feat: reflect netOrk v0.12.0–v0.28.0 release notes
Seventeen releases since the site was last brought up to date, checked against the changelog and the code at the v0.28.0 tag. - New feature sections: Security Assessment (TLS/SSH grades, CVE and container-image matching, exposure, deep scans; Knowledge Base licence), Vulnerability Management (triage queue, decisions with reasons, deferrals that come back, verified fixes), DHCP, Managed Services, Notifications (Signal). - Existing sections gain per-user SSH keys and session windows, multi-role devices, one device per address per site, LAN Scan, MAC-table topology, service checks, site reachability, per-site firewall profiles with diff, honoured drift auto-correct, 16 Ansible roles, 18 dashboard widgets. - Corrections: Docker status is Linux/OMV/QNAP, not Proxmox. - Roadmap: CVE tracking shipped and is gone from "Planned"; a "Next release" group lists what is on main but unreleased (CrowdSec across sites, Windows driver, single-use console tickets, reboots refused instead of faked). - NIS2: Art. 21 (2e) now describes the vulnerability handling that exists, (2i) adds attributable terminal sessions; CVE tracking left "coming". - Persona pages: two new items each, counts updated. Glossary: Kea, WinRM, LAPI. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
04c5c00280
commit
4cba6e156c
+80
-15
@@ -95,12 +95,22 @@ hardware and want operational visibility beyond what consumer dashboards offer.
|
||||
- Vendor/model/OS auto-populated from NAPALM `get_facts()`
|
||||
- Site assignment with FK to structured Site records
|
||||
- AP Profile assignment for grouped OpenWRT config
|
||||
- Web SSH terminal: sessions log in with each user's own SSH key, never the
|
||||
device's shared account; opened and refused sessions are recorded. Sessions
|
||||
are movable, dockable windows that survive navigating away
|
||||
- A device can hold several roles at once (e.g. storage + hypervisor + Linux)
|
||||
- One device per address per site; duplicates are refused (VMs exempt)
|
||||
- Business criticality per device and site, used in vulnerability ranking
|
||||
|
||||
### Discovery
|
||||
- ICMP ping sweep, SNMP scan, HTTP/HTTPS probing
|
||||
- Device fingerprinting: vendor + platform confidence scoring
|
||||
- FQDN resolution (reverse DNS)
|
||||
- Manual adoption from scan results (no auto-create to avoid inventory noise)
|
||||
- Discovery jobs in a sortable, filterable table, grouped per site
|
||||
- LAN Scan: ping sweep from netOrk, each site satellite and every firewall;
|
||||
live results with MAC and manufacturer; a finished scan becomes a discovery
|
||||
job in one step
|
||||
|
||||
### VM Provisioning
|
||||
- Cloud-Init based VM creation directly from a hypervisor's VMs tab — no
|
||||
@@ -124,23 +134,32 @@ Custom NAPALM drivers for all of the following:
|
||||
|
||||
| Driver | Device type |
|
||||
|---|---|
|
||||
| `openwrt` | OpenWRT access points |
|
||||
| `opnsense` | OPNsense firewalls |
|
||||
| `proxmox` | Proxmox VE hypervisors |
|
||||
| `fritzbox` | AVM Fritz!Box routers (read-only) |
|
||||
| `hpe_officeconnect` | HPE OfficeConnect 1820 / 1920S switches |
|
||||
| `linux` | Generic Linux servers |
|
||||
| `procurve` | HP ProCurve / Aruba switches |
|
||||
| `tplink_jetstream` | TP-Link Jetstream managed switches |
|
||||
| `netgear` | Netgear switches |
|
||||
| `fritzbox` | AVM Fritz!Box routers |
|
||||
| `zyxel` | Zyxel switches |
|
||||
| `netgear_plus` | Netgear Plus switches (web UI) |
|
||||
| `netgear_smart` | Netgear Smart Managed Pro switches |
|
||||
| `openmediavault` | OpenMediaVault NAS |
|
||||
| `openwrt` | OpenWrt routers and access points |
|
||||
| `opnsense` | OPNsense firewalls |
|
||||
| `procurve` | HPE ProCurve / Aruba switches |
|
||||
| `proxmox` | Proxmox VE hypervisors |
|
||||
| `qnap_qts` | QNAP NAS on QTS |
|
||||
| `sonos` | Sonos speakers |
|
||||
| `tplink_jetstream` | TP-Link JetStream managed switches |
|
||||
| `yealink` | Yealink IP phones |
|
||||
| `zyxel` | Zyxel VMG routers (not switches) |
|
||||
|
||||
Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper JunOS.
|
||||
The built-in NAPALM drivers (Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper JunOS)
|
||||
are installed but not tested with netOrk and get none of its driver-specific
|
||||
features. Capability matrix (audited against v0.28.0): see `src/pages/Drivers.tsx`.
|
||||
Reboot from netOrk actually restarts only OpenWrt and Proxmox.
|
||||
|
||||
### Networking & Inventory
|
||||
- Interface browser with IPv4/IPv6 addresses, MAC, speed, MTU
|
||||
- LLDP neighbor discovery and topology graph
|
||||
- LLDP neighbor discovery and topology graph, plus links derived from switch
|
||||
MAC tables (drawn dashed)
|
||||
- Radio problems between the access points of a site are reported
|
||||
- ARP table and DHCP lease browser per device
|
||||
- Subnet browser with interface-to-subnet assignments
|
||||
- VLAN list grouped by site; per-VLAN device membership view
|
||||
@@ -170,8 +189,10 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
|
||||
### Configuration Automation (Ansible)
|
||||
- Reusable Ansible roles and playbooks stored and edited directly in
|
||||
netOrk — no separate git checkout
|
||||
- 11 built-in roles ready to assign: base, ubuntu, docker, adguard, zoraxy,
|
||||
portainer, watchtower, uptime-kuma, vaultwarden, wireguard, fail2ban
|
||||
- 16 built-in roles ready to assign: base, ubuntu, docker, adguard, zoraxy,
|
||||
portainer, watchtower, uptime-kuma, vaultwarden, stalwart, bulwark, searxng,
|
||||
postiz, listmonk, wireguard, fail2ban
|
||||
- Roles state their resource needs; undersized hosts are refused with a reason
|
||||
- Automatic dependency resolution — assigning `docker` pulls in `base`
|
||||
automatically, no manual role ordering
|
||||
- Built-in roles can't be deleted but are fully editable; customizations
|
||||
@@ -215,7 +236,7 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
|
||||
- One-click Ack on any warning — clears it immediately and writes an audit log
|
||||
entry; for config-change warnings the current state is accepted as the new
|
||||
baseline
|
||||
- Docker container and image status (Proxmox/Linux)
|
||||
- Docker container and image status (Linux, OpenMediaVault, QNAP)
|
||||
- Service status and start/stop/restart (systemd)
|
||||
- VM/container list with OS device cross-linking (Proxmox)
|
||||
- Per-device availability windows — suppress OFFLINE status and poll-failure
|
||||
@@ -225,21 +246,65 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
|
||||
- OPNsense: TLS certificate monitoring for the Trust store, with
|
||||
expiring-soon / expired warnings
|
||||
- OPNsense: Dynamic DNS service-down warning (os-ddclient)
|
||||
- Service checks about once a minute (DNS, NTP, VPN tunnels, core daemons,
|
||||
gateways), derived automatically; three failures before an alert; can run
|
||||
from satellites, including a DHCP check
|
||||
- Site reachability: polling pauses behind a dead tunnel, one warning names
|
||||
it, everything is re-polled when it returns
|
||||
|
||||
### Dashboards
|
||||
- Configurable, shareable dashboards — build your own from a widget picker
|
||||
instead of a fixed layout
|
||||
- WYSIWYG grid-layout editor: drag, resize, and arrange widgets on a canvas
|
||||
- 13 widget types: stats, device warnings, recently updated devices, network
|
||||
- 18 widget types: stats, device warnings, recently updated devices, network
|
||||
topology, EOL status, config drift summary, Wazuh security alerts, audit log
|
||||
activity, discovery jobs status, upcoming scheduled actions, DNS zones
|
||||
overview, site overview, config snapshot history
|
||||
overview, site overview, config snapshot history, managed services,
|
||||
certificate expiry, outdated Docker images, firewall profile deployment
|
||||
status, service checks
|
||||
- Multi-instance widgets with independent per-widget settings
|
||||
- Share a dashboard with specific users; recipients can subscribe to the
|
||||
owner's live version or clone it into their own editable copy
|
||||
- Favorite dashboards for quick access from the main menu; set any dashboard
|
||||
as your home view
|
||||
|
||||
### Notifications
|
||||
- Signal messages for everything netOrk watches; each person registers their
|
||||
own number, administrators pair netOrk once via QR code
|
||||
- One message per site outage, daily summary for recurring items, hourly
|
||||
bundling, quiet hours per number, mute per kind, full history with reasons
|
||||
|
||||
### DHCP
|
||||
- DHCP reservations: import from the firewall, validated, diff, then apply
|
||||
(adds and updates only)
|
||||
- DHCP subnets (Kea on OPNsense) with options and search domains; settings
|
||||
that break a network are refused
|
||||
|
||||
### Managed Services
|
||||
- Every container-based service across devices with endpoints, TLS
|
||||
certificates and access rules
|
||||
- Compose editor with masked secrets and automatic backup snapshot; redeploy
|
||||
is a separate confirmed step
|
||||
- Zoraxy vhosts editable and written back; PostgreSQL databases listed
|
||||
|
||||
### Security Assessment
|
||||
- Security tab per device: TLS/SSH grades A–F, installed software and
|
||||
container images matched against known vulnerabilities, hardening benchmarks
|
||||
- Ratings adjusted to the device (local access, trusted network, not running,
|
||||
not booted kernel; raised when exploited in the wild)
|
||||
- Kernel reboot recommendation with the vulnerabilities it would clear
|
||||
- Exposure from firewall rules; internet-visible ports and abuse reports for
|
||||
own public addresses; on-demand hardening audit and web scan
|
||||
- Vulnerability data from the netOrk Knowledge Base (licence required)
|
||||
|
||||
### Vulnerability Management
|
||||
- Triage queue across all devices, one row per vulnerability, ordered by
|
||||
remediation deadline, exploitation, severity, likelihood, criticality, spread
|
||||
- Decisions (not applicable / accept until / defer until / fixed) with a
|
||||
mandatory reason; accept and not-applicable need an elevated permission
|
||||
- Deferred and accepted items return by themselves; ignored ones go overdue
|
||||
- Daily reassessment verifies fixes and reopens regressions
|
||||
|
||||
### Security Integrations (plugins)
|
||||
- **Wazuh** — agent enrollment tracking, vulnerability counts (by severity),
|
||||
recent alert history, CIS benchmark scores, one-click agent install fix stream
|
||||
|
||||
Reference in New Issue
Block a user