream',
|
'Wazuh — agent enrollment tracking, vulnerability counts by severity, recent alert history, CIS benchmark scores, one-click agent install fix stream',
|
||||||
'Graylog — rsyslog forwarding status per device, one-click fix to write rule',
|
'Graylog — rsyslog forwarding status per device, one-click fix to write rule',
|
||||||
'CrowdSec — org-level decisions, remediation metrics, top attack scenarios',
|
'CrowdSec — org-level decisions, remediation metrics, top attack scenarios',
|
||||||
|
'EOL Tracking — flags devices running end-of-life or soon-to-be-end-of-life firmware/OS via the endoflife.date API, checked daily',
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
@@ -198,7 +252,7 @@ const en = {
|
|||||||
'RBAC with four built-in roles: viewer / operator / engineer / administrator',
|
'RBAC with four built-in roles: viewer / operator / engineer / administrator',
|
||||||
'Permissions enforced end-to-end — nav, routes, and write actions are hidden in the UI to match the backend permission checks, not just disabled',
|
'Permissions enforced end-to-end — nav, routes, and write actions are hidden in the UI to match the backend permission checks, not just disabled',
|
||||||
'Custom roles with any permission combination',
|
'Custom roles with any permission combination',
|
||||||
'Full audit log of all orchestration actions',
|
'Full audit log of all orchestration actions, filterable by date range, user, action, or resource — export to CSV or PDF',
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
@@ -212,10 +266,11 @@ const en = {
|
|||||||
{
|
{
|
||||||
title: 'Compliance & Audit (NIS2)',
|
title: 'Compliance & Audit (NIS2)',
|
||||||
items: [
|
items: [
|
||||||
'Full audit log of all orchestration actions — who changed what, when (Art. 21 (2h))',
|
'Full audit log of all orchestration actions — who changed what, when (Art. 21 (2h)); export to CSV/PDF, filterable by date range, user, action, or resource',
|
||||||
'Two-factor authentication (MFA/TOTP), enforceable per role — administrative access control (Art. 21 (2i))',
|
'Two-factor authentication (MFA/TOTP), enforceable per role — administrative access control (Art. 21 (2i))',
|
||||||
'RBAC with four built-in roles and custom permission sets — access control evidence',
|
'RBAC with four built-in roles and custom permission sets — access control evidence',
|
||||||
'Per-device patch status and installed package list — patch management baseline (Art. 21 (2e))',
|
'Per-device patch status and installed package list — patch management baseline (Art. 21 (2e))',
|
||||||
|
'EOL Tracking plugin flags devices on unsupported firmware/OS via endoflife.date — supply chain security baseline (Art. 21 (2d))',
|
||||||
'Wazuh CVE counts by severity (critical / high / medium) linked to each device record',
|
'Wazuh CVE counts by severity (critical / high / medium) linked to each device record',
|
||||||
'Git-backed configuration snapshot history with diff viewer and OPNsense restore — config-level backup & recovery evidence (Art. 21 (2c))',
|
'Git-backed configuration snapshot history with diff viewer and OPNsense restore — config-level backup & recovery evidence (Art. 21 (2c))',
|
||||||
'Config drift tracking: desired state vs. polled state — detect unauthorized changes',
|
'Config drift tracking: desired state vs. polled state — detect unauthorized changes',
|
||||||
@@ -260,7 +315,7 @@ const en = {
|
|||||||
},
|
},
|
||||||
plugins: {
|
plugins: {
|
||||||
heading: 'Plugin System',
|
heading: 'Plugin System',
|
||||||
sub: 'Integrations are plugins, not core code. Wazuh, Graylog, CrowdSec, and apt-cacher-ng all register through the same pattern — metadata, hooks, tasks, router.',
|
sub: 'Integrations are plugins, not core code. Wazuh, Graylog, CrowdSec, apt-cacher-ng, and EOL Tracking all register through the same pattern — metadata, hooks, tasks, router.',
|
||||||
whatHeading: 'What is a plugin?',
|
whatHeading: 'What is a plugin?',
|
||||||
builtinHeading: 'Built-in plugins',
|
builtinHeading: 'Built-in plugins',
|
||||||
writingHeading: 'Writing a plugin',
|
writingHeading: 'Writing a plugin',
|
||||||
@@ -374,6 +429,10 @@ const de: Translations = {
|
|||||||
heading: 'Konfigurationsbackup und -versionierung',
|
heading: 'Konfigurationsbackup und -versionierung',
|
||||||
body: 'Bei jedem Poll wird ein Konfigurationssnapshot in einem lokalen Git-Repository gespeichert. Der Config-Tab zeigt die vollständige Snapshot-Historie, einen Side-by-Side-Diff zwischen beliebigen Zeitpunkten und — für OPNsense — einen Restore-Button. Nicht autorisierte Änderungen erscheinen als Gerätewarnung.',
|
body: 'Bei jedem Poll wird ein Konfigurationssnapshot in einem lokalen Git-Repository gespeichert. Der Config-Tab zeigt die vollständige Snapshot-Historie, einen Side-by-Side-Diff zwischen beliebigen Zeitpunkten und — für OPNsense — einen Restore-Button. Nicht autorisierte Änderungen erscheinen als Gerätewarnung.',
|
||||||
},
|
},
|
||||||
|
screenshot5: {
|
||||||
|
heading: 'Dashboards, die du wirklich selbst baust',
|
||||||
|
body: 'Aus 13 Widgets wählen und auf einem WYSIWYG-Grid anordnen — kein festes Layout mehr. Ein Dashboard mit einem Kollegen teilen, der es abonnieren oder in eine eigene Kopie klonen kann, und Favoriten im Hauptmenü anpinnen.',
|
||||||
|
},
|
||||||
nis2Label: 'NIS2 · Art. 21',
|
nis2Label: 'NIS2 · Art. 21',
|
||||||
nis2Heading: 'Nachweise, keine Papierwüste.',
|
nis2Heading: 'Nachweise, keine Papierwüste.',
|
||||||
nis2Body: 'NIS2 Art. 21 schreibt Geräteinventar, Patch-Management, Zugangskontrolle und Audit-Trails als technische Basismaßnahmen vor. netOrk fügt keine Compliance-Schicht auf — das sind seine normalen Tagesausgaben.',
|
nis2Body: 'NIS2 Art. 21 schreibt Geräteinventar, Patch-Management, Zugangskontrolle und Audit-Trails als technische Basismaßnahmen vor. netOrk fügt keine Compliance-Schicht auf — das sind seine normalen Tagesausgaben.',
|
||||||
@@ -385,7 +444,7 @@ const de: Translations = {
|
|||||||
{ art: 'Art. 21 (2b)', label: 'Incident-Erkennung', detail: 'Wazuh-Alert-Historie, CrowdSec-Entscheidungen, Graylog-Syslog pro Gerät' },
|
{ art: 'Art. 21 (2b)', label: 'Incident-Erkennung', detail: 'Wazuh-Alert-Historie, CrowdSec-Entscheidungen, Graylog-Syslog pro Gerät' },
|
||||||
],
|
],
|
||||||
pluginsHeading: 'Erweiterbar konzipiert',
|
pluginsHeading: 'Erweiterbar konzipiert',
|
||||||
pluginsBody: 'Integrationen (Wazuh, Graylog, CrowdSec, apt-cacher-ng) sind Plugins, die im Plugin-System registriert werden — sie lassen sich pro Deployment ohne Code-Änderungen aktivieren oder deaktivieren. Eine neue Integration folgt einem dokumentierten Muster mit Hook-Bus, typisiertem Metadatum und Plugin-Registry.',
|
pluginsBody: 'Integrationen (Wazuh, Graylog, CrowdSec, apt-cacher-ng, EOL-Tracking) sind Plugins, die im Plugin-System registriert werden — sie lassen sich pro Deployment ohne Code-Änderungen aktivieren oder deaktivieren. Eine neue Integration folgt einem dokumentierten Muster mit Hook-Bus, typisiertem Metadatum und Plugin-Registry.',
|
||||||
pluginsLink: 'Plugin-System-Dokumentation →',
|
pluginsLink: 'Plugin-System-Dokumentation →',
|
||||||
deployHeading: 'Self-hosted. Ein Befehl.',
|
deployHeading: 'Self-hosted. Ein Befehl.',
|
||||||
deployBody: 'netOrk läuft in Docker Compose. Fünf Container: API, zwei Worker-Pools, ein Beat-Scheduler und ein nginx-UI-Server. Keine externen Abhängigkeiten außer Redis und PostgreSQL.',
|
deployBody: 'netOrk läuft in Docker Compose. Fünf Container: API, zwei Worker-Pools, ein Beat-Scheduler und ein nginx-UI-Server. Keine externen Abhängigkeiten außer Redis und PostgreSQL.',
|
||||||
@@ -418,6 +477,19 @@ const de: Translations = {
|
|||||||
'Manuelle Übernahme aus Scan-Ergebnissen — kein Auto-Create, um Inventar-Rauschen zu vermeiden',
|
'Manuelle Übernahme aus Scan-Ergebnissen — kein Auto-Create, um Inventar-Rauschen zu vermeiden',
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
title: 'VM-Provisioning',
|
||||||
|
items: [
|
||||||
|
'Cloud-Init-basierte VM-Erstellung direkt aus dem VMs-Tab eines Hypervisors — kein manuelles Template- oder VMID-Setup',
|
||||||
|
'Multi-Distro-Image-Katalog: Debian 12, Ubuntu 22.04/24.04/26.04, Fedora 42/43/44 — Ubuntu- und Fedora-Releases werden automatisch synchronisiert, sobald neue Versionen erscheinen',
|
||||||
|
'Ziel-VLAN und IP aus dessen Subnetz auswählen — netOrk legt die DHCP-Reservierung automatisch an',
|
||||||
|
'Cloud-Init richtet einen echten Linux-Benutzer mit SSH-Schlüssel ein, plus konfigurierbare Bootstrap-Optionen (SNMP, QEMU-Guest-Agent)',
|
||||||
|
'Wiederverwendbare Provisioning-Templates für wiederkehrende Bootstrap-Einstellungen',
|
||||||
|
'Die neue VM wird nach Abschluss des Bootstraps automatisch als netOrk-Gerät verknüpft und ihr Hostname einer DNS-Zone zugewiesen',
|
||||||
|
'Deploy-Fortschritt als Live-Schritt-Checkliste in der UI',
|
||||||
|
'VM und verknüpftes netOrk-Gerät gemeinsam löschen, abgesichert durch eine Namens-Bestätigungsabfrage',
|
||||||
|
],
|
||||||
|
},
|
||||||
{
|
{
|
||||||
title: 'Unterstützte Treiber',
|
title: 'Unterstützte Treiber',
|
||||||
items: [
|
items: [
|
||||||
@@ -458,6 +530,20 @@ const de: Translations = {
|
|||||||
'Nicht autorisierte Konfigurationsänderungen werden als Gerätewarnung angezeigt',
|
'Nicht autorisierte Konfigurationsänderungen werden als Gerätewarnung angezeigt',
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
title: 'Konfigurationsautomatisierung (Ansible)',
|
||||||
|
items: [
|
||||||
|
'Wiederverwendbare Ansible-Rollen und -Playbooks, direkt in netOrk gespeichert und bearbeitet — kein separates Git-Checkout',
|
||||||
|
'11 eingebaute Rollen sofort zuweisbar: base, ubuntu, docker, adguard, zoraxy, portainer, watchtower, uptime-kuma, vaultwarden, wireguard, fail2ban',
|
||||||
|
'Automatische Abhängigkeitsauflösung — die Zuweisung von docker zieht base automatisch nach, keine manuelle Rollen-Reihenfolge nötig',
|
||||||
|
'Eingebaute Rollen lassen sich nicht löschen, sind aber vollständig editierbar; Anpassungen überstehen Updates, nur unveränderte Dateien heilen bei Bugfixes automatisch nach',
|
||||||
|
'ansible-doc-gestützte Autovervollständigung beim Schreiben von Rollen und Playbooks',
|
||||||
|
'Eigene Rolle als Archiv hochladen',
|
||||||
|
'Rollenzuweisung auf Geräteebene mit eigenem Ansible-Tab in der Gerätedetailansicht',
|
||||||
|
'Lauf-Historie pro Gerät, mit Snapshot des tatsächlich ausgeführten Rollen-/Playbook-Inhalts',
|
||||||
|
'In VM-Provisioning eingebunden: Rollen bei VM-Erstellung zuweisen — sie laufen automatisch nach dem Boot',
|
||||||
|
],
|
||||||
|
},
|
||||||
{
|
{
|
||||||
title: 'Geplante Operationen',
|
title: 'Geplante Operationen',
|
||||||
items: [
|
items: [
|
||||||
@@ -465,6 +551,17 @@ const de: Translations = {
|
|||||||
'Failback-Cron-Skript auf Gerät geschrieben für netOrk-nicht-erreichbar-Szenarien',
|
'Failback-Cron-Skript auf Gerät geschrieben für netOrk-nicht-erreichbar-Szenarien',
|
||||||
'Geplante Konfigurationsdrift-Korrekturen mit Zeitfenster-Durchsetzung',
|
'Geplante Konfigurationsdrift-Korrekturen mit Zeitfenster-Durchsetzung',
|
||||||
'Paket-Update-Planung und Ein-Klick-Anwendung',
|
'Paket-Update-Planung und Ein-Klick-Anwendung',
|
||||||
|
'Wake-on-LAN über den Treiber einer Firewall (aktuell OPNsense) — gespeicherte WOL-Ziele mit Ein-Klick-„Jetzt wecken" und wiederkehrenden Zeitplänen; ein gesehener Host lässt sich direkt aus den DHCP-/ARP-Tabs als Ziel speichern',
|
||||||
|
],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
title: 'Satellite-Deployments',
|
||||||
|
items: [
|
||||||
|
'Leichtgewichtiger Docker-Agent für Standorte, die netOrk nicht direkt erreicht — pollt Geräte lokal und synct Ergebnisse per HTTPS zurück an Central',
|
||||||
|
'In einem Ablauf per VM-Provisioning deployt: Hypervisor und Standort auswählen, netOrk provisioniert die VM und installiert den Satellite-Container automatisch',
|
||||||
|
'Central überspringt automatisch das direkte Polling für jedes Gerät an einem Standort mit einem online, aktuell heartbeatenden Satellite — kein manuelles Umschalten pro Standort',
|
||||||
|
'Geplante/On-Demand-Neustarts und der SNMP-Auto-Fix laufen über denselben Command-Kanal, egal ob ein Gerät direkt erreichbar ist oder hinter einem Satellite liegt',
|
||||||
|
'Noch nicht satellite-abgedeckt: Discovery-Scans und SNMP-Health-Metrik-Polling laufen weiterhin über Central, und WebSSH-Konsolenzugriff ist über einen Satellite nicht verfügbar',
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
@@ -478,12 +575,24 @@ const de: Translations = {
|
|||||||
'VM/Container-Liste mit OS-Geräteverknüpfung (Proxmox)',
|
'VM/Container-Liste mit OS-Geräteverknüpfung (Proxmox)',
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
title: 'Dashboards',
|
||||||
|
items: [
|
||||||
|
'Konfigurierbare, teilbare Dashboards — eigene Dashboards aus einer Widget-Auswahl bauen statt festes Layout',
|
||||||
|
'WYSIWYG-Grid-Layout-Editor: Widgets auf einem Canvas per Drag & Drop platzieren und in der Größe anpassen',
|
||||||
|
'13 Widget-Typen: Stats, Gerätewarnungen, kürzlich aktualisierte Geräte, Netzwerktopologie, EOL-Status, Konfigurationsdrift-Zusammenfassung, Wazuh-Sicherheitsalerts, Audit-Log-Aktivität, Discovery-Job-Status, anstehende geplante Aktionen, DNS-Zonen-Übersicht, Standortübersicht, Konfigurationssnapshot-Historie',
|
||||||
|
'Mehrfachinstanzen desselben Widgets mit unabhängigen Einstellungen pro Widget, z. B. zwei Warnungs-Widgets für unterschiedliche Standorte',
|
||||||
|
'Dashboard mit bestimmten Benutzern teilen; Empfänger können es abonnieren, um immer die aktuelle Version des Owners zu sehen, oder es als eigene, editierbare Kopie klonen',
|
||||||
|
'Dashboards als Favorit markieren für schnellen Zugriff über das Hauptmenü; jedes Dashboard als Home-Ansicht festlegen',
|
||||||
|
],
|
||||||
|
},
|
||||||
{
|
{
|
||||||
title: 'Sicherheitsintegrationen',
|
title: 'Sicherheitsintegrationen',
|
||||||
items: [
|
items: [
|
||||||
'Wazuh — Agent-Enrollment-Tracking, Schwachstellenanzahl nach Schweregrad, Alert-Historie, CIS-Benchmark-Scores, Ein-Klick-Agent-Install-Fix-Stream',
|
'Wazuh — Agent-Enrollment-Tracking, Schwachstellenanzahl nach Schweregrad, Alert-Historie, CIS-Benchmark-Scores, Ein-Klick-Agent-Install-Fix-Stream',
|
||||||
'Graylog — rsyslog-Weiterleitungsstatus pro Gerät, Ein-Klick-Fix zum Schreiben der Regel',
|
'Graylog — rsyslog-Weiterleitungsstatus pro Gerät, Ein-Klick-Fix zum Schreiben der Regel',
|
||||||
'CrowdSec — Org-Level-Entscheidungen, Remediation-Metriken, Top-Angriffsszenarien',
|
'CrowdSec — Org-Level-Entscheidungen, Remediation-Metriken, Top-Angriffsszenarien',
|
||||||
|
'EOL-Tracking — kennzeichnet Geräte mit End-of-Life- oder bald End-of-Life-Firmware/OS über die endoflife.date-API, täglich geprüft',
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
@@ -503,7 +612,7 @@ const de: Translations = {
|
|||||||
'RBAC mit vier integrierten Rollen: Betrachter / Operator / Ingenieur / Administrator',
|
'RBAC mit vier integrierten Rollen: Betrachter / Operator / Ingenieur / Administrator',
|
||||||
'Berechtigungen durchgängig erzwungen — Navigation, Routen und Schreibaktionen werden in der UI passend zu den Backend-Prüfungen ausgeblendet, nicht nur deaktiviert',
|
'Berechtigungen durchgängig erzwungen — Navigation, Routen und Schreibaktionen werden in der UI passend zu den Backend-Prüfungen ausgeblendet, nicht nur deaktiviert',
|
||||||
'Benutzerdefinierte Rollen mit beliebiger Berechtigungskombination',
|
'Benutzerdefinierte Rollen mit beliebiger Berechtigungskombination',
|
||||||
'Vollständiges Audit-Log aller Orchestrierungsaktionen',
|
'Vollständiges Audit-Log aller Orchestrierungsaktionen, filterbar nach Datumsbereich, Benutzer, Aktion oder Ressource — Export als CSV oder PDF',
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
@@ -517,10 +626,11 @@ const de: Translations = {
|
|||||||
{
|
{
|
||||||
title: 'Compliance & Audit (NIS2)',
|
title: 'Compliance & Audit (NIS2)',
|
||||||
items: [
|
items: [
|
||||||
'Vollständiges Audit-Log aller Orchestrierungsaktionen — wer hat was wann geändert (Art. 21 (2h))',
|
'Vollständiges Audit-Log aller Orchestrierungsaktionen — wer hat was wann geändert (Art. 21 (2h)); Export als CSV/PDF, filterbar nach Datumsbereich, Benutzer, Aktion oder Ressource',
|
||||||
'Zwei-Faktor-Authentifizierung (MFA/TOTP), pro Rolle erzwingbar — Zugangskontrolle für administrative Konten (Art. 21 (2i))',
|
'Zwei-Faktor-Authentifizierung (MFA/TOTP), pro Rolle erzwingbar — Zugangskontrolle für administrative Konten (Art. 21 (2i))',
|
||||||
'RBAC mit vier integrierten Rollen und benutzerdefinierten Berechtigungssätzen — Zugangskontrollnachweis',
|
'RBAC mit vier integrierten Rollen und benutzerdefinierten Berechtigungssätzen — Zugangskontrollnachweis',
|
||||||
'Patch-Status und installierte Paketliste pro Gerät — Patch-Management-Baseline (Art. 21 (2e))',
|
'Patch-Status und installierte Paketliste pro Gerät — Patch-Management-Baseline (Art. 21 (2e))',
|
||||||
|
'EOL-Tracking-Plugin kennzeichnet Geräte mit nicht unterstützter Firmware/OS über endoflife.date — Supply-Chain-Sicherheits-Baseline (Art. 21 (2d))',
|
||||||
'Wazuh-CVE-Anzahl nach Schweregrad (kritisch / hoch / mittel) verknüpft mit jedem Gerätedatensatz',
|
'Wazuh-CVE-Anzahl nach Schweregrad (kritisch / hoch / mittel) verknüpft mit jedem Gerätedatensatz',
|
||||||
'Git-basierte Konfigurationssnapshot-Historie mit Diff-Viewer und OPNsense-Restore — Backup- & Recovery-Nachweis auf Konfigurationsebene (Art. 21 (2c))',
|
'Git-basierte Konfigurationssnapshot-Historie mit Diff-Viewer und OPNsense-Restore — Backup- & Recovery-Nachweis auf Konfigurationsebene (Art. 21 (2c))',
|
||||||
'Konfigurationsdrift-Tracking: Sollzustand vs. abgefragter Zustand — nicht autorisierte Änderungen erkennen',
|
'Konfigurationsdrift-Tracking: Sollzustand vs. abgefragter Zustand — nicht autorisierte Änderungen erkennen',
|
||||||
@@ -565,7 +675,7 @@ const de: Translations = {
|
|||||||
},
|
},
|
||||||
plugins: {
|
plugins: {
|
||||||
heading: 'Plugin-System',
|
heading: 'Plugin-System',
|
||||||
sub: 'Integrationen sind Plugins, kein Core-Code. Wazuh, Graylog, CrowdSec und apt-cacher-ng registrieren sich alle über dasselbe Muster — Metadaten, Hooks, Tasks, Router.',
|
sub: 'Integrationen sind Plugins, kein Core-Code. Wazuh, Graylog, CrowdSec, apt-cacher-ng und EOL-Tracking registrieren sich alle über dasselbe Muster — Metadaten, Hooks, Tasks, Router.',
|
||||||
whatHeading: 'Was ist ein Plugin?',
|
whatHeading: 'Was ist ein Plugin?',
|
||||||
builtinHeading: 'Eingebaute Plugins',
|
builtinHeading: 'Eingebaute Plugins',
|
||||||
writingHeading: 'Ein Plugin schreiben',
|
writingHeading: 'Ein Plugin schreiben',
|
||||||
|
|||||||
@@ -199,6 +199,33 @@ function MockConfigDiff() {
|
|||||||
)
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function MockDashboard() {
|
||||||
|
const widgets = [
|
||||||
|
{ label: 'Stats', span: 'col-span-2' },
|
||||||
|
{ label: 'Device Warnings', span: 'col-span-1' },
|
||||||
|
{ label: 'Network Topology', span: 'col-span-2' },
|
||||||
|
{ label: 'EOL Status', span: 'col-span-1' },
|
||||||
|
]
|
||||||
|
return (
|
||||||
|
<div className="bg-slate-950 p-4">
|
||||||
|
<div className="mb-3 flex items-center justify-between">
|
||||||
|
<span className="text-xs font-semibold text-slate-100">My Dashboard</span>
|
||||||
|
<div className="flex items-center gap-2">
|
||||||
|
<span className="text-xs px-2 py-0.5 rounded-full bg-sky-500/15 text-sky-400 border border-sky-500/20">shared</span>
|
||||||
|
<span className="text-xs px-2.5 py-1 rounded-md bg-sky-600 text-white">+ Add Widget</span>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
<div className="grid grid-cols-3 gap-2">
|
||||||
|
{widgets.map((w) => (
|
||||||
|
<div key={w.label} className={`${w.span} rounded-lg border border-dashed border-slate-700 bg-slate-900 p-3 h-16 flex items-center justify-center`}>
|
||||||
|
<span className="text-xs text-slate-500">{w.label}</span>
|
||||||
|
</div>
|
||||||
|
))}
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
function MockCompliance() {
|
function MockCompliance() {
|
||||||
const checks = [
|
const checks = [
|
||||||
{ label: 'Asset inventory', detail: '18 / 18 devices tracked', ok: true },
|
{ label: 'Asset inventory', detail: '18 / 18 devices tracked', ok: true },
|
||||||
@@ -418,6 +445,15 @@ export default function Home() {
|
|||||||
<p className="text-base text-slate-400 leading-relaxed">{linkify(h.screenshot4.body)}</p>
|
<p className="text-base text-slate-400 leading-relaxed">{linkify(h.screenshot4.body)}</p>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
<div className="grid md:grid-cols-2 gap-12 items-center">
|
||||||
|
<div>
|
||||||
|
<h2 className="text-2xl md:text-3xl font-bold text-slate-100 mb-4">{h.screenshot5.heading}</h2>
|
||||||
|
<p className="text-base text-slate-400 leading-relaxed">{linkify(h.screenshot5.body)}</p>
|
||||||
|
</div>
|
||||||
|
<BrowserFrame label="netork.local / dashboards / my-dashboard">
|
||||||
|
<MockDashboard />
|
||||||
|
</BrowserFrame>
|
||||||
|
</div>
|
||||||
</div>
|
</div>
|
||||||
</section>
|
</section>
|
||||||
|
|
||||||
|
|||||||
+6
-10
@@ -13,11 +13,11 @@ const REQUIREMENTS: Record<'en' | 'de', Requirement[]> = {
|
|||||||
{ article: 'Art. 21 (2a)', label: 'Risk analysis & information system security policies', coverage: 'partial', netork: 'Config drift detection, SNMP health metrics, and security agent coverage across all devices provide a continuous risk baseline. A formal risk register is out of scope for netOrk.' },
|
{ article: 'Art. 21 (2a)', label: 'Risk analysis & information system security policies', coverage: 'partial', netork: 'Config drift detection, SNMP health metrics, and security agent coverage across all devices provide a continuous risk baseline. A formal risk register is out of scope for netOrk.' },
|
||||||
{ article: 'Art. 21 (2b)', label: 'Incident handling', coverage: 'partial', netork: 'Wazuh alert history, CrowdSec decisions, and Graylog syslog per device surface incidents at the network layer. A structured incident record with NIS2 Art. 23 reporting timers is on the roadmap.' },
|
{ article: 'Art. 21 (2b)', label: 'Incident handling', coverage: 'partial', netork: 'Wazuh alert history, CrowdSec decisions, and Graylog syslog per device surface incidents at the network layer. A structured incident record with NIS2 Art. 23 reporting timers is on the roadmap.' },
|
||||||
{ article: 'Art. 21 (2c)', label: 'Business continuity, backup management, disaster recovery', coverage: 'partial', netork: 'Every poll captures a configuration snapshot into a local Git repository — full history, a side-by-side diff viewer between any two points in time, and one-click restore for OPNsense. Backup/recovery for full device state beyond configuration is out of scope.' },
|
{ article: 'Art. 21 (2c)', label: 'Business continuity, backup management, disaster recovery', coverage: 'partial', netork: 'Every poll captures a configuration snapshot into a local Git repository — full history, a side-by-side diff viewer between any two points in time, and one-click restore for OPNsense. Backup/recovery for full device state beyond configuration is out of scope.' },
|
||||||
{ article: 'Art. 21 (2d)', label: 'Supply chain security', coverage: 'partial', netork: 'Vendor, model, firmware, and OS version are tracked per device after every poll. EOL tracking against endoflife.date is on the roadmap to flag unsupported software.' },
|
{ article: 'Art. 21 (2d)', label: 'Supply chain security', coverage: 'covered', netork: 'Vendor, model, firmware, and OS version are tracked per device after every poll. The EOL Tracking plugin checks each device\'s OS version against the endoflife.date API daily and flags unsupported or soon-to-be-unsupported software.' },
|
||||||
{ article: 'Art. 21 (2e)', label: 'Vulnerability handling in acquisition, development & maintenance', coverage: 'covered', netork: 'Per-device update status and installed package list tracked on every poll. Wazuh CVE counts by severity (critical / high / medium) linked directly to each device record. CVE cross-reference against NVD/OSV (without Wazuh) is on the roadmap.' },
|
{ article: 'Art. 21 (2e)', label: 'Vulnerability handling in acquisition, development & maintenance', coverage: 'covered', netork: 'Per-device update status and installed package list tracked on every poll. Wazuh CVE counts by severity (critical / high / medium) linked directly to each device record. CVE cross-reference against NVD/OSV (without Wazuh) is on the roadmap.' },
|
||||||
{ article: 'Art. 21 (2f)', label: 'Assessing effectiveness of cybersecurity measures', coverage: 'partial', netork: 'The audit log records all orchestration actions. A per-site compliance dashboard (on roadmap) will aggregate security agent coverage, drift status, and patch metrics into a single view.' },
|
{ article: 'Art. 21 (2f)', label: 'Assessing effectiveness of cybersecurity measures', coverage: 'partial', netork: 'The audit log records all orchestration actions. A per-site compliance dashboard (on roadmap) will aggregate security agent coverage, drift status, and patch metrics into a single view.' },
|
||||||
{ article: 'Art. 21 (2g)', label: 'Basic cyber hygiene & cybersecurity training', coverage: 'na', netork: 'Out of scope for a network orchestration platform. Training and hygiene policies are handled at the organizational level.' },
|
{ article: 'Art. 21 (2g)', label: 'Basic cyber hygiene & cybersecurity training', coverage: 'na', netork: 'Out of scope for a network orchestration platform. Training and hygiene policies are handled at the organizational level.' },
|
||||||
{ article: 'Art. 21 (2h)', label: 'Access control, asset management, human resources security', coverage: 'covered', netork: 'Full device inventory maintained automatically via discovery and continuous polling. RBAC with four built-in roles (viewer / operator / engineer / administrator) and custom role combinations. Complete audit log of all orchestration actions.' },
|
{ article: 'Art. 21 (2h)', label: 'Access control, asset management, human resources security', coverage: 'covered', netork: 'Full device inventory maintained automatically via discovery and continuous polling. RBAC with four built-in roles (viewer / operator / engineer / administrator) and custom role combinations. Complete audit log of all orchestration actions, filterable by date range, user, action, or resource — export to CSV or PDF for audit submissions.' },
|
||||||
{ article: 'Art. 21 (2i)', label: 'Multi-factor authentication', coverage: 'covered', netork: 'TOTP-based MFA for netOrk user accounts — authenticator app at login, backup codes for emergencies, session invalidation on TOTP changes, enforceable per role.' },
|
{ article: 'Art. 21 (2i)', label: 'Multi-factor authentication', coverage: 'covered', netork: 'TOTP-based MFA for netOrk user accounts — authenticator app at login, backup codes for emergencies, session invalidation on TOTP changes, enforceable per role.' },
|
||||||
{ article: 'Art. 21 (2j)', label: 'Physical and environmental security', coverage: 'na', netork: 'Out of scope. Physical security of the infrastructure hosting netOrk is an organizational and facility concern.' },
|
{ article: 'Art. 21 (2j)', label: 'Physical and environmental security', coverage: 'na', netork: 'Out of scope. Physical security of the infrastructure hosting netOrk is an organizational and facility concern.' },
|
||||||
],
|
],
|
||||||
@@ -25,11 +25,11 @@ const REQUIREMENTS: Record<'en' | 'de', Requirement[]> = {
|
|||||||
{ article: 'Art. 21 (2a)', label: 'Risikoanalyse und Sicherheitsrichtlinien für Informationssysteme', coverage: 'partial', netork: 'Konfigurationsdrift-Erkennung, SNMP-Gesundheitsmetriken und Security-Agent-Abdeckung über alle Geräte liefern eine kontinuierliche Risiko-Baseline. Ein formales Risikoregister liegt außerhalb des Scopes von netOrk.' },
|
{ article: 'Art. 21 (2a)', label: 'Risikoanalyse und Sicherheitsrichtlinien für Informationssysteme', coverage: 'partial', netork: 'Konfigurationsdrift-Erkennung, SNMP-Gesundheitsmetriken und Security-Agent-Abdeckung über alle Geräte liefern eine kontinuierliche Risiko-Baseline. Ein formales Risikoregister liegt außerhalb des Scopes von netOrk.' },
|
||||||
{ article: 'Art. 21 (2b)', label: 'Bewältigung von Sicherheitsvorfällen', coverage: 'partial', netork: 'Wazuh-Alert-Historie, CrowdSec-Entscheidungen und Graylog-Syslog pro Gerät decken Vorfälle auf Netzwerkebene auf. Ein strukturierter Incident-Datensatz mit NIS2 Art. 23 Melde-Timern ist auf der Roadmap.' },
|
{ article: 'Art. 21 (2b)', label: 'Bewältigung von Sicherheitsvorfällen', coverage: 'partial', netork: 'Wazuh-Alert-Historie, CrowdSec-Entscheidungen und Graylog-Syslog pro Gerät decken Vorfälle auf Netzwerkebene auf. Ein strukturierter Incident-Datensatz mit NIS2 Art. 23 Melde-Timern ist auf der Roadmap.' },
|
||||||
{ article: 'Art. 21 (2c)', label: 'Geschäftskontinuität, Backup-Management, Disaster Recovery', coverage: 'partial', netork: 'Bei jedem Poll wird ein Konfigurationssnapshot in einem lokalen Git-Repository gespeichert — vollständige Historie, ein Side-by-Side-Diff-Viewer zwischen beliebigen Zeitpunkten und Ein-Klick-Restore für OPNsense. Backup/Recovery für den vollständigen Gerätezustand über die Konfiguration hinaus liegt außerhalb des Scopes.' },
|
{ article: 'Art. 21 (2c)', label: 'Geschäftskontinuität, Backup-Management, Disaster Recovery', coverage: 'partial', netork: 'Bei jedem Poll wird ein Konfigurationssnapshot in einem lokalen Git-Repository gespeichert — vollständige Historie, ein Side-by-Side-Diff-Viewer zwischen beliebigen Zeitpunkten und Ein-Klick-Restore für OPNsense. Backup/Recovery für den vollständigen Gerätezustand über die Konfiguration hinaus liegt außerhalb des Scopes.' },
|
||||||
{ article: 'Art. 21 (2d)', label: 'Supply-Chain-Sicherheit', coverage: 'partial', netork: 'Hersteller, Modell, Firmware und OS-Version werden nach jedem Poll pro Gerät erfasst. EOL-Tracking über endoflife.date ist auf der Roadmap, um nicht unterstützte Software zu kennzeichnen.' },
|
{ article: 'Art. 21 (2d)', label: 'Supply-Chain-Sicherheit', coverage: 'covered', netork: 'Hersteller, Modell, Firmware und OS-Version werden nach jedem Poll pro Gerät erfasst. Das EOL-Tracking-Plugin gleicht die OS-Version jedes Geräts täglich mit der endoflife.date-API ab und kennzeichnet nicht mehr oder bald nicht mehr unterstützte Software.' },
|
||||||
{ article: 'Art. 21 (2e)', label: 'Schwachstellenbehandlung bei Erwerb, Entwicklung & Wartung', coverage: 'covered', netork: 'Update-Status und installierte Paketliste pro Gerät werden bei jedem Poll erfasst. Wazuh-CVE-Anzahl nach Schweregrad (kritisch / hoch / mittel) direkt mit jedem Gerätedatensatz verknüpft. CVE-Abgleich gegen NVD/OSV (ohne Wazuh) ist auf der Roadmap.' },
|
{ article: 'Art. 21 (2e)', label: 'Schwachstellenbehandlung bei Erwerb, Entwicklung & Wartung', coverage: 'covered', netork: 'Update-Status und installierte Paketliste pro Gerät werden bei jedem Poll erfasst. Wazuh-CVE-Anzahl nach Schweregrad (kritisch / hoch / mittel) direkt mit jedem Gerätedatensatz verknüpft. CVE-Abgleich gegen NVD/OSV (ohne Wazuh) ist auf der Roadmap.' },
|
||||||
{ article: 'Art. 21 (2f)', label: 'Beurteilung der Wirksamkeit von Cybersicherheitsmaßnahmen', coverage: 'partial', netork: 'Das Audit-Log erfasst alle Orchestrierungsaktionen. Ein Compliance-Dashboard pro Standort (auf der Roadmap) wird Security-Agent-Abdeckung, Drift-Status und Patch-Metriken in einer Ansicht zusammenfassen.' },
|
{ article: 'Art. 21 (2f)', label: 'Beurteilung der Wirksamkeit von Cybersicherheitsmaßnahmen', coverage: 'partial', netork: 'Das Audit-Log erfasst alle Orchestrierungsaktionen. Ein Compliance-Dashboard pro Standort (auf der Roadmap) wird Security-Agent-Abdeckung, Drift-Status und Patch-Metriken in einer Ansicht zusammenfassen.' },
|
||||||
{ article: 'Art. 21 (2g)', label: 'Grundlegende Cyberhygiene und Cybersicherheitsschulungen', coverage: 'na', netork: 'Außerhalb des Scopes einer Netzwerk-Orchestrierungsplattform. Schulungen und Hygiene-Richtlinien werden auf Organisationsebene gehandhabt.' },
|
{ article: 'Art. 21 (2g)', label: 'Grundlegende Cyberhygiene und Cybersicherheitsschulungen', coverage: 'na', netork: 'Außerhalb des Scopes einer Netzwerk-Orchestrierungsplattform. Schulungen und Hygiene-Richtlinien werden auf Organisationsebene gehandhabt.' },
|
||||||
{ article: 'Art. 21 (2h)', label: 'Zugangskontrolle, Asset-Management, Personalsicherheit', coverage: 'covered', netork: 'Vollständiges Geräteinventar automatisch über Discovery und kontinuierliches Polling gepflegt. RBAC mit vier integrierten Rollen (Betrachter / Operator / Ingenieur / Administrator) und benutzerdefinierten Rollenkombinationen. Vollständiges Audit-Log aller Orchestrierungsaktionen.' },
|
{ article: 'Art. 21 (2h)', label: 'Zugangskontrolle, Asset-Management, Personalsicherheit', coverage: 'covered', netork: 'Vollständiges Geräteinventar automatisch über Discovery und kontinuierliches Polling gepflegt. RBAC mit vier integrierten Rollen (Betrachter / Operator / Ingenieur / Administrator) und benutzerdefinierten Rollenkombinationen. Vollständiges Audit-Log aller Orchestrierungsaktionen, filterbar nach Datumsbereich, Benutzer, Aktion oder Ressource — Export als CSV oder PDF für Audit-Einreichungen.' },
|
||||||
{ article: 'Art. 21 (2i)', label: 'Multi-Faktor-Authentifizierung', coverage: 'covered', netork: 'TOTP-basierte MFA für netOrk-Benutzerkonten — Authenticator-App beim Login, Backup-Codes für Notfälle, Session-Invalidierung bei TOTP-Änderungen, pro Rolle erzwingbar.' },
|
{ article: 'Art. 21 (2i)', label: 'Multi-Faktor-Authentifizierung', coverage: 'covered', netork: 'TOTP-basierte MFA für netOrk-Benutzerkonten — Authenticator-App beim Login, Backup-Codes für Notfälle, Session-Invalidierung bei TOTP-Änderungen, pro Rolle erzwingbar.' },
|
||||||
{ article: 'Art. 21 (2j)', label: 'Physische und umgebungsbezogene Sicherheit', coverage: 'na', netork: 'Außerhalb des Scopes. Die physische Sicherheit der Infrastruktur, die netOrk hostet, ist eine organisatorische und gebäudetechnische Angelegenheit.' },
|
{ article: 'Art. 21 (2j)', label: 'Physische und umgebungsbezogene Sicherheit', coverage: 'na', netork: 'Außerhalb des Scopes. Die physische Sicherheit der Infrastruktur, die netOrk hostet, ist eine organisatorische und gebäudetechnische Angelegenheit.' },
|
||||||
],
|
],
|
||||||
@@ -66,7 +66,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = {
|
|||||||
'Subnet browser — IP space coverage',
|
'Subnet browser — IP space coverage',
|
||||||
'VLAN matrix — which devices carry which VLANs',
|
'VLAN matrix — which devices carry which VLANs',
|
||||||
'Configuration diff between any two snapshots; one-click restore (OPNsense)',
|
'Configuration diff between any two snapshots; one-click restore (OPNsense)',
|
||||||
'Audit log export to PDF / CSV (roadmap)',
|
'Audit log export to PDF / CSV, filtered by date range, user, action, or resource',
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
],
|
],
|
||||||
@@ -100,7 +100,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = {
|
|||||||
'Subnetz-Browser — IP-Raum-Abdeckung',
|
'Subnetz-Browser — IP-Raum-Abdeckung',
|
||||||
'VLAN-Matrix — welche Geräte welche VLANs führen',
|
'VLAN-Matrix — welche Geräte welche VLANs führen',
|
||||||
'Konfigurations-Diff zwischen zwei beliebigen Snapshots; Ein-Klick-Restore (OPNsense)',
|
'Konfigurations-Diff zwischen zwei beliebigen Snapshots; Ein-Klick-Restore (OPNsense)',
|
||||||
'Audit-Log-Export als PDF / CSV (Roadmap)',
|
'Audit-Log-Export als PDF / CSV, gefiltert nach Datumsbereich, Benutzer, Aktion oder Ressource',
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
],
|
],
|
||||||
@@ -110,16 +110,12 @@ const COMING: Record<'en' | 'de', ComingItem[]> = {
|
|||||||
en: [
|
en: [
|
||||||
{ title: 'CVE tracking per device', detail: 'Automatic cross-reference of installed packages against NVD / OSV — no Wazuh agent required.' },
|
{ title: 'CVE tracking per device', detail: 'Automatic cross-reference of installed packages against NVD / OSV — no Wazuh agent required.' },
|
||||||
{ title: 'Compliance dashboard', detail: 'Per-site Art. 21 checklist: asset coverage, patch status, agent deployment, drift, syslog, audit activity.' },
|
{ title: 'Compliance dashboard', detail: 'Per-site Art. 21 checklist: asset coverage, patch status, agent deployment, drift, syslog, audit activity.' },
|
||||||
{ title: 'Audit log export', detail: 'PDF and CSV export filtered by date range, device, user, or action — ready to hand to an auditor.' },
|
|
||||||
{ title: 'Incident workflow', detail: 'Structured incident records with NIS2 Art. 23 reporting timers (24 h / 72 h) and external webhook delivery.' },
|
{ title: 'Incident workflow', detail: 'Structured incident records with NIS2 Art. 23 reporting timers (24 h / 72 h) and external webhook delivery.' },
|
||||||
{ title: 'EOL tracking', detail: 'Flag devices running end-of-life firmware or OS versions via the endoflife.date API.' },
|
|
||||||
],
|
],
|
||||||
de: [
|
de: [
|
||||||
{ title: 'CVE-Tracking pro Gerät', detail: 'Automatischer Abgleich installierter Pakete gegen NVD / OSV — kein Wazuh-Agent erforderlich.' },
|
{ title: 'CVE-Tracking pro Gerät', detail: 'Automatischer Abgleich installierter Pakete gegen NVD / OSV — kein Wazuh-Agent erforderlich.' },
|
||||||
{ title: 'Compliance-Dashboard', detail: 'Art. 21-Checkliste pro Standort: Asset-Abdeckung, Patch-Status, Agent-Deployment, Drift, Syslog, Audit-Aktivität.' },
|
{ title: 'Compliance-Dashboard', detail: 'Art. 21-Checkliste pro Standort: Asset-Abdeckung, Patch-Status, Agent-Deployment, Drift, Syslog, Audit-Aktivität.' },
|
||||||
{ title: 'Audit-Log-Export', detail: 'PDF- und CSV-Export gefiltert nach Datumsbereich, Gerät, Benutzer oder Aktion — bereit zur Übergabe an einen Prüfer.' },
|
|
||||||
{ title: 'Incident-Workflow', detail: 'Strukturierte Incident-Datensätze mit NIS2 Art. 23 Melde-Timern (24 h / 72 h) und externer Webhook-Zustellung.' },
|
{ title: 'Incident-Workflow', detail: 'Strukturierte Incident-Datensätze mit NIS2 Art. 23 Melde-Timern (24 h / 72 h) und externer Webhook-Zustellung.' },
|
||||||
{ title: 'EOL-Tracking', detail: 'Geräte mit End-of-Life-Firmware oder OS-Versionen über die endoflife.date-API kennzeichnen.' },
|
|
||||||
],
|
],
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -29,12 +29,14 @@ const BUILTIN: Record<'en' | 'de', BuiltinPlugin[]> = {
|
|||||||
{ label: 'Graylog Syslog', body: 'Checks whether syslog-capable devices forward logs to Graylog via rsyslog, and can automatically write the forwarding rule.', hosts: [], hooks: [] },
|
{ label: 'Graylog Syslog', body: 'Checks whether syslog-capable devices forward logs to Graylog via rsyslog, and can automatically write the forwarding rule.', hosts: [], hooks: [] },
|
||||||
{ label: 'CrowdSec', body: 'Surfaces org-level CrowdSec security health data per device: active decisions, blocked requests, remediation metrics, and top attack scenarios.', hosts: ['admin.api.crowdsec.net:443'], hooks: [] },
|
{ label: 'CrowdSec', body: 'Surfaces org-level CrowdSec security health data per device: active decisions, blocked requests, remediation metrics, and top attack scenarios.', hosts: ['admin.api.crowdsec.net:443'], hooks: [] },
|
||||||
{ label: 'apt-cacher-ng', body: "Auto-detects apt-cacher-ng on Docker hosts and configures the APT proxy on devices within the same site so APT traffic is routed through the local cache.", hosts: [], hooks: ['poll.complete'] },
|
{ label: 'apt-cacher-ng', body: "Auto-detects apt-cacher-ng on Docker hosts and configures the APT proxy on devices within the same site so APT traffic is routed through the local cache.", hosts: [], hooks: ['poll.complete'] },
|
||||||
|
{ label: 'EOL Tracking', body: "Flags devices running end-of-life or soon-to-be-end-of-life firmware/OS versions, checked daily against the endoflife.date API. Reuses the OS version already collected during polling — no extra device I/O.", hosts: ['endoflife.date'], hooks: [] },
|
||||||
],
|
],
|
||||||
de: [
|
de: [
|
||||||
{ label: 'Wazuh Security', body: 'Synchronisiert die Geräte-Registrierung mit dem Wazuh-Manager und zeigt Agent-Health-Warnungen, Schwachstellenanzahl, Alerts und CIS-Benchmark-Scores an.', hosts: ['wazuh-manager:55000', 'wazuh-indexer:9200'], hooks: ['poll.complete'] },
|
{ label: 'Wazuh Security', body: 'Synchronisiert die Geräte-Registrierung mit dem Wazuh-Manager und zeigt Agent-Health-Warnungen, Schwachstellenanzahl, Alerts und CIS-Benchmark-Scores an.', hosts: ['wazuh-manager:55000', 'wazuh-indexer:9200'], hooks: ['poll.complete'] },
|
||||||
{ label: 'Graylog Syslog', body: 'Prüft, ob syslog-fähige Geräte Logs via rsyslog an Graylog weiterleiten, und kann die Weiterleitungsregel automatisch schreiben.', hosts: [], hooks: [] },
|
{ label: 'Graylog Syslog', body: 'Prüft, ob syslog-fähige Geräte Logs via rsyslog an Graylog weiterleiten, und kann die Weiterleitungsregel automatisch schreiben.', hosts: [], hooks: [] },
|
||||||
{ label: 'CrowdSec', body: 'Zeigt Org-Level-CrowdSec-Sicherheitsdaten pro Gerät: aktive Entscheidungen, geblockte Requests, Remediation-Metriken und Top-Angriffsszenarien.', hosts: ['admin.api.crowdsec.net:443'], hooks: [] },
|
{ label: 'CrowdSec', body: 'Zeigt Org-Level-CrowdSec-Sicherheitsdaten pro Gerät: aktive Entscheidungen, geblockte Requests, Remediation-Metriken und Top-Angriffsszenarien.', hosts: ['admin.api.crowdsec.net:443'], hooks: [] },
|
||||||
{ label: 'apt-cacher-ng', body: 'Erkennt apt-cacher-ng automatisch auf Docker-Hosts und konfiguriert den APT-Proxy auf Geräten im selben Standort, sodass APT-Traffic über den lokalen Cache läuft.', hosts: [], hooks: ['poll.complete'] },
|
{ label: 'apt-cacher-ng', body: 'Erkennt apt-cacher-ng automatisch auf Docker-Hosts und konfiguriert den APT-Proxy auf Geräten im selben Standort, sodass APT-Traffic über den lokalen Cache läuft.', hosts: [], hooks: ['poll.complete'] },
|
||||||
|
{ label: 'EOL-Tracking', body: 'Kennzeichnet Geräte mit End-of-Life- oder bald End-of-Life-Firmware/OS, täglich gegen die endoflife.date-API geprüft. Nutzt die beim Polling bereits erfasste OS-Version — keine zusätzliche Geräte-I/O.', hosts: ['endoflife.date'], hooks: [] },
|
||||||
],
|
],
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -19,11 +19,6 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
|
|||||||
detail: 'Per-site Art. 21 checklist: asset coverage, patch status, security agent deployment, config drift, syslog forwarding, audit activity — aggregated into a single view.',
|
detail: 'Per-site Art. 21 checklist: asset coverage, patch status, security agent deployment, config drift, syslog forwarding, audit activity — aggregated into a single view.',
|
||||||
nis2: true,
|
nis2: true,
|
||||||
},
|
},
|
||||||
{
|
|
||||||
title: 'Audit log export',
|
|
||||||
detail: 'PDF and CSV export of the audit log, filtered by date range, device, user, or action type. For NIS2 audit submissions and internal reviews.',
|
|
||||||
nis2: true,
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
title: 'Webhook engine',
|
title: 'Webhook engine',
|
||||||
detail: 'Outbound HTTP webhooks for events: device discovered, config change detected, job failed, alert threshold exceeded. HMAC-SHA256 payload signing. Integrates with n8n, Slack, PagerDuty.',
|
detail: 'Outbound HTTP webhooks for events: device discovered, config change detected, job failed, alert threshold exceeded. HMAC-SHA256 payload signing. Integrates with n8n, Slack, PagerDuty.',
|
||||||
@@ -59,11 +54,6 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
|
|||||||
detail: 'Structured incident record tied to devices and security events. Deadline tracker for NIS2 Art. 23 reporting windows (24 h early warning, 72 h full notification). Webhook to external ticketing systems.',
|
detail: 'Structured incident record tied to devices and security events. Deadline tracker for NIS2 Art. 23 reporting windows (24 h early warning, 72 h full notification). Webhook to external ticketing systems.',
|
||||||
nis2: true,
|
nis2: true,
|
||||||
},
|
},
|
||||||
{
|
|
||||||
title: 'EOL tracking for firmware and OS',
|
|
||||||
detail: 'Flag devices running end-of-life software via the endoflife.date API. Covers OPNsense, OpenWRT, Debian, Ubuntu, and more — matched to the OS versions netOrk already polls.',
|
|
||||||
nis2: true,
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
title: 'mDNS scanner',
|
title: 'mDNS scanner',
|
||||||
detail: 'Discover media devices (Apple TV, Chromecast, Sonos) via mDNS/Bonjour without needing a NAPALM driver. Inventory visibility and firewall segmentation suggestions.',
|
detail: 'Discover media devices (Apple TV, Chromecast, Sonos) via mDNS/Bonjour without needing a NAPALM driver. Inventory visibility and firewall segmentation suggestions.',
|
||||||
@@ -93,11 +83,6 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
|
|||||||
detail: 'Art. 21-Checkliste pro Standort: Asset-Abdeckung, Patch-Status, Security-Agent-Deployment, Config-Drift, Syslog-Weiterleitung, Audit-Aktivität — zusammengefasst in einer Ansicht.',
|
detail: 'Art. 21-Checkliste pro Standort: Asset-Abdeckung, Patch-Status, Security-Agent-Deployment, Config-Drift, Syslog-Weiterleitung, Audit-Aktivität — zusammengefasst in einer Ansicht.',
|
||||||
nis2: true,
|
nis2: true,
|
||||||
},
|
},
|
||||||
{
|
|
||||||
title: 'Audit-Log-Export',
|
|
||||||
detail: 'PDF- und CSV-Export des Audit-Logs, gefiltert nach Datumsbereich, Gerät, Benutzer oder Aktionstyp. Für NIS2-Audit-Einreichungen und interne Reviews.',
|
|
||||||
nis2: true,
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
title: 'Webhook-Engine',
|
title: 'Webhook-Engine',
|
||||||
detail: 'Ausgehende HTTP-Webhooks für Events: Gerät entdeckt, Konfigurationsänderung erkannt, Job fehlgeschlagen, Warnschwelle überschritten. HMAC-SHA256-Payload-Signierung. Integrierbar mit n8n, Slack, PagerDuty.',
|
detail: 'Ausgehende HTTP-Webhooks für Events: Gerät entdeckt, Konfigurationsänderung erkannt, Job fehlgeschlagen, Warnschwelle überschritten. HMAC-SHA256-Payload-Signierung. Integrierbar mit n8n, Slack, PagerDuty.',
|
||||||
@@ -133,11 +118,6 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
|
|||||||
detail: 'Strukturierter Incident-Datensatz, verknüpft mit Geräten und Sicherheitsereignissen. Fristen-Tracker für NIS2 Art. 23 Meldepflichten (24 h Frühwarnung, 72 h vollständige Meldung). Webhook zu externen Ticketing-Systemen.',
|
detail: 'Strukturierter Incident-Datensatz, verknüpft mit Geräten und Sicherheitsereignissen. Fristen-Tracker für NIS2 Art. 23 Meldepflichten (24 h Frühwarnung, 72 h vollständige Meldung). Webhook zu externen Ticketing-Systemen.',
|
||||||
nis2: true,
|
nis2: true,
|
||||||
},
|
},
|
||||||
{
|
|
||||||
title: 'EOL-Tracking für Firmware und OS',
|
|
||||||
detail: 'Markiert Geräte mit End-of-Life-Software über die endoflife.date-API. Deckt OPNsense, OpenWRT, Debian, Ubuntu und weitere ab — abgeglichen mit den OS-Versionen, die netOrk bereits abfragt.',
|
|
||||||
nis2: true,
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
title: 'mDNS-Scanner',
|
title: 'mDNS-Scanner',
|
||||||
detail: 'Entdeckt Mediengeräte (Apple TV, Chromecast, Sonos) über mDNS/Bonjour ohne NAPALM-Treiber. Inventarsichtbarkeit und Empfehlungen zur Firewall-Segmentierung.',
|
detail: 'Entdeckt Mediengeräte (Apple TV, Chromecast, Sonos) über mDNS/Bonjour ohne NAPALM-Treiber. Inventarsichtbarkeit und Empfehlungen zur Firewall-Segmentierung.',
|
||||||
|
|||||||
Reference in New Issue
Block a user