The site felt old, unfocused and bloated: 11 pages, a features page of 171
bullets, a homepage of 830 words in card grids around seven mockup-style
screenshots, and no single thing it wanted a visitor to understand.
- Message: control instead of drift. Audience: IT departments in small and
mid-sized companies. Goal: buy a licence — netOrk itself is free, the
licence adds vulnerability data and image updates.
- Home is under 400 words: the drift comparison of a real access point, three
steps, the hardware it runs on, vulnerabilities with a licence, what else is
in the box, one closing band. Features, Drivers and Roadmap are gone; their
URLs redirect (router and nginx 301).
- New Pricing page: the free core, Starter / Pro / Enterprise on request with
the plan differences from the licence server, four questions; buttons go to
the licence portal. The unit-less KB request limit is left out.
- Persona pages are one template; NIS2 and Plugins are cut to half or less.
Impressum and Datenschutz exist as marked placeholders; the unsupported
"MIT licence" claim is gone from the footer.
- Look: light paper and ink, the dark product on a stage, Inter self-hosted,
split sections and ruled lists instead of cards. Four real, cropped
screenshots replace eight full-window ones.
- Language follows the browser until someone chooses; <html lang> is set.
Scroll-to-top on navigation, a catch-all route, no dead /docs/architecture.
- CLAUDE.md, DESIGN.md, PAGES.md and PRODUCT.md describe the new rules.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- shots.py crops to a region (clip) or to what one or more elements cover
(element, pad), per-shot viewport; capture.py writes the published sizes to
src/data/screenshots.json so the page reserves the right space.
- anonymize.py no longer empties secrets that netOrk compares with each other
(Wi-Fi keys on an SSID against the key read from the access point). Emptying
them invented passphrase "drift" that never existed; a keyed hash keeps equal
equal, reverses nothing, and its key lives for one run.
- scripts/check/site.py checks the built site in both languages at four widths:
sideways overflow, one h1, images with alt and size, console errors, requests
to other origins, links to unknown routes, old-URL redirects, language
detection, and word counts against the budgets.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- The navigation had no mobile layout: every page was 413px wider than a
phone. Below lg the links now sit behind a menu button, grouped like the
desktop dropdowns; the menu closes on navigation.
- Glossary tooltips were invisible but still laid out, so a term near the
right edge widened the page. Hidden tooltips no longer take up space;
they show on hover and on keyboard focus as before.
- Long German words in page headings ("produktionstauglich",
"Konfigurationstiefe") overflowed at 360px; headings start a size smaller
on phones.
- The roadmap intro dropped everything after its second "NIS2" ("…the
baseline requirements of"); it is split at the first one only now.
Checked at 360, 390 and 768px on every page: no horizontal overflow.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The homepage showed seven hand-built JSX imitations of the netOrk UI. They
are gone; every image is now a screenshot of netOrk v0.28.0 itself, taken
from an anonymized copy of a production database (scripts/demo) with
scripts/screenshots/capture.py and published as WebP (~630 KB for all eight).
- Hero: the device inventory. Walkthrough: device detail, VLANs, the Security
tab, the vulnerability triage queue (replacing the config-diff row), the
dashboard and service checks (new row 6). NIS2: the audit log, filtered to
what people did.
- Copy follows the images: row 3 describes the security assessment, row 4 the
triage queue; row 2 no longer claims corrections are always automatic;
18 widgets. Alt texts in both languages.
- Also fixed on the homepage: the NIS2 teaser for Art. 21 (2e) and the
container list of a deployment (three worker pools, plus Flower, registry,
APT cache and the Signal gateway).
- Demo tooling hardened on the real dump: secrets inside JSON (Wi-Fi keys),
reverse DNS zones, glued identifiers, tens of thousands of CrowdSec
addresses, a schema newer than the release (anonymize, then downgrade),
MFA-enforcing roles, and click steps for view filters.
- DESIGN.md: real screenshots only. PAGES.md: the six rows as they are.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The site has shown hand-built JSX mockups of the UI so far. This adds the
tooling to replace them with screenshots of the real application:
- scripts/demo/up.sh restores a pg_dump of a production database into a
local Postgres and starts netOrk (a pinned release, default v0.28.0) with
only the API and the UI: no worker, no beat, no Redis, a random encryption
key. Nothing polls and nothing can reach a device.
- scripts/demo/anonymize.py rewrites every text, JSON and address column of
every table: domains to example.demo, private IPv4 per /16 with the host
part kept, public addresses into the documentation ranges, MACs with the
vendor prefix kept, e-mail addresses and configured names. Secrets are
emptied by column name, one admin "netork" is left. It refuses non-local
databases and ends with a leak report. The real-to-demo name map lives
outside the repo.
- scripts/screenshots/capture.py drives headless Chromium through a
declarative list of pages, logs in to the demo copy by itself, and aborts
every non-GET API request, so taking screenshots cannot change anything.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Seventeen releases since the site was last brought up to date, checked
against the changelog and the code at the v0.28.0 tag.
- New feature sections: Security Assessment (TLS/SSH grades, CVE and
container-image matching, exposure, deep scans; Knowledge Base licence),
Vulnerability Management (triage queue, decisions with reasons, deferrals
that come back, verified fixes), DHCP, Managed Services, Notifications
(Signal).
- Existing sections gain per-user SSH keys and session windows, multi-role
devices, one device per address per site, LAN Scan, MAC-table topology,
service checks, site reachability, per-site firewall profiles with diff,
honoured drift auto-correct, 16 Ansible roles, 18 dashboard widgets.
- Corrections: Docker status is Linux/OMV/QNAP, not Proxmox.
- Roadmap: CVE tracking shipped and is gone from "Planned"; a "Next release"
group lists what is on main but unreleased (CrowdSec across sites, Windows
driver, single-use console tickets, reboots refused instead of faked).
- NIS2: Art. 21 (2e) now describes the vulnerability handling that exists,
(2i) adds attributable terminal sessions; CVE tracking left "coming".
- Persona pages: two new items each, counts updated. Glossary: Kea, WinRM,
LAPI.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Audited the drivers that actually ship in v0.28.0 (vendor-drivers.txt at the
tag, each driver package at its pin) instead of carrying the old table on.
- Reboot: netOrk's reboot really restarts only OpenWrt and Proxmox. For every
other driver the request reported success while nothing happened, so the
column now says so. Rebooting through an update run is mentioned in a note.
- Config push: OPNsense, ProCurve, TP-Link JetStream, Netgear Smart and Proxmox
do get configuration written by netOrk; the column was missing them.
- Zyxel is a VMG residential gateway, not a switch: no LLDP, VLANs or health,
but SSIDs. Fritz!Box is read-only and has no health metrics. Proxmox has no
Docker view.
- netgear is two drivers, netgear_smart and netgear_plus. New: hpe_officeconnect,
qnap_qts, yealink.
- The built-in NAPALM drivers are installed but untested with netOrk and get
none of its driver-specific features; the page no longer says "supported".
- Notes explain the Health, LLDP, Config push and Reboot columns.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diese Anwendung teilt sich Netz, Datenbankcluster, öffentlichen Eingang und
Backup mit anderen Projekten. Wer dort etwas ändert, ändert es für alle, und
dem eigenen Repo sieht man es nicht an.
Die Regel steht vollständig in christianmanivong/infrastructure; hier nur der
Verweis, damit sie dort gelesen wird, wo gearbeitet wird.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The image moves off registry.netork.io. That registry is plain registry:2 with
htpasswd auth, which knows nothing about repositories: every account that can log
in reads and writes everything on it, including the accounts issued to customer
instances. Verified -- a customer server's credentials list the whole catalogue.
It keeps the images those instances are meant to pull; the marketing site is not
one of them. Gitea scopes packages to their owning account, and no customer has
one. netOrk #172.
Login uses a REGISTRY_TOKEN secret (a Gitea token with write:package). The token
Actions injects per run does not work here -- the package registry rejects it
with a bare "unauthorized", which is a confusing way to spend an afternoon.
The deploy job is removed rather than migrated, because it had quietly stopped
being correct. It ran `docker run` against whatever runner picked the job up,
which worked while exactly one runner existed. There are now several --
netork-runner-12 on .12, netork-runner-13 on .13, plus the original
netork-runner -- and none of them is on 10.7.224.11, where this site runs and
where the proxy-net it attaches to lives. The next push would have started a
second website container on the wrong host and reported success while netork.io
went on serving the old one. Nothing had failed yet; the last deploy was
2026-07-17, back when the pool was one runner.
scripts/deploy.sh replaces it: it names the target, pulls before it removes
anything, compares the running container's image id against what was pulled, and
finishes by checking that netork.io actually answers 200.
Push-to-deploy can come back by registering a runner on .11 with a label of its
own and pinning `runs-on:` to it, or by giving CI an ssh key. Both decide where a
credential lives, so neither was decided here.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Adds three "who it's for" pages reachable via a new nav dropdown, each
built around a distinct day-to-day workflow rather than a reworded
homepage pitch:
- /for/it-department — the core admin/engineer audience: drift-fix,
Ansible automation, VM provisioning, dashboards
- /for/it-support — day-to-day operators: status at a glance, one-click
Ack, Wake-on-LAN, scheduled reboots, filterable audit log
- /for/msp — managed service providers: Satellite deployments for
unreachable client sites, audit trail as client-facing evidence,
self-hosted with no per-seat SaaS
The MSP page deliberately avoids claiming per-site/per-customer RBAC —
verified against netork/models/role.py that permissions are global
role-based sets, not site-scoped, and phrased the copy accordingly.
Nav.tsx's Docs dropdown logic is extracted into a reusable NavDropdown
component (open state, outside-click, route-change-close) instead of
being duplicated for the new "Für wen" dropdown, which also links to
the existing /nis2 page rather than rebuilding that persona.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Corrects a claim from the previous update: Satellite Phase 3 shipped, so
discovery scans now run through satellite-covered sites too (only SNMP
health-metric polling and WebSSH remain Central-only).
New capabilities added to the feature list: per-device availability
windows (suppress false OFFLINE warnings during expected downtime),
per-SSID MAC access-control lists with a dedicated Wireless ACL tab, a
new RADIUS Management section (global FreeRADIUS server/NAS/user
management), and three OPNsense monitoring additions (BGP neighbors, TLS
certificate/Trust-store monitoring, DDNS-down warning). Also notes that
netOrk's own config pushes are now auto-recognized so they're never
mistaken for an unauthorized change.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Dashboards (configurable/shareable, 13 widgets, WYSIWYG grid editor) and
the EOL Tracking plugin ship in v0.5.x, so both move from roadmap to
shipped: Features, Plugins, NIS2 mapping, and a homepage screenshot row.
v0.6.0–v0.9.0 add three more major capabilities, verified against code
rather than the (partly stale) TODO.md: VM Provisioning (Cloud-Init VMs
from a hypervisor's VMs tab), Ansible-based configuration automation (11
built-in roles, VM-provisioning integration), and Satellite deployments
(a remote polling agent for sites Central can't reach directly, with its
current limitations noted honestly). Wake-on-LAN and the audit log
CSV/PDF export (previously a roadmap item) round out the update.
Roadmap and the NIS2 coverage page are reconciled to match: shipped items
removed from "planned"/"coming", Art. 21 (2d) and (2h) text updated.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
linkify() was returning a bare array, so its fragments landed as
direct children of flex <li> bullets — each text/link piece became
its own flex item and scrambled the reading order on wrap. Now
wrapped in a single <span> so text flows normally.
Tooltips also always centered under the term regardless of position,
overflowing off-screen near the viewport edges. GlossaryMark now
measures the anchor on hover and flips to a left- or right-aligned
placement when centering would push it out of view.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Every abbreviation and technical term used in the site's copy (RBAC,
NAPALM, config drift, ...) now links to a new /glossary page and shows
a short definition on hover, wherever it appears in body text. Product
and vendor brand names are deliberately excluded — the glossary stays
a dictionary of vocabulary, not a company directory.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- Document the Web-SSH browser console and end-to-end RBAC enforcement
(frontend gating added in v0.4.3), both previously missing from the
feature list.
- Sync the roadmap with netOrk's docs/TODO.md: add Vault integration
and the firewall-profile rework (top engineering priorities) and
VLAN visualization.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The nav and footer have linked to /plugins since the start, but no
route or page existed, so it rendered blank. Adds the page per the
docs/PAGES.md spec — plugin building blocks, the four built-in
plugins, a step-by-step "writing a plugin" guide with real code from
netork/plugins/, and the fire/call/transform hook bus — sourced from
the actual plugin system in the main NetOrk repo for accuracy.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Moves MFA/TOTP and config backup & versioning from roadmap to shipped
across the NIS2 coverage page, features list, and roadmap, and adds a
homepage screenshot row for the new config snapshot/diff/restore UI.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Add LangContext with localStorage persistence (default: DE).
DE/EN toggle in Nav (top-right, before CTA button).
All pages translated:
- Home: all 8 sections incl. NIS2 block
- Features: all 13 sections with full German bullet points
- Drivers: headings and descriptions
- Getting Started (coming soon)
- Roadmap: bilingual data arrays inline (Planned + Under consideration)
- NIS2: full Art. 21 mapping, evidence blocks, coming-soon list
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- New /nis2 page: full Art. 21 mapping with covered/partial/roadmap/n-a
tags, evidence-by-trigger breakdown, and roadmap callout
- New /roadmap page: planned and under-consideration items, NIS2-tagged
items highlighted with monospace badge
- Home: new NIS2 section between screenshots and plugin block — Art. 21
mapping list + MockCompliance UI + link to /nis2
- Features: new "Compliance & Audit (NIS2)" section
- Nav: Roadmap link added; NIS2 in Docs dropdown
- Footer: Roadmap and NIS2 links added
- docs/PRODUCT.md: NIS2 evidence foundation as value proposition #9
- docs/PAGES.md: /nis2, /roadmap, and NIS2 home section documented
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Deployment path not yet available; commercial plans in preparation.
Replace step-by-step install guide with a coming-soon page and
mailto CTA. Update hero + footer CTA on landing page accordingly.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Workflow (3 jobs, all on the local netork-runner on 10.7.224.11):
typecheck (ubuntu-latest)
→ npm ci + tsc --noEmit on every push/PR
publish (ubuntu-latest, main only)
→ docker build + push to registry.netork.io/netork/website:latest
and registry.netork.io/netork/website:main-<sha>
deploy (build/host, after publish)
→ runs directly on the host (no SSH needed)
→ copies docker-compose.yml to /opt/netork-website/
→ docker compose pull + up -d --remove-orphans
docker-compose.yml: replaced local build: . with
registry.netork.io/netork/website:latest so the deploy job
pulls the just-published image instead of building again.
Required Gitea secrets: REGISTRY_USER, REGISTRY_PASSWORD
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Establishes the documentation foundation for the netOrk website:
- CLAUDE.md — tech stack (React 18/Vite/Tailwind), design rules, tone of
voice, and file structure guidance for the implementation instance
- docs/PRODUCT.md — one-liner, elevator pitch, target audience, value props,
full feature list, driver table, architecture summary
- docs/DESIGN.md — exact Tailwind classes for colors, typography, spacing,
and all reusable component patterns (cards, buttons, screenshot frames,
badges, nav) lifted directly from the product UI
- docs/PAGES.md — page-by-page content plan with route, purpose, section
structure, and draft copy for every page
No code yet — that follows in a separate instance.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>