feat: reflect netOrk v0.5.0–v0.9.0 release notes across the site

Dashboards (configurable/shareable, 13 widgets, WYSIWYG grid editor) and
the EOL Tracking plugin ship in v0.5.x, so both move from roadmap to
shipped: Features, Plugins, NIS2 mapping, and a homepage screenshot row.

v0.6.0–v0.9.0 add three more major capabilities, verified against code
rather than the (partly stale) TODO.md: VM Provisioning (Cloud-Init VMs
from a hypervisor's VMs tab), Ansible-based configuration automation (11
built-in roles, VM-provisioning integration), and Satellite deployments
(a remote polling agent for sites Central can't reach directly, with its
current limitations noted honestly). Wake-on-LAN and the audit log
CSV/PDF export (previously a roadmap item) round out the update.

Roadmap and the NIS2 coverage page are reconciled to match: shipped items
removed from "planned"/"coming", Art. 21 (2d) and (2h) text updated.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Christian Manivong
2026-07-15 10:22:16 +02:00
co-authored by Claude Sonnet 5
parent d8892c53ce
commit d8fd9fe675
7 changed files with 282 additions and 61 deletions
+23 -12
View File
@@ -156,6 +156,14 @@ Each badge uses the `Driver / Integration Badge` component from DESIGN.md.
device warning.`
- Screenshot: ConfigTab inside DeviceDetailPage
**Row 5 — Left text, right screenshot**
- Heading: `Dashboards you actually build`
- Copy: `Pick from 13 widgets and arrange them on a WYSIWYG grid — no
more fixed layout. Share a dashboard with a colleague, let them
subscribe to your live version or clone it into their own, and pin
favorites to the main menu.`
- Screenshot: DashboardDetailPage (edit mode)
---
### Section 5b — NIS2
@@ -254,16 +262,21 @@ sticky section nav). One section per capability area.
**Sections** (map directly to feature list in `docs/PRODUCT.md`):
1. Device Management
2. Discovery
3. Supported Drivers (full table)
4. Networking & Inventory
5. Configuration Management & Drift
6. Scheduled Operations
7. Monitoring & Health
8. Security Integrations
9. DNS Management
10. Access Control (RBAC)
11. NetBox Sync
12. Developer Experience
3. VM Provisioning
4. Supported Drivers (full table)
5. Networking & Inventory
6. Configuration Management & Drift
7. Configuration Automation (Ansible)
8. Scheduled Operations
9. Satellite Deployments
10. Monitoring & Health
11. Dashboards
12. Security Integrations
13. DNS Management
14. Access Control (RBAC)
15. NetBox Sync
16. Compliance & Audit (NIS2)
17. Developer Experience
Each section: `text-xl font-semibold text-slate-200` heading +
feature items as a clean list with `text-slate-400` body.
@@ -340,7 +353,6 @@ address NIS2 Art. 21 technical baseline requirements.
**Planned items (NIS2-tagged):**
- CVE tracking per device — NVD / OSV cross-reference
- Compliance dashboard — per-site Art. 21 checklist view
- Audit log export — PDF / CSV with filters
**Planned items (general):**
- Webhook engine — outbound events with HMAC signing
@@ -349,7 +361,6 @@ address NIS2 Art. 21 technical baseline requirements.
**Under consideration (NIS2-tagged):**
- Incident workflow — structured record + NIS2 Art. 23 Fristen-Tracker
- EOL tracking — endoflife.date integration for firmware / OS
**Under consideration (general):**
- mDNS scanner — media device discovery
+97 -11
View File
@@ -68,8 +68,21 @@ hardware and want operational visibility beyond what consumer dashboards offer.
9. **NIS2 evidence foundation** — NIS2 Art. 21 mandates asset inventory, patch
management, access control, and audit trails. netOrk produces all of these as
day-to-day operational outputs: full device inventory, per-device update status,
Wazuh CVE tracking, RBAC with MFA, Git-backed config snapshots with diff/restore,
config drift detection, and a complete audit log.
Wazuh CVE tracking, EOL firmware/OS flagging, RBAC with MFA, Git-backed config
snapshots with diff/restore, config drift detection, and a complete audit log.
10. **Build your own view** — Configurable, shareable dashboards: pick from 13
widgets, arrange them on a WYSIWYG grid, and share the result with colleagues
who can subscribe to the live version or clone their own copy.
11. **From zero to managed in one flow** — Provision a Cloud-Init VM on a
Proxmox hypervisor, assign Ansible roles to configure it, and netOrk
auto-links it as a Device — no separate tools, no manual SSH-and-copy.
12. **Reach sites netOrk can't touch directly** — Deploy a lightweight
Satellite agent to poll devices locally at a disconnected or firewalled
site and sync results back over HTTPS; scheduled fixes route through it
the same way they do for directly reachable devices.
---
@@ -89,6 +102,23 @@ hardware and want operational visibility beyond what consumer dashboards offer.
- FQDN resolution (reverse DNS)
- Manual adoption from scan results (no auto-create to avoid inventory noise)
### VM Provisioning
- Cloud-Init based VM creation directly from a hypervisor's VMs tab — no
manual template or VMID setup
- Multi-distro image catalog: Debian 12, Ubuntu 22.04/24.04/26.04,
Fedora 42/43/44, with Ubuntu and Fedora releases synced automatically as
new versions ship
- Pick a target VLAN and an IP from its subnet — netOrk creates the DHCP
reservation automatically
- Cloud-init provisions a real Linux user with an SSH key, plus configurable
bootstrap toggles (SNMP, QEMU guest agent)
- Reusable provisioning templates for repeatable bootstrap settings
- The new VM is auto-linked as a netOrk Device and its hostname assigned to
a DNS zone once bootstrap finishes
- Deploy progress shown as a live step checklist in the UI
- Delete a VM and its linked netOrk Device together, gated behind a
name-confirmation prompt
### Supported Device Drivers
Custom NAPALM drivers for all of the following:
@@ -127,11 +157,46 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
- One-click config restore for OPNsense from any prior snapshot
- Unauthorised configuration changes are surfaced as a device warning
### Configuration Automation (Ansible)
- Reusable Ansible roles and playbooks stored and edited directly in
netOrk — no separate git checkout
- 11 built-in roles ready to assign: base, ubuntu, docker, adguard, zoraxy,
portainer, watchtower, uptime-kuma, vaultwarden, wireguard, fail2ban
- Automatic dependency resolution — assigning `docker` pulls in `base`
automatically, no manual role ordering
- Built-in roles can't be deleted but are fully editable; customizations
survive upgrades, and only untouched files auto-heal on bugfixes
- `ansible-doc`-backed autocomplete while writing roles and playbooks
- Upload your own role as an archive
- Device-level role assignment with a dedicated Ansible tab on the device
detail page
- Run history per device, snapshotting the exact role/playbook content
that was executed
- Wired into VM provisioning: assign roles at VM-creation time and they
run automatically after boot
### Scheduled Operations
- Scheduled reboots for OpenWRT APs with per-site concurrency lock
- Failback cron script written to device for netOrk-unreachable scenarios
- Scheduled config drift fixes with time-window enforcement
- Package update scheduling and one-click apply
- Wake-on-LAN via a firewall's driver (OPNsense today) — saved WOL targets
with on-demand "Wake now" and recurring schedules; save a seen host as a
target directly from the DHCP/ARP tabs
### Satellite Deployments
- Lightweight Docker agent deployed at a site netOrk can't reach directly —
polls devices locally and syncs results back to Central over HTTPS
- Deployed in one flow via VM provisioning: pick a hypervisor and site,
netOrk provisions the VM and installs the satellite container automatically
- Central automatically skips direct polling for any device at a site with
an online, heartbeating satellite — no manual per-site toggling
- Scheduled/on-demand reboots and the SNMP auto-fix flow run through the
same command channel whether a device is directly reachable or behind a
satellite
- Not yet satellite-covered: discovery scans and SNMP health-metric polling
still run from Central, and WebSSH console access isn't available through
a satellite
### Monitoring & Health
- SNMP health metrics (CPU, memory, interface counters) via `get_health_metrics()`
@@ -143,11 +208,27 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
- Service status and start/stop/restart (systemd)
- VM/container list with OS device cross-linking (Proxmox)
### Dashboards
- Configurable, shareable dashboards — build your own from a widget picker
instead of a fixed layout
- WYSIWYG grid-layout editor: drag, resize, and arrange widgets on a canvas
- 13 widget types: stats, device warnings, recently updated devices, network
topology, EOL status, config drift summary, Wazuh security alerts, audit log
activity, discovery jobs status, upcoming scheduled actions, DNS zones
overview, site overview, config snapshot history
- Multi-instance widgets with independent per-widget settings
- Share a dashboard with specific users; recipients can subscribe to the
owner's live version or clone it into their own editable copy
- Favorite dashboards for quick access from the main menu; set any dashboard
as your home view
### Security Integrations (plugins)
- **Wazuh** — agent enrollment tracking, vulnerability counts (by severity),
recent alert history, CIS benchmark scores, one-click agent install fix stream
- **Graylog** — rsyslog forwarding status per device, one-click fix to write rule
- **CrowdSec** — org-level decisions, remediation metrics, top attack scenarios
- **EOL Tracking** — flags devices running end-of-life or soon-to-be-end-of-life
firmware/OS via the endoflife.date API, checked daily
### DNS
- DNS zone management with authoritative device assignment
@@ -162,7 +243,8 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
per role
- RBAC with four built-in roles: viewer / operator / engineer / administrator
- Custom roles with any permission combination
- Full audit log of all orchestration actions
- Full audit log of all orchestration actions, filterable by date range,
user, action, or resource — export to CSV or PDF
### NetBox Sync
- Pushes vendor, model, OS version, status to NetBox dcim.devices
@@ -180,11 +262,15 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
## Architecture in One Paragraph
netOrk runs as five Docker containers: a FastAPI API server, two Celery worker
pools (general + poll), a Celery Beat scheduler, and an nginx UI server. Redis
is the broker. PostgreSQL stores all state. Device communication is always
blocking I/O executed in Celery workers — FastAPI request handlers are
async-only for DB and quick operations. Custom NAPALM drivers live in `vendor/`
as editable packages and self-register via `@register_driver`. The plugin system
(`netork/plugins/`) provides a hook bus, a plugin registry with enable/disable
state in the DB, and a documented pattern for adding integrations.
netOrk runs as a set of Docker containers: a FastAPI API server, three Celery
worker pools (general, poll, and Ansible), a Celery Beat scheduler, and an
nginx UI server. Redis is the broker. PostgreSQL stores all state. Device
communication is always blocking I/O executed in Celery workers — FastAPI
request handlers are async-only for DB and quick operations. Custom NAPALM
drivers live in `vendor/` as editable packages and self-register via
`@register_driver`. The plugin system (`netork/plugins/`) provides a hook bus,
a plugin registry with enable/disable state in the DB, and a documented
pattern for adding integrations. For sites Central can't reach directly, a
separate Satellite container polls devices locally and syncs results back
over HTTPS; Central dispatches actions (reboots, SNMP fixes) to it through a
generic command channel, transparently to the UI.