feat: reflect netOrk v0.4.0 features (MFA, config backup, ack warnings)
CI / TypeScript — type-check (push) Successful in 9s
CI / Publish — build & push image (push) Successful in 8s
CI / Deploy — pull & restart on host (push) Successful in 2s

Moves MFA/TOTP and config backup & versioning from roadmap to shipped
across the NIS2 coverage page, features list, and roadmap, and adds a
homepage screenshot row for the new config snapshot/diff/restore UI.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Christian Manivong
2026-06-30 13:23:37 +02:00
co-authored by Claude Sonnet 4.6
parent 77a73030b4
commit 2f8cbf48af
6 changed files with 96 additions and 31 deletions
+9 -2
View File
@@ -147,6 +147,15 @@ Each badge uses the `Driver / Integration Badge` component from DESIGN.md.
agent is missing. Graylog syslog forwarding status with auto-fix.`
- Screenshot: SecurityTab inside DeviceDetailPage
**Row 4 — Right text, left screenshot**
- Heading: `Configuration backup and versioning`
- Copy: `Every poll captures a config snapshot into a local Git
repository. The Config tab shows the full snapshot history, a
side-by-side diff between any two points in time, and — for
OPNsense — a Restore button. Unauthorized changes show up as a
device warning.`
- Screenshot: ConfigTab inside DeviceDetailPage
---
### Section 5b — NIS2
@@ -330,7 +339,6 @@ address NIS2 Art. 21 technical baseline requirements.
**Planned items (NIS2-tagged):**
- CVE tracking per device — NVD / OSV cross-reference
- Configuration backup & versioning — git-backed snapshots, change detection
- Compliance dashboard — per-site Art. 21 checklist view
- Audit log export — PDF / CSV with filters
@@ -342,7 +350,6 @@ address NIS2 Art. 21 technical baseline requirements.
**Under consideration (NIS2-tagged):**
- Incident workflow — structured record + NIS2 Art. 23 Fristen-Tracker
- EOL tracking — endoflife.date integration for firmware / OS
- MFA (TOTP) — second factor for netOrk logins
**Under consideration (general):**
- mDNS scanner — media device discovery
+13 -1
View File
@@ -68,7 +68,8 @@ hardware and want operational visibility beyond what consumer dashboards offer.
9. **NIS2 evidence foundation** — NIS2 Art. 21 mandates asset inventory, patch
management, access control, and audit trails. netOrk produces all of these as
day-to-day operational outputs: full device inventory, per-device update status,
Wazuh CVE tracking, RBAC, config drift detection, and a complete audit log.
Wazuh CVE tracking, RBAC with MFA, Git-backed config snapshots with diff/restore,
config drift detection, and a complete audit log.
---
@@ -120,6 +121,11 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
- One-click drift fix stream with live SSH output in the browser
- UCI-based config push for OpenWRT (VLAN names, SSID settings, radio config)
- AP profile system: country code, HT/VHT mode, 802.11r, NTP, syslog, SSH port
- Configuration backup & versioning: every poll captures a config snapshot into
a local Git repository, with full history and a side-by-side diff viewer
between any two points in time
- One-click config restore for OPNsense from any prior snapshot
- Unauthorised configuration changes are surfaced as a device warning
### Scheduled Operations
- Scheduled reboots for OpenWRT APs with per-site concurrency lock
@@ -130,6 +136,9 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
### Monitoring & Health
- SNMP health metrics (CPU, memory, interface counters) via `get_health_metrics()`
- Per-device warning system with severity levels (error / warning / info)
- One-click Ack on any warning — clears it immediately and writes an audit log
entry; for config-change warnings the current state is accepted as the new
baseline
- Docker container and image status (Proxmox/Linux)
- Service status and start/stop/restart (systemd)
- VM/container list with OS device cross-linking (Proxmox)
@@ -148,6 +157,9 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
### Access Control
- JWT authentication with remember-me (localStorage) or session-only (sessionStorage)
- Two-factor authentication (MFA/TOTP) — authenticator app at login, backup
codes for emergencies, session invalidation on TOTP changes, enforceable
per role
- RBAC with four built-in roles: viewer / operator / engineer / administrator
- Custom roles with any permission combination
- Full audit log of all orchestration actions