feat: reflect netOrk v0.12.0–v0.28.0 release notes

Seventeen releases since the site was last brought up to date, checked
against the changelog and the code at the v0.28.0 tag.

- New feature sections: Security Assessment (TLS/SSH grades, CVE and
  container-image matching, exposure, deep scans; Knowledge Base licence),
  Vulnerability Management (triage queue, decisions with reasons, deferrals
  that come back, verified fixes), DHCP, Managed Services, Notifications
  (Signal).
- Existing sections gain per-user SSH keys and session windows, multi-role
  devices, one device per address per site, LAN Scan, MAC-table topology,
  service checks, site reachability, per-site firewall profiles with diff,
  honoured drift auto-correct, 16 Ansible roles, 18 dashboard widgets.
- Corrections: Docker status is Linux/OMV/QNAP, not Proxmox.
- Roadmap: CVE tracking shipped and is gone from "Planned"; a "Next release"
  group lists what is on main but unreleased (CrowdSec across sites, Windows
  driver, single-use console tickets, reboots refused instead of faked).
- NIS2: Art. 21 (2e) now describes the vulnerability handling that exists,
  (2i) adds attributable terminal sessions; CVE tracking left "coming".
- Persona pages: two new items each, counts updated. Glossary: Kea, WinRM,
  LAPI.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Christian Manivong
2026-09-26 07:33:02 +02:00
co-authored by Claude Opus 5.5
parent 04c5c00280
commit 4cba6e156c
8 changed files with 335 additions and 53 deletions
+80 -15
View File
@@ -95,12 +95,22 @@ hardware and want operational visibility beyond what consumer dashboards offer.
- Vendor/model/OS auto-populated from NAPALM `get_facts()`
- Site assignment with FK to structured Site records
- AP Profile assignment for grouped OpenWRT config
- Web SSH terminal: sessions log in with each user's own SSH key, never the
device's shared account; opened and refused sessions are recorded. Sessions
are movable, dockable windows that survive navigating away
- A device can hold several roles at once (e.g. storage + hypervisor + Linux)
- One device per address per site; duplicates are refused (VMs exempt)
- Business criticality per device and site, used in vulnerability ranking
### Discovery
- ICMP ping sweep, SNMP scan, HTTP/HTTPS probing
- Device fingerprinting: vendor + platform confidence scoring
- FQDN resolution (reverse DNS)
- Manual adoption from scan results (no auto-create to avoid inventory noise)
- Discovery jobs in a sortable, filterable table, grouped per site
- LAN Scan: ping sweep from netOrk, each site satellite and every firewall;
live results with MAC and manufacturer; a finished scan becomes a discovery
job in one step
### VM Provisioning
- Cloud-Init based VM creation directly from a hypervisor's VMs tab — no
@@ -124,23 +134,32 @@ Custom NAPALM drivers for all of the following:
| Driver | Device type |
|---|---|
| `openwrt` | OpenWRT access points |
| `opnsense` | OPNsense firewalls |
| `proxmox` | Proxmox VE hypervisors |
| `fritzbox` | AVM Fritz!Box routers (read-only) |
| `hpe_officeconnect` | HPE OfficeConnect 1820 / 1920S switches |
| `linux` | Generic Linux servers |
| `procurve` | HP ProCurve / Aruba switches |
| `tplink_jetstream` | TP-Link Jetstream managed switches |
| `netgear` | Netgear switches |
| `fritzbox` | AVM Fritz!Box routers |
| `zyxel` | Zyxel switches |
| `netgear_plus` | Netgear Plus switches (web UI) |
| `netgear_smart` | Netgear Smart Managed Pro switches |
| `openmediavault` | OpenMediaVault NAS |
| `openwrt` | OpenWrt routers and access points |
| `opnsense` | OPNsense firewalls |
| `procurve` | HPE ProCurve / Aruba switches |
| `proxmox` | Proxmox VE hypervisors |
| `qnap_qts` | QNAP NAS on QTS |
| `sonos` | Sonos speakers |
| `tplink_jetstream` | TP-Link JetStream managed switches |
| `yealink` | Yealink IP phones |
| `zyxel` | Zyxel VMG routers (not switches) |
Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper JunOS.
The built-in NAPALM drivers (Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper JunOS)
are installed but not tested with netOrk and get none of its driver-specific
features. Capability matrix (audited against v0.28.0): see `src/pages/Drivers.tsx`.
Reboot from netOrk actually restarts only OpenWrt and Proxmox.
### Networking & Inventory
- Interface browser with IPv4/IPv6 addresses, MAC, speed, MTU
- LLDP neighbor discovery and topology graph
- LLDP neighbor discovery and topology graph, plus links derived from switch
MAC tables (drawn dashed)
- Radio problems between the access points of a site are reported
- ARP table and DHCP lease browser per device
- Subnet browser with interface-to-subnet assignments
- VLAN list grouped by site; per-VLAN device membership view
@@ -170,8 +189,10 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
### Configuration Automation (Ansible)
- Reusable Ansible roles and playbooks stored and edited directly in
netOrk — no separate git checkout
- 11 built-in roles ready to assign: base, ubuntu, docker, adguard, zoraxy,
portainer, watchtower, uptime-kuma, vaultwarden, wireguard, fail2ban
- 16 built-in roles ready to assign: base, ubuntu, docker, adguard, zoraxy,
portainer, watchtower, uptime-kuma, vaultwarden, stalwart, bulwark, searxng,
postiz, listmonk, wireguard, fail2ban
- Roles state their resource needs; undersized hosts are refused with a reason
- Automatic dependency resolution — assigning `docker` pulls in `base`
automatically, no manual role ordering
- Built-in roles can't be deleted but are fully editable; customizations
@@ -215,7 +236,7 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
- One-click Ack on any warning — clears it immediately and writes an audit log
entry; for config-change warnings the current state is accepted as the new
baseline
- Docker container and image status (Proxmox/Linux)
- Docker container and image status (Linux, OpenMediaVault, QNAP)
- Service status and start/stop/restart (systemd)
- VM/container list with OS device cross-linking (Proxmox)
- Per-device availability windows — suppress OFFLINE status and poll-failure
@@ -225,21 +246,65 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
- OPNsense: TLS certificate monitoring for the Trust store, with
expiring-soon / expired warnings
- OPNsense: Dynamic DNS service-down warning (os-ddclient)
- Service checks about once a minute (DNS, NTP, VPN tunnels, core daemons,
gateways), derived automatically; three failures before an alert; can run
from satellites, including a DHCP check
- Site reachability: polling pauses behind a dead tunnel, one warning names
it, everything is re-polled when it returns
### Dashboards
- Configurable, shareable dashboards — build your own from a widget picker
instead of a fixed layout
- WYSIWYG grid-layout editor: drag, resize, and arrange widgets on a canvas
- 13 widget types: stats, device warnings, recently updated devices, network
- 18 widget types: stats, device warnings, recently updated devices, network
topology, EOL status, config drift summary, Wazuh security alerts, audit log
activity, discovery jobs status, upcoming scheduled actions, DNS zones
overview, site overview, config snapshot history
overview, site overview, config snapshot history, managed services,
certificate expiry, outdated Docker images, firewall profile deployment
status, service checks
- Multi-instance widgets with independent per-widget settings
- Share a dashboard with specific users; recipients can subscribe to the
owner's live version or clone it into their own editable copy
- Favorite dashboards for quick access from the main menu; set any dashboard
as your home view
### Notifications
- Signal messages for everything netOrk watches; each person registers their
own number, administrators pair netOrk once via QR code
- One message per site outage, daily summary for recurring items, hourly
bundling, quiet hours per number, mute per kind, full history with reasons
### DHCP
- DHCP reservations: import from the firewall, validated, diff, then apply
(adds and updates only)
- DHCP subnets (Kea on OPNsense) with options and search domains; settings
that break a network are refused
### Managed Services
- Every container-based service across devices with endpoints, TLS
certificates and access rules
- Compose editor with masked secrets and automatic backup snapshot; redeploy
is a separate confirmed step
- Zoraxy vhosts editable and written back; PostgreSQL databases listed
### Security Assessment
- Security tab per device: TLS/SSH grades A–F, installed software and
container images matched against known vulnerabilities, hardening benchmarks
- Ratings adjusted to the device (local access, trusted network, not running,
not booted kernel; raised when exploited in the wild)
- Kernel reboot recommendation with the vulnerabilities it would clear
- Exposure from firewall rules; internet-visible ports and abuse reports for
own public addresses; on-demand hardening audit and web scan
- Vulnerability data from the netOrk Knowledge Base (licence required)
### Vulnerability Management
- Triage queue across all devices, one row per vulnerability, ordered by
remediation deadline, exploitation, severity, likelihood, criticality, spread
- Decisions (not applicable / accept until / defer until / fixed) with a
mandatory reason; accept and not-applicable need an elevated permission
- Deferred and accepted items return by themselves; ignored ones go overdue
- Daily reassessment verifies fixes and reopens regressions
### Security Integrations (plugins)
- **Wazuh** — agent enrollment tracking, vulnerability counts (by severity),
recent alert history, CIS benchmark scores, one-click agent install fix stream