Files
Christian Manivong 1ce42ef099 feat: NAPALM driver for Windows over PowerShell Remoting
Talks PSRP over WinRM via pypsrp, one runspace pool per connection. Each
getter sends one PowerShell script that projects cmdlet results onto flat
fields and ends in ConvertTo-Json, so the Python side parses JSON, not text.

Covers facts, interfaces, IP addresses, ARP, routes and services, plus
service start/stop/restart/enable/disable. Service names are validated and
quoted as PowerShell verbatim strings, typographic quotes included.

Fixtures are synthetic: they pin down the JSON the scripts are designed to
emit. tools/harvest.py records the real output from a host.

Refs christianmanivong/netork#300
2026-09-24 09:23:25 +02:00

2.8 KiB

napalm-windows

NAPALM driver for Windows Server 2016+ and Windows 10/11, part of the netOrk driver family built on napalm-device-types.

Driver name: windows · Role: OSDriver · Transport: PowerShell Remoting (PSRP) over WinRM via pypsrp.

How it works

Every getter sends one PowerShell script. The script projects the cmdlet results onto flat, primitive fields and ends in ConvertTo-Json, so the Python side parses JSON, never text. All device I/O goes through a single seam (PsrpTransport.run(script) -> str), which is what the tests replace.

One runspace pool stays open per connection, so a poll pays the WinRM handshake once.

Supported

Method Source
get_facts Win32_ComputerSystem, Win32_OperatingSystem, Win32_BIOS, registry (DisplayVersion, UBR)
get_interfaces Get-NetAdapter
get_interfaces_ip Get-NetIPAddress (loopback dropped, IPv6 zone index stripped)
get_arp_table Get-NetNeighbor -AddressFamily IPv4 (broadcast, multicast, unreachable dropped)
get_route_to Get-NetRoute (multicast, broadcast, loopback dropped)
get_services / manage_service Win32_Service, Start-/Stop-/Restart-Service, Set-Service -StartupType

running_kernel carries the full build including the update revision (10.0.20348.2340): Windows ships fixes as UBR bumps, which is what CVE matching has to compare against.

Not yet: packages, Windows Update, scheduled tasks, health metrics, Hyper-V. See netork#300 for the plan.

Preparing a host

WinRM is on by default on Windows Server; on Windows 10/11 run Enable-PSRemoting once. Then either

  • HTTPS (5986, default) — needs a certificate-backed HTTPS listener, or
  • HTTP (5985) — set the device port to 5985. Traffic is still encrypted at message level (NTLM/Kerberos), credentials never travel in the clear.

A local administrator account additionally needs LocalAccountTokenFilterPolicy = 1 under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System; without it remote UAC strips the admin token. Domain accounts are not affected.

optional_args

Key Default Meaning
port 5986 WinRM port
winrm_ssl port != 5985 force HTTPS on or off
winrm_auth negotiate pypsrp auth protocol (negotiate, ntlm, kerberos, credssp, basic)
ssl_verify True validate the WinRM certificate

Tests and fixtures

pip install -e ".[dev]"
pytest

tests/fixtures/synthetic/ holds the JSON the scripts are designed to emit. To record the real thing from a host:

python tools/harvest.py <host> <user> <label> [--port 5985] [--insecure]

Output lands in tools/harvest-out/ (gitignored); scrub it before copying anything into tests/.