diff --git a/docs/PAGES.md b/docs/PAGES.md index 02e2c9b..646254a 100644 --- a/docs/PAGES.md +++ b/docs/PAGES.md @@ -156,6 +156,14 @@ Each badge uses the `Driver / Integration Badge` component from DESIGN.md. device warning.` - Screenshot: ConfigTab inside DeviceDetailPage +**Row 5 — Left text, right screenshot** +- Heading: `Dashboards you actually build` +- Copy: `Pick from 13 widgets and arrange them on a WYSIWYG grid — no + more fixed layout. Share a dashboard with a colleague, let them + subscribe to your live version or clone it into their own, and pin + favorites to the main menu.` +- Screenshot: DashboardDetailPage (edit mode) + --- ### Section 5b — NIS2 @@ -254,16 +262,21 @@ sticky section nav). One section per capability area. **Sections** (map directly to feature list in `docs/PRODUCT.md`): 1. Device Management 2. Discovery -3. Supported Drivers (full table) -4. Networking & Inventory -5. Configuration Management & Drift -6. Scheduled Operations -7. Monitoring & Health -8. Security Integrations -9. DNS Management -10. Access Control (RBAC) -11. NetBox Sync -12. Developer Experience +3. VM Provisioning +4. Supported Drivers (full table) +5. Networking & Inventory +6. Configuration Management & Drift +7. Configuration Automation (Ansible) +8. Scheduled Operations +9. Satellite Deployments +10. Monitoring & Health +11. Dashboards +12. Security Integrations +13. DNS Management +14. Access Control (RBAC) +15. NetBox Sync +16. Compliance & Audit (NIS2) +17. Developer Experience Each section: `text-xl font-semibold text-slate-200` heading + feature items as a clean list with `text-slate-400` body. @@ -340,7 +353,6 @@ address NIS2 Art. 21 technical baseline requirements. **Planned items (NIS2-tagged):** - CVE tracking per device — NVD / OSV cross-reference - Compliance dashboard — per-site Art. 21 checklist view -- Audit log export — PDF / CSV with filters **Planned items (general):** - Webhook engine — outbound events with HMAC signing @@ -349,7 +361,6 @@ address NIS2 Art. 21 technical baseline requirements. **Under consideration (NIS2-tagged):** - Incident workflow — structured record + NIS2 Art. 23 Fristen-Tracker -- EOL tracking — endoflife.date integration for firmware / OS **Under consideration (general):** - mDNS scanner — media device discovery diff --git a/docs/PRODUCT.md b/docs/PRODUCT.md index a544385..5232812 100644 --- a/docs/PRODUCT.md +++ b/docs/PRODUCT.md @@ -68,8 +68,21 @@ hardware and want operational visibility beyond what consumer dashboards offer. 9. **NIS2 evidence foundation** — NIS2 Art. 21 mandates asset inventory, patch management, access control, and audit trails. netOrk produces all of these as day-to-day operational outputs: full device inventory, per-device update status, - Wazuh CVE tracking, RBAC with MFA, Git-backed config snapshots with diff/restore, - config drift detection, and a complete audit log. + Wazuh CVE tracking, EOL firmware/OS flagging, RBAC with MFA, Git-backed config + snapshots with diff/restore, config drift detection, and a complete audit log. + +10. **Build your own view** — Configurable, shareable dashboards: pick from 13 + widgets, arrange them on a WYSIWYG grid, and share the result with colleagues + who can subscribe to the live version or clone their own copy. + +11. **From zero to managed in one flow** — Provision a Cloud-Init VM on a + Proxmox hypervisor, assign Ansible roles to configure it, and netOrk + auto-links it as a Device — no separate tools, no manual SSH-and-copy. + +12. **Reach sites netOrk can't touch directly** — Deploy a lightweight + Satellite agent to poll devices locally at a disconnected or firewalled + site and sync results back over HTTPS; scheduled fixes route through it + the same way they do for directly reachable devices. --- @@ -89,6 +102,23 @@ hardware and want operational visibility beyond what consumer dashboards offer. - FQDN resolution (reverse DNS) - Manual adoption from scan results (no auto-create to avoid inventory noise) +### VM Provisioning +- Cloud-Init based VM creation directly from a hypervisor's VMs tab — no + manual template or VMID setup +- Multi-distro image catalog: Debian 12, Ubuntu 22.04/24.04/26.04, + Fedora 42/43/44, with Ubuntu and Fedora releases synced automatically as + new versions ship +- Pick a target VLAN and an IP from its subnet — netOrk creates the DHCP + reservation automatically +- Cloud-init provisions a real Linux user with an SSH key, plus configurable + bootstrap toggles (SNMP, QEMU guest agent) +- Reusable provisioning templates for repeatable bootstrap settings +- The new VM is auto-linked as a netOrk Device and its hostname assigned to + a DNS zone once bootstrap finishes +- Deploy progress shown as a live step checklist in the UI +- Delete a VM and its linked netOrk Device together, gated behind a + name-confirmation prompt + ### Supported Device Drivers Custom NAPALM drivers for all of the following: @@ -127,11 +157,46 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju - One-click config restore for OPNsense from any prior snapshot - Unauthorised configuration changes are surfaced as a device warning +### Configuration Automation (Ansible) +- Reusable Ansible roles and playbooks stored and edited directly in + netOrk — no separate git checkout +- 11 built-in roles ready to assign: base, ubuntu, docker, adguard, zoraxy, + portainer, watchtower, uptime-kuma, vaultwarden, wireguard, fail2ban +- Automatic dependency resolution — assigning `docker` pulls in `base` + automatically, no manual role ordering +- Built-in roles can't be deleted but are fully editable; customizations + survive upgrades, and only untouched files auto-heal on bugfixes +- `ansible-doc`-backed autocomplete while writing roles and playbooks +- Upload your own role as an archive +- Device-level role assignment with a dedicated Ansible tab on the device + detail page +- Run history per device, snapshotting the exact role/playbook content + that was executed +- Wired into VM provisioning: assign roles at VM-creation time and they + run automatically after boot + ### Scheduled Operations - Scheduled reboots for OpenWRT APs with per-site concurrency lock - Failback cron script written to device for netOrk-unreachable scenarios - Scheduled config drift fixes with time-window enforcement - Package update scheduling and one-click apply +- Wake-on-LAN via a firewall's driver (OPNsense today) — saved WOL targets + with on-demand "Wake now" and recurring schedules; save a seen host as a + target directly from the DHCP/ARP tabs + +### Satellite Deployments +- Lightweight Docker agent deployed at a site netOrk can't reach directly — + polls devices locally and syncs results back to Central over HTTPS +- Deployed in one flow via VM provisioning: pick a hypervisor and site, + netOrk provisions the VM and installs the satellite container automatically +- Central automatically skips direct polling for any device at a site with + an online, heartbeating satellite — no manual per-site toggling +- Scheduled/on-demand reboots and the SNMP auto-fix flow run through the + same command channel whether a device is directly reachable or behind a + satellite +- Not yet satellite-covered: discovery scans and SNMP health-metric polling + still run from Central, and WebSSH console access isn't available through + a satellite ### Monitoring & Health - SNMP health metrics (CPU, memory, interface counters) via `get_health_metrics()` @@ -143,11 +208,27 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju - Service status and start/stop/restart (systemd) - VM/container list with OS device cross-linking (Proxmox) +### Dashboards +- Configurable, shareable dashboards — build your own from a widget picker + instead of a fixed layout +- WYSIWYG grid-layout editor: drag, resize, and arrange widgets on a canvas +- 13 widget types: stats, device warnings, recently updated devices, network + topology, EOL status, config drift summary, Wazuh security alerts, audit log + activity, discovery jobs status, upcoming scheduled actions, DNS zones + overview, site overview, config snapshot history +- Multi-instance widgets with independent per-widget settings +- Share a dashboard with specific users; recipients can subscribe to the + owner's live version or clone it into their own editable copy +- Favorite dashboards for quick access from the main menu; set any dashboard + as your home view + ### Security Integrations (plugins) - **Wazuh** — agent enrollment tracking, vulnerability counts (by severity), recent alert history, CIS benchmark scores, one-click agent install fix stream - **Graylog** — rsyslog forwarding status per device, one-click fix to write rule - **CrowdSec** — org-level decisions, remediation metrics, top attack scenarios +- **EOL Tracking** — flags devices running end-of-life or soon-to-be-end-of-life + firmware/OS via the endoflife.date API, checked daily ### DNS - DNS zone management with authoritative device assignment @@ -162,7 +243,8 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju per role - RBAC with four built-in roles: viewer / operator / engineer / administrator - Custom roles with any permission combination -- Full audit log of all orchestration actions +- Full audit log of all orchestration actions, filterable by date range, + user, action, or resource — export to CSV or PDF ### NetBox Sync - Pushes vendor, model, OS version, status to NetBox dcim.devices @@ -180,11 +262,15 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju ## Architecture in One Paragraph -netOrk runs as five Docker containers: a FastAPI API server, two Celery worker -pools (general + poll), a Celery Beat scheduler, and an nginx UI server. Redis -is the broker. PostgreSQL stores all state. Device communication is always -blocking I/O executed in Celery workers — FastAPI request handlers are -async-only for DB and quick operations. Custom NAPALM drivers live in `vendor/` -as editable packages and self-register via `@register_driver`. The plugin system -(`netork/plugins/`) provides a hook bus, a plugin registry with enable/disable -state in the DB, and a documented pattern for adding integrations. +netOrk runs as a set of Docker containers: a FastAPI API server, three Celery +worker pools (general, poll, and Ansible), a Celery Beat scheduler, and an +nginx UI server. Redis is the broker. PostgreSQL stores all state. Device +communication is always blocking I/O executed in Celery workers — FastAPI +request handlers are async-only for DB and quick operations. Custom NAPALM +drivers live in `vendor/` as editable packages and self-register via +`@register_driver`. The plugin system (`netork/plugins/`) provides a hook bus, +a plugin registry with enable/disable state in the DB, and a documented +pattern for adding integrations. For sites Central can't reach directly, a +separate Satellite container polls devices locally and syncs results back +over HTTPS; Central dispatches actions (reboots, SNMP fixes) to it through a +generic command channel, transparently to the UI. diff --git a/src/i18n/translations.ts b/src/i18n/translations.ts index eeec6b0..2fab2bd 100644 --- a/src/i18n/translations.ts +++ b/src/i18n/translations.ts @@ -69,6 +69,10 @@ const en = { heading: 'Configuration backup and versioning', body: 'Every poll captures a config snapshot into a local Git repository. The Config tab shows the full snapshot history, a side-by-side diff between any two points in time, and — for OPNsense — a Restore button. Unauthorized changes show up as a device warning.', }, + screenshot5: { + heading: 'Dashboards you actually build', + body: 'Pick from 13 widgets and arrange them on a WYSIWYG grid — no more fixed layout. Share a dashboard with a colleague, let them subscribe to your live version or clone it into their own, and pin favorites to the main menu.', + }, nis2Label: 'NIS2 · Art. 21', nis2Heading: 'Evidence, not paperwork.', nis2Body: "NIS2 Art. 21 mandates asset inventory, patch management, access control, and audit trails as baseline technical measures. netOrk doesn't bolt on a compliance layer — these are its day-to-day outputs.", @@ -80,7 +84,7 @@ const en = { { art: 'Art. 21 (2b)', label: 'Incident detection', detail: 'Wazuh alert history, CrowdSec decisions, Graylog syslog per device' }, ], pluginsHeading: 'Built to extend', - pluginsBody: 'Integrations (Wazuh, Graylog, CrowdSec, apt-cacher-ng) are plugins that register into the plugin system — they can be enabled or disabled per deployment without code changes. Adding a new integration follows a documented pattern with a hook bus, typed metadata, and a plugin registry.', + pluginsBody: 'Integrations (Wazuh, Graylog, CrowdSec, apt-cacher-ng, EOL Tracking) are plugins that register into the plugin system — they can be enabled or disabled per deployment without code changes. Adding a new integration follows a documented pattern with a hook bus, typed metadata, and a plugin registry.', pluginsLink: 'Plugin system docs →', deployHeading: 'Self-hosted. One command.', deployBody: 'netOrk runs in Docker Compose. Five containers: API, two worker pools, a Beat scheduler, and an nginx UI server. No external dependencies beyond Redis and PostgreSQL.', @@ -113,6 +117,19 @@ const en = { 'Manual adoption from scan results — no auto-create to avoid inventory noise', ], }, + { + title: 'VM Provisioning', + items: [ + 'Cloud-Init based VM creation directly from a hypervisor\'s VMs tab — no manual template or VMID setup', + 'Multi-distro image catalog: Debian 12, Ubuntu 22.04/24.04/26.04, Fedora 42/43/44, with Ubuntu and Fedora releases synced automatically as new versions ship', + 'Pick a target VLAN and an IP from its subnet — netOrk creates the DHCP reservation automatically', + 'Cloud-init provisions a real Linux user with an SSH key, plus configurable bootstrap toggles (SNMP, QEMU guest agent)', + 'Reusable provisioning templates for repeatable bootstrap settings', + 'The new VM is auto-linked as a netOrk Device and its hostname assigned to a DNS zone once bootstrap finishes', + 'Deploy progress shown as a live step checklist in the UI', + 'Delete a VM and its linked netOrk Device together, gated behind a name-confirmation prompt', + ], + }, { title: 'Supported Drivers', items: [ @@ -153,6 +170,20 @@ const en = { 'Unauthorized configuration changes are surfaced as a device warning', ], }, + { + title: 'Configuration Automation (Ansible)', + items: [ + 'Reusable Ansible roles and playbooks stored and edited directly in netOrk — no separate git checkout', + '11 built-in roles ready to assign: base, ubuntu, docker, adguard, zoraxy, portainer, watchtower, uptime-kuma, vaultwarden, wireguard, fail2ban', + 'Automatic dependency resolution — assigning docker pulls in base automatically, no manual role ordering', + 'Built-in roles can\'t be deleted but are fully editable; customizations survive upgrades, and only untouched files auto-heal on bugfixes', + 'ansible-doc-backed autocomplete while writing roles and playbooks', + 'Upload your own role as an archive', + 'Device-level role assignment with a dedicated Ansible tab on the device detail page', + 'Run history per device, snapshotting the exact role/playbook content that was executed', + 'Wired into VM provisioning: assign roles at VM-creation time and they run automatically after boot', + ], + }, { title: 'Scheduled Operations', items: [ @@ -160,6 +191,17 @@ const en = { 'Failback cron script written to device for netOrk-unreachable scenarios', 'Scheduled config drift fixes with time-window enforcement', 'Package update scheduling and one-click apply', + 'Wake-on-LAN via a firewall\'s driver (OPNsense today) — saved WOL targets with on-demand "Wake now" and recurring schedules; save a seen host as a target directly from the DHCP/ARP tabs', + ], + }, + { + title: 'Satellite Deployments', + items: [ + 'Lightweight Docker agent deployed at a site netOrk can\'t reach directly — polls devices locally and syncs results back to Central over HTTPS', + 'Deployed in one flow via VM provisioning: pick a hypervisor and site, netOrk provisions the VM and installs the satellite container automatically', + 'Central automatically skips direct polling for any device at a site with an online, heartbeating satellite — no manual per-site toggling', + 'Scheduled/on-demand reboots and the SNMP auto-fix flow run through the same command channel whether a device is directly reachable or behind a satellite', + 'Not yet satellite-covered: discovery scans and SNMP health-metric polling still run from Central, and WebSSH console access isn\'t available through a satellite', ], }, { @@ -173,12 +215,24 @@ const en = { 'VM/container list with OS device cross-linking (Proxmox)', ], }, + { + title: 'Dashboards', + items: [ + 'Configurable, shareable dashboards — build your own from a widget picker instead of a fixed layout', + 'WYSIWYG grid-layout editor: drag, resize, and arrange widgets on a canvas', + '13 widget types: stats, device warnings, recently updated devices, network topology, EOL status, config drift summary, Wazuh security alerts, audit log activity, discovery jobs status, upcoming scheduled actions, DNS zones overview, site overview, config snapshot history', + 'Multi-instance widgets with independent per-widget settings, e.g. two warnings widgets scoped to different sites', + 'Share a dashboard with specific users; recipients can subscribe to always see the owner\'s live version, or clone it into their own editable copy', + 'Favorite dashboards for quick access from the main menu; set any dashboard as your home view', + ], + }, { title: 'Security Integrations', items: [ 'Wazuh — agent enrollment tracking, vulnerability counts by severity, recent alert history, CIS benchmark scores, one-click agent install fix stream', 'Graylog — rsyslog forwarding status per device, one-click fix to write rule', 'CrowdSec — org-level decisions, remediation metrics, top attack scenarios', + 'EOL Tracking — flags devices running end-of-life or soon-to-be-end-of-life firmware/OS via the endoflife.date API, checked daily', ], }, { @@ -198,7 +252,7 @@ const en = { 'RBAC with four built-in roles: viewer / operator / engineer / administrator', 'Permissions enforced end-to-end — nav, routes, and write actions are hidden in the UI to match the backend permission checks, not just disabled', 'Custom roles with any permission combination', - 'Full audit log of all orchestration actions', + 'Full audit log of all orchestration actions, filterable by date range, user, action, or resource — export to CSV or PDF', ], }, { @@ -212,10 +266,11 @@ const en = { { title: 'Compliance & Audit (NIS2)', items: [ - 'Full audit log of all orchestration actions — who changed what, when (Art. 21 (2h))', + 'Full audit log of all orchestration actions — who changed what, when (Art. 21 (2h)); export to CSV/PDF, filterable by date range, user, action, or resource', 'Two-factor authentication (MFA/TOTP), enforceable per role — administrative access control (Art. 21 (2i))', 'RBAC with four built-in roles and custom permission sets — access control evidence', 'Per-device patch status and installed package list — patch management baseline (Art. 21 (2e))', + 'EOL Tracking plugin flags devices on unsupported firmware/OS via endoflife.date — supply chain security baseline (Art. 21 (2d))', 'Wazuh CVE counts by severity (critical / high / medium) linked to each device record', 'Git-backed configuration snapshot history with diff viewer and OPNsense restore — config-level backup & recovery evidence (Art. 21 (2c))', 'Config drift tracking: desired state vs. polled state — detect unauthorized changes', @@ -260,7 +315,7 @@ const en = { }, plugins: { heading: 'Plugin System', - sub: 'Integrations are plugins, not core code. Wazuh, Graylog, CrowdSec, and apt-cacher-ng all register through the same pattern — metadata, hooks, tasks, router.', + sub: 'Integrations are plugins, not core code. Wazuh, Graylog, CrowdSec, apt-cacher-ng, and EOL Tracking all register through the same pattern — metadata, hooks, tasks, router.', whatHeading: 'What is a plugin?', builtinHeading: 'Built-in plugins', writingHeading: 'Writing a plugin', @@ -374,6 +429,10 @@ const de: Translations = { heading: 'Konfigurationsbackup und -versionierung', body: 'Bei jedem Poll wird ein Konfigurationssnapshot in einem lokalen Git-Repository gespeichert. Der Config-Tab zeigt die vollständige Snapshot-Historie, einen Side-by-Side-Diff zwischen beliebigen Zeitpunkten und — für OPNsense — einen Restore-Button. Nicht autorisierte Änderungen erscheinen als Gerätewarnung.', }, + screenshot5: { + heading: 'Dashboards, die du wirklich selbst baust', + body: 'Aus 13 Widgets wählen und auf einem WYSIWYG-Grid anordnen — kein festes Layout mehr. Ein Dashboard mit einem Kollegen teilen, der es abonnieren oder in eine eigene Kopie klonen kann, und Favoriten im Hauptmenü anpinnen.', + }, nis2Label: 'NIS2 · Art. 21', nis2Heading: 'Nachweise, keine Papierwüste.', nis2Body: 'NIS2 Art. 21 schreibt Geräteinventar, Patch-Management, Zugangskontrolle und Audit-Trails als technische Basismaßnahmen vor. netOrk fügt keine Compliance-Schicht auf — das sind seine normalen Tagesausgaben.', @@ -385,7 +444,7 @@ const de: Translations = { { art: 'Art. 21 (2b)', label: 'Incident-Erkennung', detail: 'Wazuh-Alert-Historie, CrowdSec-Entscheidungen, Graylog-Syslog pro Gerät' }, ], pluginsHeading: 'Erweiterbar konzipiert', - pluginsBody: 'Integrationen (Wazuh, Graylog, CrowdSec, apt-cacher-ng) sind Plugins, die im Plugin-System registriert werden — sie lassen sich pro Deployment ohne Code-Änderungen aktivieren oder deaktivieren. Eine neue Integration folgt einem dokumentierten Muster mit Hook-Bus, typisiertem Metadatum und Plugin-Registry.', + pluginsBody: 'Integrationen (Wazuh, Graylog, CrowdSec, apt-cacher-ng, EOL-Tracking) sind Plugins, die im Plugin-System registriert werden — sie lassen sich pro Deployment ohne Code-Änderungen aktivieren oder deaktivieren. Eine neue Integration folgt einem dokumentierten Muster mit Hook-Bus, typisiertem Metadatum und Plugin-Registry.', pluginsLink: 'Plugin-System-Dokumentation →', deployHeading: 'Self-hosted. Ein Befehl.', deployBody: 'netOrk läuft in Docker Compose. Fünf Container: API, zwei Worker-Pools, ein Beat-Scheduler und ein nginx-UI-Server. Keine externen Abhängigkeiten außer Redis und PostgreSQL.', @@ -418,6 +477,19 @@ const de: Translations = { 'Manuelle Übernahme aus Scan-Ergebnissen — kein Auto-Create, um Inventar-Rauschen zu vermeiden', ], }, + { + title: 'VM-Provisioning', + items: [ + 'Cloud-Init-basierte VM-Erstellung direkt aus dem VMs-Tab eines Hypervisors — kein manuelles Template- oder VMID-Setup', + 'Multi-Distro-Image-Katalog: Debian 12, Ubuntu 22.04/24.04/26.04, Fedora 42/43/44 — Ubuntu- und Fedora-Releases werden automatisch synchronisiert, sobald neue Versionen erscheinen', + 'Ziel-VLAN und IP aus dessen Subnetz auswählen — netOrk legt die DHCP-Reservierung automatisch an', + 'Cloud-Init richtet einen echten Linux-Benutzer mit SSH-Schlüssel ein, plus konfigurierbare Bootstrap-Optionen (SNMP, QEMU-Guest-Agent)', + 'Wiederverwendbare Provisioning-Templates für wiederkehrende Bootstrap-Einstellungen', + 'Die neue VM wird nach Abschluss des Bootstraps automatisch als netOrk-Gerät verknüpft und ihr Hostname einer DNS-Zone zugewiesen', + 'Deploy-Fortschritt als Live-Schritt-Checkliste in der UI', + 'VM und verknüpftes netOrk-Gerät gemeinsam löschen, abgesichert durch eine Namens-Bestätigungsabfrage', + ], + }, { title: 'Unterstützte Treiber', items: [ @@ -458,6 +530,20 @@ const de: Translations = { 'Nicht autorisierte Konfigurationsänderungen werden als Gerätewarnung angezeigt', ], }, + { + title: 'Konfigurationsautomatisierung (Ansible)', + items: [ + 'Wiederverwendbare Ansible-Rollen und -Playbooks, direkt in netOrk gespeichert und bearbeitet — kein separates Git-Checkout', + '11 eingebaute Rollen sofort zuweisbar: base, ubuntu, docker, adguard, zoraxy, portainer, watchtower, uptime-kuma, vaultwarden, wireguard, fail2ban', + 'Automatische Abhängigkeitsauflösung — die Zuweisung von docker zieht base automatisch nach, keine manuelle Rollen-Reihenfolge nötig', + 'Eingebaute Rollen lassen sich nicht löschen, sind aber vollständig editierbar; Anpassungen überstehen Updates, nur unveränderte Dateien heilen bei Bugfixes automatisch nach', + 'ansible-doc-gestützte Autovervollständigung beim Schreiben von Rollen und Playbooks', + 'Eigene Rolle als Archiv hochladen', + 'Rollenzuweisung auf Geräteebene mit eigenem Ansible-Tab in der Gerätedetailansicht', + 'Lauf-Historie pro Gerät, mit Snapshot des tatsächlich ausgeführten Rollen-/Playbook-Inhalts', + 'In VM-Provisioning eingebunden: Rollen bei VM-Erstellung zuweisen — sie laufen automatisch nach dem Boot', + ], + }, { title: 'Geplante Operationen', items: [ @@ -465,6 +551,17 @@ const de: Translations = { 'Failback-Cron-Skript auf Gerät geschrieben für netOrk-nicht-erreichbar-Szenarien', 'Geplante Konfigurationsdrift-Korrekturen mit Zeitfenster-Durchsetzung', 'Paket-Update-Planung und Ein-Klick-Anwendung', + 'Wake-on-LAN über den Treiber einer Firewall (aktuell OPNsense) — gespeicherte WOL-Ziele mit Ein-Klick-„Jetzt wecken" und wiederkehrenden Zeitplänen; ein gesehener Host lässt sich direkt aus den DHCP-/ARP-Tabs als Ziel speichern', + ], + }, + { + title: 'Satellite-Deployments', + items: [ + 'Leichtgewichtiger Docker-Agent für Standorte, die netOrk nicht direkt erreicht — pollt Geräte lokal und synct Ergebnisse per HTTPS zurück an Central', + 'In einem Ablauf per VM-Provisioning deployt: Hypervisor und Standort auswählen, netOrk provisioniert die VM und installiert den Satellite-Container automatisch', + 'Central überspringt automatisch das direkte Polling für jedes Gerät an einem Standort mit einem online, aktuell heartbeatenden Satellite — kein manuelles Umschalten pro Standort', + 'Geplante/On-Demand-Neustarts und der SNMP-Auto-Fix laufen über denselben Command-Kanal, egal ob ein Gerät direkt erreichbar ist oder hinter einem Satellite liegt', + 'Noch nicht satellite-abgedeckt: Discovery-Scans und SNMP-Health-Metrik-Polling laufen weiterhin über Central, und WebSSH-Konsolenzugriff ist über einen Satellite nicht verfügbar', ], }, { @@ -478,12 +575,24 @@ const de: Translations = { 'VM/Container-Liste mit OS-Geräteverknüpfung (Proxmox)', ], }, + { + title: 'Dashboards', + items: [ + 'Konfigurierbare, teilbare Dashboards — eigene Dashboards aus einer Widget-Auswahl bauen statt festes Layout', + 'WYSIWYG-Grid-Layout-Editor: Widgets auf einem Canvas per Drag & Drop platzieren und in der Größe anpassen', + '13 Widget-Typen: Stats, Gerätewarnungen, kürzlich aktualisierte Geräte, Netzwerktopologie, EOL-Status, Konfigurationsdrift-Zusammenfassung, Wazuh-Sicherheitsalerts, Audit-Log-Aktivität, Discovery-Job-Status, anstehende geplante Aktionen, DNS-Zonen-Übersicht, Standortübersicht, Konfigurationssnapshot-Historie', + 'Mehrfachinstanzen desselben Widgets mit unabhängigen Einstellungen pro Widget, z. B. zwei Warnungs-Widgets für unterschiedliche Standorte', + 'Dashboard mit bestimmten Benutzern teilen; Empfänger können es abonnieren, um immer die aktuelle Version des Owners zu sehen, oder es als eigene, editierbare Kopie klonen', + 'Dashboards als Favorit markieren für schnellen Zugriff über das Hauptmenü; jedes Dashboard als Home-Ansicht festlegen', + ], + }, { title: 'Sicherheitsintegrationen', items: [ 'Wazuh — Agent-Enrollment-Tracking, Schwachstellenanzahl nach Schweregrad, Alert-Historie, CIS-Benchmark-Scores, Ein-Klick-Agent-Install-Fix-Stream', 'Graylog — rsyslog-Weiterleitungsstatus pro Gerät, Ein-Klick-Fix zum Schreiben der Regel', 'CrowdSec — Org-Level-Entscheidungen, Remediation-Metriken, Top-Angriffsszenarien', + 'EOL-Tracking — kennzeichnet Geräte mit End-of-Life- oder bald End-of-Life-Firmware/OS über die endoflife.date-API, täglich geprüft', ], }, { @@ -503,7 +612,7 @@ const de: Translations = { 'RBAC mit vier integrierten Rollen: Betrachter / Operator / Ingenieur / Administrator', 'Berechtigungen durchgängig erzwungen — Navigation, Routen und Schreibaktionen werden in der UI passend zu den Backend-Prüfungen ausgeblendet, nicht nur deaktiviert', 'Benutzerdefinierte Rollen mit beliebiger Berechtigungskombination', - 'Vollständiges Audit-Log aller Orchestrierungsaktionen', + 'Vollständiges Audit-Log aller Orchestrierungsaktionen, filterbar nach Datumsbereich, Benutzer, Aktion oder Ressource — Export als CSV oder PDF', ], }, { @@ -517,10 +626,11 @@ const de: Translations = { { title: 'Compliance & Audit (NIS2)', items: [ - 'Vollständiges Audit-Log aller Orchestrierungsaktionen — wer hat was wann geändert (Art. 21 (2h))', + 'Vollständiges Audit-Log aller Orchestrierungsaktionen — wer hat was wann geändert (Art. 21 (2h)); Export als CSV/PDF, filterbar nach Datumsbereich, Benutzer, Aktion oder Ressource', 'Zwei-Faktor-Authentifizierung (MFA/TOTP), pro Rolle erzwingbar — Zugangskontrolle für administrative Konten (Art. 21 (2i))', 'RBAC mit vier integrierten Rollen und benutzerdefinierten Berechtigungssätzen — Zugangskontrollnachweis', 'Patch-Status und installierte Paketliste pro Gerät — Patch-Management-Baseline (Art. 21 (2e))', + 'EOL-Tracking-Plugin kennzeichnet Geräte mit nicht unterstützter Firmware/OS über endoflife.date — Supply-Chain-Sicherheits-Baseline (Art. 21 (2d))', 'Wazuh-CVE-Anzahl nach Schweregrad (kritisch / hoch / mittel) verknüpft mit jedem Gerätedatensatz', 'Git-basierte Konfigurationssnapshot-Historie mit Diff-Viewer und OPNsense-Restore — Backup- & Recovery-Nachweis auf Konfigurationsebene (Art. 21 (2c))', 'Konfigurationsdrift-Tracking: Sollzustand vs. abgefragter Zustand — nicht autorisierte Änderungen erkennen', @@ -565,7 +675,7 @@ const de: Translations = { }, plugins: { heading: 'Plugin-System', - sub: 'Integrationen sind Plugins, kein Core-Code. Wazuh, Graylog, CrowdSec und apt-cacher-ng registrieren sich alle über dasselbe Muster — Metadaten, Hooks, Tasks, Router.', + sub: 'Integrationen sind Plugins, kein Core-Code. Wazuh, Graylog, CrowdSec, apt-cacher-ng und EOL-Tracking registrieren sich alle über dasselbe Muster — Metadaten, Hooks, Tasks, Router.', whatHeading: 'Was ist ein Plugin?', builtinHeading: 'Eingebaute Plugins', writingHeading: 'Ein Plugin schreiben', diff --git a/src/pages/Home.tsx b/src/pages/Home.tsx index ec9e5aa..3b7f16d 100644 --- a/src/pages/Home.tsx +++ b/src/pages/Home.tsx @@ -199,6 +199,33 @@ function MockConfigDiff() { ) } +function MockDashboard() { + const widgets = [ + { label: 'Stats', span: 'col-span-2' }, + { label: 'Device Warnings', span: 'col-span-1' }, + { label: 'Network Topology', span: 'col-span-2' }, + { label: 'EOL Status', span: 'col-span-1' }, + ] + return ( +
{linkify(h.screenshot4.body)}
+{linkify(h.screenshot5.body)}
+