feat: reflect netOrk v0.4.1–v0.4.4 release notes and reconcile roadmap
CI / TypeScript — type-check (push) Failing after 10s
CI / Publish — build & push image (push) Has been skipped
CI / Deploy — pull & restart on host (push) Has been skipped

- Document the Web-SSH browser console and end-to-end RBAC enforcement
  (frontend gating added in v0.4.3), both previously missing from the
  feature list.
- Sync the roadmap with netOrk's docs/TODO.md: add Vault integration
  and the firewall-profile rework (top engineering priorities) and
  VLAN visualization.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Christian Manivong
2026-07-02 15:16:59 +02:00
co-authored by Claude Sonnet 5
parent b37703bbbb
commit 2a8a87bdd1
2 changed files with 30 additions and 0 deletions
+4
View File
@@ -94,6 +94,7 @@ const en = {
title: 'Device Management', title: 'Device Management',
items: [ items: [
'CRUD for devices with credential profiles and SSH key management', 'CRUD for devices with credential profiles and SSH key management',
'Interactive Web-SSH console — full terminal session to any device straight from the browser, no separate SSH client needed',
'Per-device poll intervals (minutes) or manual-only', 'Per-device poll intervals (minutes) or manual-only',
'Status tracking: planned / staged / active / decommissioning / offline / disabled', 'Status tracking: planned / staged / active / decommissioning / offline / disabled',
'Vendor / model / OS auto-populated from NAPALM get_facts()', 'Vendor / model / OS auto-populated from NAPALM get_facts()',
@@ -193,6 +194,7 @@ const en = {
'JWT authentication with remember-me (localStorage) or session-only (sessionStorage)', 'JWT authentication with remember-me (localStorage) or session-only (sessionStorage)',
'Two-factor authentication (MFA/TOTP): authenticator app at login, backup codes, session invalidation on TOTP changes, enforceable per role', 'Two-factor authentication (MFA/TOTP): authenticator app at login, backup codes, session invalidation on TOTP changes, enforceable per role',
'RBAC with four built-in roles: viewer / operator / engineer / administrator', 'RBAC with four built-in roles: viewer / operator / engineer / administrator',
'Permissions enforced end-to-end — nav, routes, and write actions are hidden in the UI to match the backend permission checks, not just disabled',
'Custom roles with any permission combination', 'Custom roles with any permission combination',
'Full audit log of all orchestration actions', 'Full audit log of all orchestration actions',
], ],
@@ -391,6 +393,7 @@ const de: Translations = {
title: 'Geräteverwaltung', title: 'Geräteverwaltung',
items: [ items: [
'CRUD für Geräte mit Credential-Profilen und SSH-Schlüsselverwaltung', 'CRUD für Geräte mit Credential-Profilen und SSH-Schlüsselverwaltung',
'Interaktive Web-SSH-Konsole — vollständige Terminal-Sitzung zu jedem Gerät direkt im Browser, kein separater SSH-Client nötig',
'Konfigurierbare Poll-Intervalle (Minuten) oder nur manuell', 'Konfigurierbare Poll-Intervalle (Minuten) oder nur manuell',
'Statusverfolgung: geplant / bereitgestellt / aktiv / außer Betrieb / offline / deaktiviert', 'Statusverfolgung: geplant / bereitgestellt / aktiv / außer Betrieb / offline / deaktiviert',
'Hersteller / Modell / OS automatisch befüllt über NAPALM get_facts()', 'Hersteller / Modell / OS automatisch befüllt über NAPALM get_facts()',
@@ -490,6 +493,7 @@ const de: Translations = {
'JWT-Authentifizierung mit Remember-Me (localStorage) oder nur Sitzung (sessionStorage)', 'JWT-Authentifizierung mit Remember-Me (localStorage) oder nur Sitzung (sessionStorage)',
'Zwei-Faktor-Authentifizierung (MFA/TOTP): Authenticator-App beim Login, Backup-Codes, Session-Invalidierung bei TOTP-Änderungen, pro Rolle erzwingbar', 'Zwei-Faktor-Authentifizierung (MFA/TOTP): Authenticator-App beim Login, Backup-Codes, Session-Invalidierung bei TOTP-Änderungen, pro Rolle erzwingbar',
'RBAC mit vier integrierten Rollen: Betrachter / Operator / Ingenieur / Administrator', 'RBAC mit vier integrierten Rollen: Betrachter / Operator / Ingenieur / Administrator',
'Berechtigungen durchgängig erzwungen — Navigation, Routen und Schreibaktionen werden in der UI passend zu den Backend-Prüfungen ausgeblendet, nicht nur deaktiviert',
'Benutzerdefinierte Rollen mit beliebiger Berechtigungskombination', 'Benutzerdefinierte Rollen mit beliebiger Berechtigungskombination',
'Vollständiges Audit-Log aller Orchestrierungsaktionen', 'Vollständiges Audit-Log aller Orchestrierungsaktionen',
], ],
+26
View File
@@ -35,11 +35,24 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
title: 'NetBox sync — manual trigger & status view', title: 'NetBox sync — manual trigger & status view',
detail: 'POST /api/v1/netbox/sync endpoint with progress feedback and a sync history view in the UI. Currently sync runs automatically; the manual trigger and status are missing.', detail: 'POST /api/v1/netbox/sync endpoint with progress feedback and a sync history view in the UI. Currently sync runs automatically; the manual trigger and status are missing.',
}, },
{
title: 'HashiCorp Vault integration',
detail: 'Real secret management as the first security plugin, replacing the current Fernet-based encryption at rest for device credentials and SSH keys.',
nis2: true,
},
{
title: 'Firewall profile management — rework',
detail: 'Push reusable firewall rule templates to OPNsense and OpenWRT devices. The existing implementation is being re-scoped from scratch — profile types, rule sets, and the push mechanism are all under review before further work lands.',
},
], ],
}, },
{ {
label: 'Under consideration', label: 'Under consideration',
items: [ items: [
{
title: 'VLAN visualization',
detail: 'Heatmap or matrix view of which devices carry which VLANs, without digging through per-device VLAN lists.',
},
{ {
title: 'Incident workflow', title: 'Incident workflow',
detail: 'Structured incident record tied to devices and security events. Deadline tracker for NIS2 Art. 23 reporting windows (24 h early warning, 72 h full notification). Webhook to external ticketing systems.', detail: 'Structured incident record tied to devices and security events. Deadline tracker for NIS2 Art. 23 reporting windows (24 h early warning, 72 h full notification). Webhook to external ticketing systems.',
@@ -96,11 +109,24 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
title: 'NetBox-Sync — manueller Trigger & Statusansicht', title: 'NetBox-Sync — manueller Trigger & Statusansicht',
detail: 'POST /api/v1/netbox/sync-Endpunkt mit Fortschrittsfeedback und Sync-Verlaufsansicht in der UI. Derzeit läuft der Sync automatisch; manueller Trigger und Status fehlen noch.', detail: 'POST /api/v1/netbox/sync-Endpunkt mit Fortschrittsfeedback und Sync-Verlaufsansicht in der UI. Derzeit läuft der Sync automatisch; manueller Trigger und Status fehlen noch.',
}, },
{
title: 'HashiCorp-Vault-Integration',
detail: 'Echtes Secret-Management als erstes Security-Plugin — löst die aktuelle Fernet-basierte Verschlüsselung von Geräte-Credentials und SSH-Schlüsseln ab.',
nis2: true,
},
{
title: 'Firewall-Profile — Überarbeitung',
detail: 'Wiederverwendbare Firewall-Regel-Templates auf OPNsense- und OpenWRT-Geräte pushen. Die bestehende Implementierung wird von Grund auf neu bewertet — Profiltypen, Regelsätze und der Push-Mechanismus stehen vor der Weiterentwicklung auf dem Prüfstand.',
},
], ],
}, },
{ {
label: 'In Erwägung', label: 'In Erwägung',
items: [ items: [
{
title: 'VLAN-Visualisierung',
detail: 'Heatmap- oder Matrixansicht, welche Geräte welche VLANs führen — ohne sich durch geräteweise VLAN-Listen zu graben.',
},
{ {
title: 'Incident-Workflow', title: 'Incident-Workflow',
detail: 'Strukturierter Incident-Datensatz, verknüpft mit Geräten und Sicherheitsereignissen. Fristen-Tracker für NIS2 Art. 23 Meldepflichten (24 h Frühwarnung, 72 h vollständige Meldung). Webhook zu externen Ticketing-Systemen.', detail: 'Strukturierter Incident-Datensatz, verknüpft mit Geräten und Sicherheitsereignissen. Fristen-Tracker für NIS2 Art. 23 Meldepflichten (24 h Frühwarnung, 72 h vollständige Meldung). Webhook zu externen Ticketing-Systemen.',