Brings the site from netOrk v0.11 (last update 2026-07-17) to v0.28.0, and replaces every hand-built UI mockup with a real screenshot of netOrk.
Real screenshots instead of mockups
The images come from an anonymized copy of a production database, served by netOrk v0.28.0 running locally. scripts/demo/up.sh restores the copy, scripts/demo/anonymize.py anonymizes it, and scripts/screenshots/capture.py takes the screenshots.
What the anonymizer does:
Domains become example.demo / example-cloud.demo.
Private IPs move per /16 and keep the network plan intact. Public IPs move into the documentation and benchmark ranges.
MACs keep their vendor prefix.
Hostnames, site and VLAN names are mapped. The mapping lives outside the repo.
Every secret is emptied, including Wi-Fi keys inside JSON snapshots.
Everything logs in as the user netork.
A leak report runs at the end.
The local copy never reaches the network: only the API and UI run. There is no worker, beat or Redis, and the encryption key is random.
The screenshot script cannot change anything: it aborts every API request that is not a GET.
Homepage: the hero plus six walkthrough rows (device detail, VLANs, Security tab, triage queue, dashboard, service checks) and the audit log in the NIS2 section. All images are WebP, about 630 KB in total.
Content v0.12 → v0.28, in EN and DE
Driver matrix, checked against the code at v0.28.0:
Reboot is only ✓ for OpenWrt and Proxmox; the others reported success without doing anything.
Config push is added where netOrk writes config.
Zyxel is a VMG router, and netgear is split into netgear_smart and netgear_plus.
Additions to existing sections: SSH keys per user, session windows, multi-role devices, LAN scan, service checks, site reachability, firewall profile diff, 16 Ansible roles, 18 widgets.
Roadmap: a new "Next release" group lists what is on main but unreleased. CVE tracking is gone from "Planned", since it shipped.
NIS2 page: Art. 21 (2e) and (2i) are updated. Persona pages, the glossary (Kea, WinRM, LAPI) and docs/ are updated too.
Fixes
Mobile menu: the navigation used to make every page 413 px wider than a phone screen.
Invisible glossary tooltips no longer widen the page.
Long German headings fit at 360 px.
The roadmap intro no longer gets cut off.
Checked with no horizontal overflow at 360, 390 and 768 px on every page.
Before merging
Look at the 8 images in public/screenshots/
Decide whether OPNsense "one-click restore" stays advertised: going by the code, load_replace_candidate is missing from the driver at v0.28.0 (not verified at runtime)
Brings the site from netOrk v0.11 (last update 2026-07-17) to **v0.28.0**, and replaces every hand-built UI mockup with a **real screenshot** of netOrk.
## Real screenshots instead of mockups
- The images come from an **anonymized copy of a production database**, served by netOrk v0.28.0 running locally. `scripts/demo/up.sh` restores the copy, `scripts/demo/anonymize.py` anonymizes it, and `scripts/screenshots/capture.py` takes the screenshots.
- **What the anonymizer does:**
- Domains become `example.demo` / `example-cloud.demo`.
- Private IPs move per /16 and keep the network plan intact. Public IPs move into the documentation and benchmark ranges.
- MACs keep their vendor prefix.
- Hostnames, site and VLAN names are mapped. The mapping lives outside the repo.
- Every secret is emptied, including Wi-Fi keys inside JSON snapshots.
- Everything logs in as the user `netork`.
- A leak report runs at the end.
- **The local copy never reaches the network:** only the API and UI run. There is no worker, beat or Redis, and the encryption key is random.
- **The screenshot script cannot change anything:** it aborts every API request that is not a GET.
- **Homepage:** the hero plus six walkthrough rows (device detail, VLANs, Security tab, triage queue, dashboard, service checks) and the audit log in the NIS2 section. All images are WebP, about 630 KB in total.
## Content v0.12 → v0.28, in EN and DE
- **Driver matrix, checked against the code at v0.28.0:**
- Reboot is only ✓ for OpenWrt and Proxmox; the others reported success without doing anything.
- Config push is added where netOrk writes config.
- Zyxel is a VMG router, and netgear is split into netgear_smart and netgear_plus.
- New drivers: HPE OfficeConnect, QNAP, Yealink.
- Notes explain the columns.
- **Features:**
- New sections: Security Assessment, Vulnerability Management, DHCP, Managed Services, Notifications (Signal).
- Additions to existing sections: SSH keys per user, session windows, multi-role devices, LAN scan, service checks, site reachability, firewall profile diff, 16 Ansible roles, 18 widgets.
- **Roadmap:** a new "Next release" group lists what is on main but unreleased. CVE tracking is gone from "Planned", since it shipped.
- **NIS2 page:** Art. 21 (2e) and (2i) are updated. Persona pages, the glossary (Kea, WinRM, LAPI) and `docs/` are updated too.
## Fixes
- Mobile menu: the navigation used to make every page 413 px wider than a phone screen.
- Invisible glossary tooltips no longer widen the page.
- Long German headings fit at 360 px.
- The roadmap intro no longer gets cut off.
- Checked with no horizontal overflow at 360, 390 and 768 px on every page.
## Before merging
- [ ] Look at the 8 images in `public/screenshots/`
- [ ] Decide whether OPNsense "one-click restore" stays advertised: going by the code, `load_replace_candidate` is missing from the driver at v0.28.0 (not verified at runtime)
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Audited the drivers that actually ship in v0.28.0 (vendor-drivers.txt at the
tag, each driver package at its pin) instead of carrying the old table on.
- Reboot: netOrk's reboot really restarts only OpenWrt and Proxmox. For every
other driver the request reported success while nothing happened, so the
column now says so. Rebooting through an update run is mentioned in a note.
- Config push: OPNsense, ProCurve, TP-Link JetStream, Netgear Smart and Proxmox
do get configuration written by netOrk; the column was missing them.
- Zyxel is a VMG residential gateway, not a switch: no LLDP, VLANs or health,
but SSIDs. Fritz!Box is read-only and has no health metrics. Proxmox has no
Docker view.
- netgear is two drivers, netgear_smart and netgear_plus. New: hpe_officeconnect,
qnap_qts, yealink.
- The built-in NAPALM drivers are installed but untested with netOrk and get
none of its driver-specific features; the page no longer says "supported".
- Notes explain the Health, LLDP, Config push and Reboot columns.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Seventeen releases since the site was last brought up to date, checked
against the changelog and the code at the v0.28.0 tag.
- New feature sections: Security Assessment (TLS/SSH grades, CVE and
container-image matching, exposure, deep scans; Knowledge Base licence),
Vulnerability Management (triage queue, decisions with reasons, deferrals
that come back, verified fixes), DHCP, Managed Services, Notifications
(Signal).
- Existing sections gain per-user SSH keys and session windows, multi-role
devices, one device per address per site, LAN Scan, MAC-table topology,
service checks, site reachability, per-site firewall profiles with diff,
honoured drift auto-correct, 16 Ansible roles, 18 dashboard widgets.
- Corrections: Docker status is Linux/OMV/QNAP, not Proxmox.
- Roadmap: CVE tracking shipped and is gone from "Planned"; a "Next release"
group lists what is on main but unreleased (CrowdSec across sites, Windows
driver, single-use console tickets, reboots refused instead of faked).
- NIS2: Art. 21 (2e) now describes the vulnerability handling that exists,
(2i) adds attributable terminal sessions; CVE tracking left "coming".
- Persona pages: two new items each, counts updated. Glossary: Kea, WinRM,
LAPI.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The site has shown hand-built JSX mockups of the UI so far. This adds the
tooling to replace them with screenshots of the real application:
- scripts/demo/up.sh restores a pg_dump of a production database into a
local Postgres and starts netOrk (a pinned release, default v0.28.0) with
only the API and the UI: no worker, no beat, no Redis, a random encryption
key. Nothing polls and nothing can reach a device.
- scripts/demo/anonymize.py rewrites every text, JSON and address column of
every table: domains to example.demo, private IPv4 per /16 with the host
part kept, public addresses into the documentation ranges, MACs with the
vendor prefix kept, e-mail addresses and configured names. Secrets are
emptied by column name, one admin "netork" is left. It refuses non-local
databases and ends with a leak report. The real-to-demo name map lives
outside the repo.
- scripts/screenshots/capture.py drives headless Chromium through a
declarative list of pages, logs in to the demo copy by itself, and aborts
every non-GET API request, so taking screenshots cannot change anything.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The homepage showed seven hand-built JSX imitations of the netOrk UI. They
are gone; every image is now a screenshot of netOrk v0.28.0 itself, taken
from an anonymized copy of a production database (scripts/demo) with
scripts/screenshots/capture.py and published as WebP (~630 KB for all eight).
- Hero: the device inventory. Walkthrough: device detail, VLANs, the Security
tab, the vulnerability triage queue (replacing the config-diff row), the
dashboard and service checks (new row 6). NIS2: the audit log, filtered to
what people did.
- Copy follows the images: row 3 describes the security assessment, row 4 the
triage queue; row 2 no longer claims corrections are always automatic;
18 widgets. Alt texts in both languages.
- Also fixed on the homepage: the NIS2 teaser for Art. 21 (2e) and the
container list of a deployment (three worker pools, plus Flower, registry,
APT cache and the Signal gateway).
- Demo tooling hardened on the real dump: secrets inside JSON (Wi-Fi keys),
reverse DNS zones, glued identifiers, tens of thousands of CrowdSec
addresses, a schema newer than the release (anonymize, then downgrade),
MFA-enforcing roles, and click steps for view filters.
- DESIGN.md: real screenshots only. PAGES.md: the six rows as they are.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- The navigation had no mobile layout: every page was 413px wider than a
phone. Below lg the links now sit behind a menu button, grouped like the
desktop dropdowns; the menu closes on navigation.
- Glossary tooltips were invisible but still laid out, so a term near the
right edge widened the page. Hidden tooltips no longer take up space;
they show on hover and on keyboard focus as before.
- Long German words in page headings ("produktionstauglich",
"Konfigurationstiefe") overflowed at 360px; headings start a size smaller
on phones.
- The roadmap intro dropped everything after its second "NIS2" ("…the
baseline requirements of"); it is split at the first one only now.
Checked at 360, 390 and 768px on every page: no horizontal overflow.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Brings the site from netOrk v0.11 (last update 2026-07-17) to v0.28.0, and replaces every hand-built UI mockup with a real screenshot of netOrk.
Real screenshots instead of mockups
scripts/demo/up.shrestores the copy,scripts/demo/anonymize.pyanonymizes it, andscripts/screenshots/capture.pytakes the screenshots.example.demo/example-cloud.demo.netork.Content v0.12 → v0.28, in EN and DE
docs/are updated too.Fixes
Before merging
public/screenshots/load_replace_candidateis missing from the driver at v0.28.0 (not verified at runtime)🤖 Generated with Claude Code
- The navigation had no mobile layout: every page was 413px wider than a phone. Below lg the links now sit behind a menu button, grouped like the desktop dropdowns; the menu closes on navigation. - Glossary tooltips were invisible but still laid out, so a term near the right edge widened the page. Hidden tooltips no longer take up space; they show on hover and on keyboard focus as before. - Long German words in page headings ("produktionstauglich", "Konfigurationstiefe") overflowed at 360px; headings start a size smaller on phones. - The roadmap intro dropped everything after its second "NIS2" ("…the baseline requirements of"); it is split at the first one only now. Checked at 360, 390 and 768px on every page: no horizontal overflow. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>