- The navigation had no mobile layout: every page was 413px wider than a
phone. Below lg the links now sit behind a menu button, grouped like the
desktop dropdowns; the menu closes on navigation.
- Glossary tooltips were invisible but still laid out, so a term near the
right edge widened the page. Hidden tooltips no longer take up space;
they show on hover and on keyboard focus as before.
- Long German words in page headings ("produktionstauglich",
"Konfigurationstiefe") overflowed at 360px; headings start a size smaller
on phones.
- The roadmap intro dropped everything after its second "NIS2" ("…the
baseline requirements of"); it is split at the first one only now.
Checked at 360, 390 and 768px on every page: no horizontal overflow.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The homepage showed seven hand-built JSX imitations of the netOrk UI. They
are gone; every image is now a screenshot of netOrk v0.28.0 itself, taken
from an anonymized copy of a production database (scripts/demo) with
scripts/screenshots/capture.py and published as WebP (~630 KB for all eight).
- Hero: the device inventory. Walkthrough: device detail, VLANs, the Security
tab, the vulnerability triage queue (replacing the config-diff row), the
dashboard and service checks (new row 6). NIS2: the audit log, filtered to
what people did.
- Copy follows the images: row 3 describes the security assessment, row 4 the
triage queue; row 2 no longer claims corrections are always automatic;
18 widgets. Alt texts in both languages.
- Also fixed on the homepage: the NIS2 teaser for Art. 21 (2e) and the
container list of a deployment (three worker pools, plus Flower, registry,
APT cache and the Signal gateway).
- Demo tooling hardened on the real dump: secrets inside JSON (Wi-Fi keys),
reverse DNS zones, glued identifiers, tens of thousands of CrowdSec
addresses, a schema newer than the release (anonymize, then downgrade),
MFA-enforcing roles, and click steps for view filters.
- DESIGN.md: real screenshots only. PAGES.md: the six rows as they are.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The site has shown hand-built JSX mockups of the UI so far. This adds the
tooling to replace them with screenshots of the real application:
- scripts/demo/up.sh restores a pg_dump of a production database into a
local Postgres and starts netOrk (a pinned release, default v0.28.0) with
only the API and the UI: no worker, no beat, no Redis, a random encryption
key. Nothing polls and nothing can reach a device.
- scripts/demo/anonymize.py rewrites every text, JSON and address column of
every table: domains to example.demo, private IPv4 per /16 with the host
part kept, public addresses into the documentation ranges, MACs with the
vendor prefix kept, e-mail addresses and configured names. Secrets are
emptied by column name, one admin "netork" is left. It refuses non-local
databases and ends with a leak report. The real-to-demo name map lives
outside the repo.
- scripts/screenshots/capture.py drives headless Chromium through a
declarative list of pages, logs in to the demo copy by itself, and aborts
every non-GET API request, so taking screenshots cannot change anything.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Seventeen releases since the site was last brought up to date, checked
against the changelog and the code at the v0.28.0 tag.
- New feature sections: Security Assessment (TLS/SSH grades, CVE and
container-image matching, exposure, deep scans; Knowledge Base licence),
Vulnerability Management (triage queue, decisions with reasons, deferrals
that come back, verified fixes), DHCP, Managed Services, Notifications
(Signal).
- Existing sections gain per-user SSH keys and session windows, multi-role
devices, one device per address per site, LAN Scan, MAC-table topology,
service checks, site reachability, per-site firewall profiles with diff,
honoured drift auto-correct, 16 Ansible roles, 18 dashboard widgets.
- Corrections: Docker status is Linux/OMV/QNAP, not Proxmox.
- Roadmap: CVE tracking shipped and is gone from "Planned"; a "Next release"
group lists what is on main but unreleased (CrowdSec across sites, Windows
driver, single-use console tickets, reboots refused instead of faked).
- NIS2: Art. 21 (2e) now describes the vulnerability handling that exists,
(2i) adds attributable terminal sessions; CVE tracking left "coming".
- Persona pages: two new items each, counts updated. Glossary: Kea, WinRM,
LAPI.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Audited the drivers that actually ship in v0.28.0 (vendor-drivers.txt at the
tag, each driver package at its pin) instead of carrying the old table on.
- Reboot: netOrk's reboot really restarts only OpenWrt and Proxmox. For every
other driver the request reported success while nothing happened, so the
column now says so. Rebooting through an update run is mentioned in a note.
- Config push: OPNsense, ProCurve, TP-Link JetStream, Netgear Smart and Proxmox
do get configuration written by netOrk; the column was missing them.
- Zyxel is a VMG residential gateway, not a switch: no LLDP, VLANs or health,
but SSIDs. Fritz!Box is read-only and has no health metrics. Proxmox has no
Docker view.
- netgear is two drivers, netgear_smart and netgear_plus. New: hpe_officeconnect,
qnap_qts, yealink.
- The built-in NAPALM drivers are installed but untested with netOrk and get
none of its driver-specific features; the page no longer says "supported".
- Notes explain the Health, LLDP, Config push and Reboot columns.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>