import { useLang } from '../context/LangContext' import { linkify } from '../lib/glossary' type Item = { title: string; detail: string; nis2?: boolean } type Group = { label: string; items: Item[] } const GROUPS: Record<'en' | 'de', Group[]> = { en: [ { label: 'Next release', items: [ { title: 'CrowdSec across sites', detail: 'The CrowdSec plugin grows into its own section: every LAPI instance, decisions and alerts across sites, how many sites one address reached, bans inside your own subnets counted separately, and which internet-facing hosts nobody watches yet.', }, { title: 'Windows driver', detail: 'Windows hosts over WinRM: facts, interfaces, ARP, routes and services, including service control.', }, { title: 'Single-use console tickets', detail: 'The browser terminal opens with a one-time ticket instead of passing the session token in the WebSocket URL.', nis2: true, }, { title: 'Honest reboots', detail: 'A reboot request for a device whose driver cannot restart it is refused with a reason instead of being reported as done.', }, ], }, { label: 'Planned', items: [ { title: 'Compliance dashboard', detail: 'Per-site Art. 21 checklist: asset coverage, patch status, security agent deployment, config drift, syslog forwarding, audit activity — aggregated into a single view.', nis2: true, }, { title: 'Webhook engine', detail: 'Outbound HTTP webhooks for events: device discovered, config change detected, job failed, alert threshold exceeded. HMAC-SHA256 payload signing. Integrates with n8n, Slack, PagerDuty.', }, { title: 'Live job log streaming', detail: 'WebSocket endpoint for real-time Celery task output in the UI. Currently streamed via SSE for fix-flows; full job log streaming for all long-running operations.', }, { title: 'NetBox sync — manual trigger & status view', detail: 'POST /api/v1/netbox/sync endpoint with progress feedback and a sync history view in the UI. Currently sync runs automatically; the manual trigger and status are missing.', }, { title: 'HashiCorp Vault integration', detail: 'Real secret management as the first security plugin, replacing the current Fernet-based encryption at rest for device credentials and SSH keys.', nis2: true, }, { title: 'Firewall profile management — next steps', detail: 'Per-site profiles with a diff against a live OPNsense and step-by-step apply shipped in 0.12. Profile types, OpenWrt as a target, and the push mechanism beyond that are still under review.', }, ], }, { label: 'Under consideration', items: [ { title: 'VLAN visualization', detail: 'Heatmap or matrix view of which devices carry which VLANs, without digging through per-device VLAN lists.', }, { title: 'Incident workflow', detail: 'Structured incident record tied to devices and security events. Deadline tracker for NIS2 Art. 23 reporting windows (24 h early warning, 72 h full notification). Webhook to external ticketing systems.', nis2: true, }, { title: 'mDNS scanner', detail: 'Discover media devices (Apple TV, Chromecast, Sonos) via mDNS/Bonjour without needing a NAPALM driver. Inventory visibility and firewall segmentation suggestions.', }, { title: 'Prometheus metrics + Grafana dashboards', detail: 'Expose per-device SNMP health metrics as a Prometheus scrape endpoint. Pre-built Grafana dashboard for interface counters, CPU, memory, and poll lag.', }, { title: 'Kubernetes Helm chart', detail: 'Helm chart for production-grade deployments: horizontal scaling for the API and worker pods, Secrets via Vault Agent Injector, Ingress with TLS termination.', }, ], }, ], de: [ { label: 'Nächstes Release', items: [ { title: 'CrowdSec über alle Standorte', detail: 'Das CrowdSec-Plugin wird ein eigener Bereich: jede LAPI-Instanz, Entscheidungen und Alerts über alle Standorte, wie viele Standorte eine Adresse erreicht hat, Sperren im eigenen Netz getrennt gezählt, und welche vom Internet erreichbaren Hosts noch niemand überwacht.', }, { title: 'Windows-Treiber', detail: 'Windows-Hosts über WinRM: Fakten, Interfaces, ARP, Routen und Dienste, inklusive Dienststeuerung.', }, { title: 'Einmal-Tickets für die Konsole', detail: 'Das Browser-Terminal öffnet mit einem einmal gültigen Ticket, statt das Sitzungstoken in der WebSocket-URL mitzugeben.', nis2: true, }, { title: 'Ehrliche Neustarts', detail: 'Eine Neustart-Anfrage für ein Gerät, dessen Treiber es nicht neu starten kann, wird mit Begründung abgelehnt, statt als erledigt gemeldet zu werden.', }, ], }, { label: 'Geplant', items: [ { title: 'Compliance-Dashboard', detail: 'Art. 21-Checkliste pro Standort: Asset-Abdeckung, Patch-Status, Security-Agent-Deployment, Config-Drift, Syslog-Weiterleitung, Audit-Aktivität — zusammengefasst in einer Ansicht.', nis2: true, }, { title: 'Webhook-Engine', detail: 'Ausgehende HTTP-Webhooks für Events: Gerät entdeckt, Konfigurationsänderung erkannt, Job fehlgeschlagen, Warnschwelle überschritten. HMAC-SHA256-Payload-Signierung. Integrierbar mit n8n, Slack, PagerDuty.', }, { title: 'Live-Job-Log-Streaming', detail: 'WebSocket-Endpunkt für Echtzeit-Celery-Task-Output in der UI. Aktuell wird via SSE für Fix-Flows gestreamt; vollständiges Job-Log-Streaming für alle lang laufenden Operationen geplant.', }, { title: 'NetBox-Sync — manueller Trigger & Statusansicht', detail: 'POST /api/v1/netbox/sync-Endpunkt mit Fortschrittsfeedback und Sync-Verlaufsansicht in der UI. Derzeit läuft der Sync automatisch; manueller Trigger und Status fehlen noch.', }, { title: 'HashiCorp-Vault-Integration', detail: 'Echtes Secret-Management als erstes Security-Plugin — löst die aktuelle Fernet-basierte Verschlüsselung von Geräte-Credentials und SSH-Schlüsseln ab.', nis2: true, }, { title: 'Firewall-Profile — nächste Schritte', detail: 'Profile pro Standort mit Diff gegen eine echte OPNsense und schrittweisem Anwenden kamen mit 0.12. Profiltypen, OpenWrt als Ziel und der Push-Mechanismus darüber hinaus stehen noch auf dem Prüfstand.', }, ], }, { label: 'In Erwägung', items: [ { title: 'VLAN-Visualisierung', detail: 'Heatmap- oder Matrixansicht, welche Geräte welche VLANs führen — ohne sich durch geräteweise VLAN-Listen zu graben.', }, { title: 'Incident-Workflow', detail: 'Strukturierter Incident-Datensatz, verknüpft mit Geräten und Sicherheitsereignissen. Fristen-Tracker für NIS2 Art. 23 Meldepflichten (24 h Frühwarnung, 72 h vollständige Meldung). Webhook zu externen Ticketing-Systemen.', nis2: true, }, { title: 'mDNS-Scanner', detail: 'Entdeckt Mediengeräte (Apple TV, Chromecast, Sonos) über mDNS/Bonjour ohne NAPALM-Treiber. Inventarsichtbarkeit und Empfehlungen zur Firewall-Segmentierung.', }, { title: 'Prometheus-Metriken + Grafana-Dashboards', detail: 'Veröffentlicht gerätebezogene SNMP-Gesundheitsmetriken als Prometheus-Scrape-Endpunkt. Vorgefertigtes Grafana-Dashboard für Schnittstellenzähler, CPU, Speicher und Poll-Lag.', }, { title: 'Kubernetes Helm Chart', detail: 'Helm Chart für produktionsreife Deployments: horizontale Skalierung für API- und Worker-Pods, Secrets via Vault Agent Injector, Ingress mit TLS-Terminierung.', }, ], }, ], } function Nis2Badge() { return ( NIS2 ) } export default function Roadmap() { const { lang, t } = useLang() const groups = GROUPS[lang] return (
{t.roadmap.sub.split('NIS2')[0]}
{linkify(item.detail)}