Every abbreviation and technical term used in the site's copy (RBAC, NAPALM, config drift, ...) now links to a new /glossary page and shows a short definition on hover, wherever it appears in body text. Product and vendor brand names are deliberately excluded — the glossary stays a dictionary of vocabulary, not a company directory. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
612 lines
32 KiB
TypeScript
612 lines
32 KiB
TypeScript
export type Lang = 'en' | 'de'
|
|
|
|
const en = {
|
|
nav: {
|
|
features: 'Features',
|
|
drivers: 'Drivers',
|
|
docs: 'Docs',
|
|
plugins: 'Plugins',
|
|
roadmap: 'Roadmap',
|
|
getStarted: 'Get started',
|
|
docsItems: {
|
|
gettingStarted: 'Getting Started',
|
|
architecture: 'Architecture',
|
|
nis2: 'NIS2 Compliance',
|
|
glossary: 'Glossary',
|
|
},
|
|
},
|
|
footer: {
|
|
tagline: 'Self-hosted network orchestration',
|
|
links: 'Links',
|
|
resources: 'Resources',
|
|
legal: 'Legal',
|
|
gettingStarted: 'Getting Started',
|
|
architecture: 'Architecture',
|
|
changelog: 'Changelog',
|
|
nis2: 'NIS2',
|
|
roadmap: 'Roadmap',
|
|
glossary: 'Glossary',
|
|
mit: 'MIT License',
|
|
privacy: 'Privacy (none collected)',
|
|
},
|
|
home: {
|
|
hero: {
|
|
line1: 'Network orchestration',
|
|
line2: 'for heterogeneous infrastructure.',
|
|
sub: 'netOrk discovers, monitors, and manages your routers, switches, access points, firewalls, and servers from a single UI — regardless of vendor. No SaaS dependency. Runs on your infrastructure.',
|
|
cta1: 'Get in touch →',
|
|
cta2: 'View features',
|
|
},
|
|
problem: 'Managing a mixed network means juggling a different admin UI for every vendor — one for OPNsense, one for HP ProCurve, one for OpenWRT, one for Proxmox. Config changes happen directly on devices with no audit trail. You find out something drifted when it breaks.',
|
|
cap1: {
|
|
title: 'Discover everything on your network',
|
|
body: 'ICMP sweep, SNMP scan, and HTTP probing find devices before you add them. Fingerprinting identifies vendor and platform automatically. Adopt results into your inventory with a single click.',
|
|
},
|
|
cap2: {
|
|
title: 'Poll device state continuously',
|
|
body: 'Every device is polled on a configurable interval via NAPALM. Interface status, ARP tables, DHCP leases, VLAN membership, Docker containers, and SNMP health metrics — all in one place.',
|
|
},
|
|
cap3: {
|
|
title: 'Detect drift. Fix it.',
|
|
body: 'Define desired state in netOrk. On every poll, device config is compared against it. Drifted devices get a warning; a one-click fix stream applies the correction and shows you live SSH output.',
|
|
},
|
|
driversHeading: 'Works with your hardware',
|
|
driversSub: 'netOrk ships with custom NAPALM drivers for 11 device types, plus all built-in NAPALM drivers. New drivers follow a documented registration pattern.',
|
|
driversLink: 'Full driver reference →',
|
|
screenshot1: {
|
|
heading: 'Device detail at a glance',
|
|
body: 'Hostname, IP, vendor, OS version, last poll time, and active warnings on one card. Tabbed detail view for interfaces, LLDP neighbors, ARP table, VLAN membership, packages, services, and scheduled jobs.',
|
|
},
|
|
screenshot2: {
|
|
heading: 'Intent-based VLAN and SSID management',
|
|
body: "Define VLAN names and SSID settings once. netOrk compares them against every polled device and pushes corrections automatically via UCI (OpenWRT) or the device's native API.",
|
|
},
|
|
screenshot3: {
|
|
heading: 'Security visibility per device',
|
|
body: 'Wazuh agent status, CVE counts by severity, and recent alerts — all linked to the device record. One-click agent install if the agent is missing. Graylog syslog forwarding status with auto-fix.',
|
|
},
|
|
screenshot4: {
|
|
heading: 'Configuration backup and versioning',
|
|
body: 'Every poll captures a config snapshot into a local Git repository. The Config tab shows the full snapshot history, a side-by-side diff between any two points in time, and — for OPNsense — a Restore button. Unauthorized changes show up as a device warning.',
|
|
},
|
|
nis2Label: 'NIS2 · Art. 21',
|
|
nis2Heading: 'Evidence, not paperwork.',
|
|
nis2Body: "NIS2 Art. 21 mandates asset inventory, patch management, access control, and audit trails as baseline technical measures. netOrk doesn't bolt on a compliance layer — these are its day-to-day outputs.",
|
|
nis2Link: 'Full Art. 21 mapping →',
|
|
nis2Items: [
|
|
{ art: 'Art. 21 (2e)', label: 'Patch & vulnerability management', detail: 'Per-device update status, Wazuh CVE counts by severity' },
|
|
{ art: 'Art. 21 (2h)', label: 'Asset management & access control', detail: 'Full device inventory, RBAC with four roles, complete audit log' },
|
|
{ art: 'Art. 21 (2a)', label: 'Risk analysis baseline', detail: 'Config drift detection, SNMP health metrics, security agent coverage' },
|
|
{ art: 'Art. 21 (2b)', label: 'Incident detection', detail: 'Wazuh alert history, CrowdSec decisions, Graylog syslog per device' },
|
|
],
|
|
pluginsHeading: 'Built to extend',
|
|
pluginsBody: 'Integrations (Wazuh, Graylog, CrowdSec, apt-cacher-ng) are plugins that register into the plugin system — they can be enabled or disabled per deployment without code changes. Adding a new integration follows a documented pattern with a hook bus, typed metadata, and a plugin registry.',
|
|
pluginsLink: 'Plugin system docs →',
|
|
deployHeading: 'Self-hosted. One command.',
|
|
deployBody: 'netOrk runs in Docker Compose. Five containers: API, two worker pools, a Beat scheduler, and an nginx UI server. No external dependencies beyond Redis and PostgreSQL.',
|
|
ctaHeading: 'Interested?',
|
|
ctaBody: 'Deployment options and hosted plans are coming. Get in touch for early access.',
|
|
ctaButton: 'Get in touch →',
|
|
},
|
|
features: {
|
|
heading: 'Features',
|
|
sub: 'Complete reference for all netOrk capabilities.',
|
|
sections: [
|
|
{
|
|
title: 'Device Management',
|
|
items: [
|
|
'CRUD for devices with credential profiles and SSH key management',
|
|
'Interactive Web-SSH console — full terminal session to any device straight from the browser, no separate SSH client needed',
|
|
'Per-device poll intervals (minutes) or manual-only',
|
|
'Status tracking: planned / staged / active / decommissioning / offline / disabled',
|
|
'Vendor / model / OS auto-populated from NAPALM get_facts()',
|
|
'Site assignment with FK to structured Site records',
|
|
'AP Profile assignment for grouped OpenWRT config',
|
|
],
|
|
},
|
|
{
|
|
title: 'Discovery',
|
|
items: [
|
|
'ICMP ping sweep, SNMP scan, HTTP/HTTPS probing',
|
|
'Device fingerprinting: vendor + platform confidence scoring',
|
|
'FQDN resolution (reverse DNS)',
|
|
'Manual adoption from scan results — no auto-create to avoid inventory noise',
|
|
],
|
|
},
|
|
{
|
|
title: 'Supported Drivers',
|
|
items: [
|
|
'fritzbox — AVM Fritz!Box routers',
|
|
'procurve — HP ProCurve / Aruba switches',
|
|
'linux — Generic Linux servers',
|
|
'netgear — Netgear switches',
|
|
'openmediavault — OpenMediaVault NAS',
|
|
'openwrt — OpenWRT access points',
|
|
'opnsense — OPNsense firewalls',
|
|
'proxmox — Proxmox VE hypervisors',
|
|
'sonos — Sonos speakers',
|
|
'tplink_jetstream — TP-Link Jetstream managed switches',
|
|
'zyxel — Zyxel switches',
|
|
'Plus all built-in NAPALM drivers: Cisco IOS / IOS-XE / NX-OS, Arista EOS, Juniper JunOS',
|
|
],
|
|
},
|
|
{
|
|
title: 'Networking & Inventory',
|
|
items: [
|
|
'Interface browser with IPv4/IPv6 addresses, MAC, speed, MTU',
|
|
'LLDP neighbor discovery and topology graph',
|
|
'ARP table and DHCP lease browser per device',
|
|
'Subnet browser with interface-to-subnet assignments',
|
|
'VLAN list grouped by site; per-VLAN device membership view',
|
|
'SSID management with push to OpenWRT APs via UCI',
|
|
],
|
|
},
|
|
{
|
|
title: 'Configuration Management & Drift',
|
|
items: [
|
|
'Config drift detection: desired state (DB) vs device state (poll snapshot)',
|
|
'One-click drift fix stream with live SSH output in the browser',
|
|
'UCI-based config push for OpenWRT (VLAN names, SSID settings, radio config)',
|
|
'AP profile system: country code, HT/VHT mode, 802.11r, NTP, syslog, SSH port',
|
|
'Configuration backup & versioning: every poll snapshots config into a local Git repo, with full history and a side-by-side diff viewer',
|
|
'One-click config restore for OPNsense from any prior snapshot',
|
|
'Unauthorized configuration changes are surfaced as a device warning',
|
|
],
|
|
},
|
|
{
|
|
title: 'Scheduled Operations',
|
|
items: [
|
|
'Scheduled reboots for OpenWRT APs with per-site concurrency lock',
|
|
'Failback cron script written to device for netOrk-unreachable scenarios',
|
|
'Scheduled config drift fixes with time-window enforcement',
|
|
'Package update scheduling and one-click apply',
|
|
],
|
|
},
|
|
{
|
|
title: 'Monitoring & Health',
|
|
items: [
|
|
'SNMP health metrics (CPU, memory, interface counters) via get_health_metrics()',
|
|
'Per-device warning system with severity levels (error / warning / info)',
|
|
'One-click Ack on any warning — clears it immediately and logs the action; config-change warnings accept the current state as the new baseline',
|
|
'Docker container and image status (Proxmox/Linux)',
|
|
'Service status and start/stop/restart (systemd)',
|
|
'VM/container list with OS device cross-linking (Proxmox)',
|
|
],
|
|
},
|
|
{
|
|
title: 'Security Integrations',
|
|
items: [
|
|
'Wazuh — agent enrollment tracking, vulnerability counts by severity, recent alert history, CIS benchmark scores, one-click agent install fix stream',
|
|
'Graylog — rsyslog forwarding status per device, one-click fix to write rule',
|
|
'CrowdSec — org-level decisions, remediation metrics, top attack scenarios',
|
|
],
|
|
},
|
|
{
|
|
title: 'DNS Management',
|
|
items: [
|
|
'DNS zone management with authoritative device assignment',
|
|
'Forward record provisioning (A records from device interfaces)',
|
|
'PTR record provisioning to reverse zones',
|
|
'Pending job queue for zone changes when device is unreachable',
|
|
],
|
|
},
|
|
{
|
|
title: 'Access Control (RBAC)',
|
|
items: [
|
|
'JWT authentication with remember-me (localStorage) or session-only (sessionStorage)',
|
|
'Two-factor authentication (MFA/TOTP): authenticator app at login, backup codes, session invalidation on TOTP changes, enforceable per role',
|
|
'RBAC with four built-in roles: viewer / operator / engineer / administrator',
|
|
'Permissions enforced end-to-end — nav, routes, and write actions are hidden in the UI to match the backend permission checks, not just disabled',
|
|
'Custom roles with any permission combination',
|
|
'Full audit log of all orchestration actions',
|
|
],
|
|
},
|
|
{
|
|
title: 'NetBox Sync',
|
|
items: [
|
|
'Pushes vendor, model, OS version, status to NetBox dcim.devices',
|
|
'Syncs interfaces, IP addresses, prefixes, VLANs',
|
|
'VM interfaces and disks for Proxmox hosts',
|
|
],
|
|
},
|
|
{
|
|
title: 'Compliance & Audit (NIS2)',
|
|
items: [
|
|
'Full audit log of all orchestration actions — who changed what, when (Art. 21 (2h))',
|
|
'Two-factor authentication (MFA/TOTP), enforceable per role — administrative access control (Art. 21 (2i))',
|
|
'RBAC with four built-in roles and custom permission sets — access control evidence',
|
|
'Per-device patch status and installed package list — patch management baseline (Art. 21 (2e))',
|
|
'Wazuh CVE counts by severity (critical / high / medium) linked to each device record',
|
|
'Git-backed configuration snapshot history with diff viewer and OPNsense restore — config-level backup & recovery evidence (Art. 21 (2c))',
|
|
'Config drift tracking: desired state vs. polled state — detect unauthorized changes',
|
|
'Security agent coverage report: which devices have Wazuh, Graylog, CrowdSec active',
|
|
'SNMP health metrics as continuous monitoring baseline (Art. 21 (2a))',
|
|
'Incident-relevant data per device: Wazuh alerts, CrowdSec decisions, syslog forwarding status (Art. 21 (2b))',
|
|
],
|
|
},
|
|
{
|
|
title: 'Developer Experience',
|
|
items: [
|
|
'OpenAPI / Swagger at /docs',
|
|
'Plugin system: new integrations follow a documented pattern',
|
|
'Celery task queue with dedicated queues per workload type',
|
|
'Docker Compose deployment (single command)',
|
|
'Alembic migrations run automatically on deploy',
|
|
],
|
|
},
|
|
],
|
|
},
|
|
drivers: {
|
|
heading: 'Supported Devices',
|
|
sub: 'netOrk ships with custom NAPALM drivers for 11 device types and supports all built-in NAPALM drivers. Capability availability varies by driver.',
|
|
customHeading: 'Custom Drivers',
|
|
napalmHeading: 'Built-in NAPALM Drivers',
|
|
napalmSub: 'All standard NAPALM drivers are supported. Capabilities depend on the upstream NAPALM implementation.',
|
|
},
|
|
gettingStarted: {
|
|
label: 'coming soon',
|
|
heading: 'netOrk is getting ready\nfor production.',
|
|
sub: "We're working on deployment options, hosted plans, and professional support. If you want early access or have questions, get in touch.",
|
|
cta: 'Get in touch',
|
|
bottomText: 'In the meantime, explore what netOrk can do.',
|
|
bottomFeatures: 'Features →',
|
|
bottomDrivers: 'Supported devices →',
|
|
},
|
|
roadmap: {
|
|
heading: 'Roadmap',
|
|
sub: "What's being built and what's being evaluated. Items tagged NIS2 directly address NIS2 Art. 21 technical baseline requirements.",
|
|
groupPlanned: 'Planned',
|
|
groupConsidering: 'Under consideration',
|
|
},
|
|
plugins: {
|
|
heading: 'Plugin System',
|
|
sub: 'Integrations are plugins, not core code. Wazuh, Graylog, CrowdSec, and apt-cacher-ng all register through the same pattern — metadata, hooks, tasks, router.',
|
|
whatHeading: 'What is a plugin?',
|
|
builtinHeading: 'Built-in plugins',
|
|
writingHeading: 'Writing a plugin',
|
|
hookBusHeading: 'Hook bus',
|
|
registryHeading: 'Plugin registry & enable/disable',
|
|
cta: {
|
|
heading: 'Add your own integration.',
|
|
body: 'One documented pattern — metadata, hooks, tasks, router. No core code changes required.',
|
|
button: 'Get started →',
|
|
},
|
|
},
|
|
nis2: {
|
|
heading: 'NIS2 & netOrk',
|
|
sub: 'NIS2 Art. 21 defines ten categories of technical and organizational measures. Some of them are directly addressed by what netOrk does every day. This page maps each requirement to netOrk\'s current capabilities — honestly, including what\'s partial and what\'s not applicable.',
|
|
mappingHeading: 'Art. 21 — requirement by requirement',
|
|
evidenceHeading: 'What netOrk produces as evidence',
|
|
evidenceSub: "NIS2 audits require demonstrable outputs, not just claimed controls. Here's what netOrk generates automatically.",
|
|
comingHeading: "What's coming",
|
|
coverageLabels: {
|
|
covered: '✓ Covered',
|
|
partial: '⚠ Partial',
|
|
roadmap: '→ Roadmap',
|
|
na: '— N/A',
|
|
},
|
|
legendLabels: {
|
|
covered: 'netOrk covers this today',
|
|
partial: 'partially covered — see description',
|
|
roadmap: 'planned — see roadmap',
|
|
na: 'outside scope of a network management tool',
|
|
},
|
|
cta: {
|
|
heading: 'Start with the foundation.',
|
|
body: 'Asset inventory, continuous polling, drift detection, RBAC, and a full audit log — deployed in one command.',
|
|
button: 'Get started →',
|
|
},
|
|
},
|
|
glossary: {
|
|
heading: 'Glossary',
|
|
sub: 'Every abbreviation and technical term used on this site, in one place. Hover any underlined term anywhere on the site for a quick definition.',
|
|
},
|
|
}
|
|
|
|
type Translations = typeof en
|
|
|
|
const de: Translations = {
|
|
nav: {
|
|
features: 'Funktionen',
|
|
drivers: 'Treiber',
|
|
docs: 'Docs',
|
|
plugins: 'Plugins',
|
|
roadmap: 'Roadmap',
|
|
getStarted: 'Loslegen',
|
|
docsItems: {
|
|
gettingStarted: 'Erste Schritte',
|
|
architecture: 'Architektur',
|
|
nis2: 'NIS2-Compliance',
|
|
glossary: 'Glossar',
|
|
},
|
|
},
|
|
footer: {
|
|
tagline: 'Self-hosted Netzwerk-Orchestrierung',
|
|
links: 'Links',
|
|
resources: 'Ressourcen',
|
|
legal: 'Rechtliches',
|
|
gettingStarted: 'Erste Schritte',
|
|
architecture: 'Architektur',
|
|
changelog: 'Changelog',
|
|
nis2: 'NIS2',
|
|
roadmap: 'Roadmap',
|
|
glossary: 'Glossar',
|
|
mit: 'MIT-Lizenz',
|
|
privacy: 'Datenschutz (keine Daten erhoben)',
|
|
},
|
|
home: {
|
|
hero: {
|
|
line1: 'Netzwerk-Orchestrierung',
|
|
line2: 'für heterogene Infrastruktur.',
|
|
sub: 'netOrk entdeckt, überwacht und verwaltet Router, Switches, Access Points, Firewalls und Server aus einer einzigen Oberfläche — herstellerunabhängig. Kein SaaS-Dienst. Läuft auf deiner Infrastruktur.',
|
|
cta1: 'Kontakt aufnehmen →',
|
|
cta2: 'Funktionen ansehen',
|
|
},
|
|
problem: 'Ein gemischtes Netzwerk zu verwalten bedeutet, für jeden Hersteller eine eigene Admin-Oberfläche zu jonglieren — eine für OPNsense, eine für HP ProCurve, eine für OpenWRT, eine für Proxmox. Konfigurationsänderungen erfolgen direkt auf den Geräten ohne Audit-Trail. Einen Drift bemerkt man erst, wenn es zu einem Ausfall kommt.',
|
|
cap1: {
|
|
title: 'Alles im Netzwerk entdecken',
|
|
body: 'ICMP-Sweep, SNMP-Scan und HTTP-Probing finden Geräte, bevor sie manuell erfasst werden. Fingerprinting identifiziert Hersteller und Plattform automatisch. Ergebnisse mit einem Klick ins Inventar übernehmen.',
|
|
},
|
|
cap2: {
|
|
title: 'Gerätezustand kontinuierlich abfragen',
|
|
body: 'Jedes Gerät wird in konfigurierbaren Intervallen über NAPALM abgefragt. Schnittstellenstatus, ARP-Tabellen, DHCP-Leases, VLAN-Zugehörigkeit, Docker-Container und SNMP-Gesundheitsmetriken — alles an einem Ort.',
|
|
},
|
|
cap3: {
|
|
title: 'Drift erkennen. Beheben.',
|
|
body: 'Sollzustand in netOrk definieren. Bei jeder Abfrage wird die Gerätekonfiguration damit verglichen. Abweichende Geräte erhalten eine Warnung; ein Ein-Klick-Fix-Stream wendet die Korrektur an und zeigt den SSH-Output live im Browser.',
|
|
},
|
|
driversHeading: 'Funktioniert mit deiner Hardware',
|
|
driversSub: 'netOrk liefert eigene NAPALM-Treiber für 11 Gerätetypen, plus alle integrierten NAPALM-Treiber. Neue Treiber folgen einem dokumentierten Registrierungsmuster.',
|
|
driversLink: 'Vollständige Treiberreferenz →',
|
|
screenshot1: {
|
|
heading: 'Gerätedetails auf einen Blick',
|
|
body: 'Hostname, IP, Hersteller, OS-Version, letzter Poll-Zeitpunkt und aktive Warnungen auf einer Karte. Tabellarische Detailansicht für Schnittstellen, LLDP-Nachbarn, ARP-Tabelle, VLAN-Zugehörigkeit, Pakete, Services und geplante Jobs.',
|
|
},
|
|
screenshot2: {
|
|
heading: 'Intent-basiertes VLAN- und SSID-Management',
|
|
body: 'VLAN-Namen und SSID-Einstellungen einmal definieren. netOrk vergleicht sie bei jeder Abfrage mit jedem Gerät und korrigiert Abweichungen automatisch via UCI (OpenWRT) oder der nativen Geräte-API.',
|
|
},
|
|
screenshot3: {
|
|
heading: 'Sicherheitssichtbarkeit pro Gerät',
|
|
body: 'Wazuh-Agent-Status, CVE-Anzahl nach Schweregrad und aktuelle Alerts — alle mit dem Gerätedatensatz verknüpft. Ein-Klick-Agent-Installation falls der Agent fehlt. Graylog-Syslog-Weiterleitungsstatus mit Auto-Fix.',
|
|
},
|
|
screenshot4: {
|
|
heading: 'Konfigurationsbackup und -versionierung',
|
|
body: 'Bei jedem Poll wird ein Konfigurationssnapshot in einem lokalen Git-Repository gespeichert. Der Config-Tab zeigt die vollständige Snapshot-Historie, einen Side-by-Side-Diff zwischen beliebigen Zeitpunkten und — für OPNsense — einen Restore-Button. Nicht autorisierte Änderungen erscheinen als Gerätewarnung.',
|
|
},
|
|
nis2Label: 'NIS2 · Art. 21',
|
|
nis2Heading: 'Nachweise, keine Papierwüste.',
|
|
nis2Body: 'NIS2 Art. 21 schreibt Geräteinventar, Patch-Management, Zugangskontrolle und Audit-Trails als technische Basismaßnahmen vor. netOrk fügt keine Compliance-Schicht auf — das sind seine normalen Tagesausgaben.',
|
|
nis2Link: 'Vollständiges Art. 21-Mapping →',
|
|
nis2Items: [
|
|
{ art: 'Art. 21 (2e)', label: 'Patch- & Schwachstellen-Management', detail: 'Update-Status pro Gerät, Wazuh-CVE-Anzahl nach Schweregrad' },
|
|
{ art: 'Art. 21 (2h)', label: 'Asset-Management & Zugangskontrolle', detail: 'Vollständiges Geräteinventar, RBAC mit vier Rollen, vollständiges Audit-Log' },
|
|
{ art: 'Art. 21 (2a)', label: 'Risikoanalyse-Baseline', detail: 'Konfigurationsdrift-Erkennung, SNMP-Gesundheitsmetriken, Security-Agent-Abdeckung' },
|
|
{ art: 'Art. 21 (2b)', label: 'Incident-Erkennung', detail: 'Wazuh-Alert-Historie, CrowdSec-Entscheidungen, Graylog-Syslog pro Gerät' },
|
|
],
|
|
pluginsHeading: 'Erweiterbar konzipiert',
|
|
pluginsBody: 'Integrationen (Wazuh, Graylog, CrowdSec, apt-cacher-ng) sind Plugins, die im Plugin-System registriert werden — sie lassen sich pro Deployment ohne Code-Änderungen aktivieren oder deaktivieren. Eine neue Integration folgt einem dokumentierten Muster mit Hook-Bus, typisiertem Metadatum und Plugin-Registry.',
|
|
pluginsLink: 'Plugin-System-Dokumentation →',
|
|
deployHeading: 'Self-hosted. Ein Befehl.',
|
|
deployBody: 'netOrk läuft in Docker Compose. Fünf Container: API, zwei Worker-Pools, ein Beat-Scheduler und ein nginx-UI-Server. Keine externen Abhängigkeiten außer Redis und PostgreSQL.',
|
|
ctaHeading: 'Interesse?',
|
|
ctaBody: 'Deployment-Optionen und gehostete Pläne folgen. Jetzt Kontakt aufnehmen für Early Access.',
|
|
ctaButton: 'Kontakt aufnehmen →',
|
|
},
|
|
features: {
|
|
heading: 'Funktionen',
|
|
sub: 'Vollständige Referenz aller netOrk-Funktionen.',
|
|
sections: [
|
|
{
|
|
title: 'Geräteverwaltung',
|
|
items: [
|
|
'CRUD für Geräte mit Credential-Profilen und SSH-Schlüsselverwaltung',
|
|
'Interaktive Web-SSH-Konsole — vollständige Terminal-Sitzung zu jedem Gerät direkt im Browser, kein separater SSH-Client nötig',
|
|
'Konfigurierbare Poll-Intervalle (Minuten) oder nur manuell',
|
|
'Statusverfolgung: geplant / bereitgestellt / aktiv / außer Betrieb / offline / deaktiviert',
|
|
'Hersteller / Modell / OS automatisch befüllt über NAPALM get_facts()',
|
|
'Standortzuweisung über FK zu strukturierten Standortdatensätzen',
|
|
'AP-Profil-Zuweisung für gruppierte OpenWRT-Konfiguration',
|
|
],
|
|
},
|
|
{
|
|
title: 'Discovery',
|
|
items: [
|
|
'ICMP-Ping-Sweep, SNMP-Scan, HTTP/HTTPS-Probing',
|
|
'Geräte-Fingerprinting: Hersteller + Plattform mit Confidence-Score',
|
|
'FQDN-Auflösung (Reverse DNS)',
|
|
'Manuelle Übernahme aus Scan-Ergebnissen — kein Auto-Create, um Inventar-Rauschen zu vermeiden',
|
|
],
|
|
},
|
|
{
|
|
title: 'Unterstützte Treiber',
|
|
items: [
|
|
'fritzbox — AVM Fritz!Box Router',
|
|
'procurve — HP ProCurve / Aruba Switches',
|
|
'linux — Generische Linux-Server',
|
|
'netgear — Netgear Switches',
|
|
'openmediavault — OpenMediaVault NAS',
|
|
'openwrt — OpenWRT Access Points',
|
|
'opnsense — OPNsense Firewalls',
|
|
'proxmox — Proxmox VE Hypervisoren',
|
|
'sonos — Sonos Lautsprecher',
|
|
'tplink_jetstream — TP-Link Jetstream Managed Switches',
|
|
'zyxel — Zyxel Switches',
|
|
'Sowie alle integrierten NAPALM-Treiber: Cisco IOS / IOS-XE / NX-OS, Arista EOS, Juniper JunOS',
|
|
],
|
|
},
|
|
{
|
|
title: 'Netzwerk & Inventar',
|
|
items: [
|
|
'Schnittstellen-Browser mit IPv4/IPv6-Adressen, MAC, Geschwindigkeit, MTU',
|
|
'LLDP-Nachbarn-Erkennung und Topologie-Graph',
|
|
'ARP-Tabelle und DHCP-Lease-Browser pro Gerät',
|
|
'Subnetz-Browser mit Schnittstellen-zu-Subnetz-Zuordnungen',
|
|
'VLAN-Liste gruppiert nach Standort; VLAN-Mitgliedsansicht pro Gerät',
|
|
'SSID-Verwaltung mit Push auf OpenWRT-APs via UCI',
|
|
],
|
|
},
|
|
{
|
|
title: 'Konfigurationsmanagement & Drift',
|
|
items: [
|
|
'Konfigurationsdrift-Erkennung: Sollzustand (DB) vs. Gerätezustand (Poll-Snapshot)',
|
|
'Ein-Klick-Drift-Fix-Stream mit Live-SSH-Output im Browser',
|
|
'UCI-basierter Config-Push für OpenWRT (VLAN-Namen, SSID-Einstellungen, Radio-Konfiguration)',
|
|
'AP-Profil-System: Ländercode, HT/VHT-Modus, 802.11r, NTP, Syslog, SSH-Port',
|
|
'Konfigurationsbackup & -versionierung: bei jedem Poll wird ein Snapshot in ein lokales Git-Repository geschrieben — vollständige Historie und Side-by-Side-Diff-Viewer',
|
|
'Ein-Klick-Konfigurations-Restore für OPNsense aus jedem früheren Snapshot',
|
|
'Nicht autorisierte Konfigurationsänderungen werden als Gerätewarnung angezeigt',
|
|
],
|
|
},
|
|
{
|
|
title: 'Geplante Operationen',
|
|
items: [
|
|
'Geplante Neustarts für OpenWRT-APs mit standortbezogener Concurrency-Sperre',
|
|
'Failback-Cron-Skript auf Gerät geschrieben für netOrk-nicht-erreichbar-Szenarien',
|
|
'Geplante Konfigurationsdrift-Korrekturen mit Zeitfenster-Durchsetzung',
|
|
'Paket-Update-Planung und Ein-Klick-Anwendung',
|
|
],
|
|
},
|
|
{
|
|
title: 'Monitoring & Health',
|
|
items: [
|
|
'SNMP-Gesundheitsmetriken (CPU, Speicher, Schnittstellenzähler) via get_health_metrics()',
|
|
'Gerätespezifisches Warnsystem mit Schweregraden (Fehler / Warnung / Info)',
|
|
'Ein-Klick-Ack für jede Warnung — löscht sie sofort und protokolliert die Aktion; bei Config-Change-Warnungen wird der aktuelle Zustand als neue Baseline akzeptiert',
|
|
'Docker-Container- und Image-Status (Proxmox/Linux)',
|
|
'Service-Status und Start/Stop/Neustart (systemd)',
|
|
'VM/Container-Liste mit OS-Geräteverknüpfung (Proxmox)',
|
|
],
|
|
},
|
|
{
|
|
title: 'Sicherheitsintegrationen',
|
|
items: [
|
|
'Wazuh — Agent-Enrollment-Tracking, Schwachstellenanzahl nach Schweregrad, Alert-Historie, CIS-Benchmark-Scores, Ein-Klick-Agent-Install-Fix-Stream',
|
|
'Graylog — rsyslog-Weiterleitungsstatus pro Gerät, Ein-Klick-Fix zum Schreiben der Regel',
|
|
'CrowdSec — Org-Level-Entscheidungen, Remediation-Metriken, Top-Angriffsszenarien',
|
|
],
|
|
},
|
|
{
|
|
title: 'DNS-Verwaltung',
|
|
items: [
|
|
'DNS-Zonenverwaltung mit autoritativer Gerätezuweisung',
|
|
'Forward-Record-Bereitstellung (A-Records aus Geräteschnittstellen)',
|
|
'PTR-Record-Bereitstellung in Reverse-Zonen',
|
|
'Ausstehende Job-Queue für Zonenänderungen bei nicht erreichbarem Gerät',
|
|
],
|
|
},
|
|
{
|
|
title: 'Zugangskontrolle (RBAC)',
|
|
items: [
|
|
'JWT-Authentifizierung mit Remember-Me (localStorage) oder nur Sitzung (sessionStorage)',
|
|
'Zwei-Faktor-Authentifizierung (MFA/TOTP): Authenticator-App beim Login, Backup-Codes, Session-Invalidierung bei TOTP-Änderungen, pro Rolle erzwingbar',
|
|
'RBAC mit vier integrierten Rollen: Betrachter / Operator / Ingenieur / Administrator',
|
|
'Berechtigungen durchgängig erzwungen — Navigation, Routen und Schreibaktionen werden in der UI passend zu den Backend-Prüfungen ausgeblendet, nicht nur deaktiviert',
|
|
'Benutzerdefinierte Rollen mit beliebiger Berechtigungskombination',
|
|
'Vollständiges Audit-Log aller Orchestrierungsaktionen',
|
|
],
|
|
},
|
|
{
|
|
title: 'NetBox-Synchronisation',
|
|
items: [
|
|
'Überträgt Hersteller, Modell, OS-Version, Status an NetBox dcim.devices',
|
|
'Synchronisiert Schnittstellen, IP-Adressen, Präfixe, VLANs',
|
|
'VM-Schnittstellen und Festplatten für Proxmox-Hosts',
|
|
],
|
|
},
|
|
{
|
|
title: 'Compliance & Audit (NIS2)',
|
|
items: [
|
|
'Vollständiges Audit-Log aller Orchestrierungsaktionen — wer hat was wann geändert (Art. 21 (2h))',
|
|
'Zwei-Faktor-Authentifizierung (MFA/TOTP), pro Rolle erzwingbar — Zugangskontrolle für administrative Konten (Art. 21 (2i))',
|
|
'RBAC mit vier integrierten Rollen und benutzerdefinierten Berechtigungssätzen — Zugangskontrollnachweis',
|
|
'Patch-Status und installierte Paketliste pro Gerät — Patch-Management-Baseline (Art. 21 (2e))',
|
|
'Wazuh-CVE-Anzahl nach Schweregrad (kritisch / hoch / mittel) verknüpft mit jedem Gerätedatensatz',
|
|
'Git-basierte Konfigurationssnapshot-Historie mit Diff-Viewer und OPNsense-Restore — Backup- & Recovery-Nachweis auf Konfigurationsebene (Art. 21 (2c))',
|
|
'Konfigurationsdrift-Tracking: Sollzustand vs. abgefragter Zustand — nicht autorisierte Änderungen erkennen',
|
|
'Security-Agent-Abdeckungsbericht: welche Geräte haben Wazuh, Graylog, CrowdSec aktiv',
|
|
'SNMP-Gesundheitsmetriken als kontinuierliche Monitoring-Baseline (Art. 21 (2a))',
|
|
'Incident-relevante Daten pro Gerät: Wazuh-Alerts, CrowdSec-Entscheidungen, Syslog-Weiterleitungsstatus (Art. 21 (2b))',
|
|
],
|
|
},
|
|
{
|
|
title: 'Developer Experience',
|
|
items: [
|
|
'OpenAPI / Swagger unter /docs',
|
|
'Plugin-System: neue Integrationen folgen einem dokumentierten Muster',
|
|
'Celery Task Queue mit dedizierten Queues pro Workload-Typ',
|
|
'Docker Compose Deployment (ein Befehl)',
|
|
'Alembic-Migrationen laufen automatisch beim Deployment',
|
|
],
|
|
},
|
|
],
|
|
},
|
|
drivers: {
|
|
heading: 'Unterstützte Geräte',
|
|
sub: 'netOrk liefert eigene NAPALM-Treiber für 11 Gerätetypen und unterstützt alle integrierten NAPALM-Treiber. Der Funktionsumfang variiert je nach Treiber.',
|
|
customHeading: 'Eigene Treiber',
|
|
napalmHeading: 'Integrierte NAPALM-Treiber',
|
|
napalmSub: 'Alle Standard-NAPALM-Treiber werden unterstützt. Der Funktionsumfang hängt von der jeweiligen NAPALM-Implementierung ab.',
|
|
},
|
|
gettingStarted: {
|
|
label: 'demnächst verfügbar',
|
|
heading: 'netOrk wird\nproduktionstauglich.',
|
|
sub: 'Wir arbeiten an Deployment-Optionen, gehosteten Plänen und professionellem Support. Bei Interesse an Early Access oder Fragen: einfach melden.',
|
|
cta: 'Kontakt aufnehmen',
|
|
bottomText: 'In der Zwischenzeit: entdecke, was netOrk kann.',
|
|
bottomFeatures: 'Funktionen →',
|
|
bottomDrivers: 'Unterstützte Geräte →',
|
|
},
|
|
roadmap: {
|
|
heading: 'Roadmap',
|
|
sub: 'Was gebaut und was evaluiert wird. Mit NIS2 markierte Einträge adressieren direkt die technischen Baseline-Anforderungen von NIS2 Art. 21.',
|
|
groupPlanned: 'Geplant',
|
|
groupConsidering: 'In Erwägung',
|
|
},
|
|
plugins: {
|
|
heading: 'Plugin-System',
|
|
sub: 'Integrationen sind Plugins, kein Core-Code. Wazuh, Graylog, CrowdSec und apt-cacher-ng registrieren sich alle über dasselbe Muster — Metadaten, Hooks, Tasks, Router.',
|
|
whatHeading: 'Was ist ein Plugin?',
|
|
builtinHeading: 'Eingebaute Plugins',
|
|
writingHeading: 'Ein Plugin schreiben',
|
|
hookBusHeading: 'Hook-Bus',
|
|
registryHeading: 'Plugin-Registry & Aktivieren/Deaktivieren',
|
|
cta: {
|
|
heading: 'Eigene Integration hinzufügen.',
|
|
body: 'Ein dokumentiertes Muster — Metadaten, Hooks, Tasks, Router. Keine Änderungen am Core-Code nötig.',
|
|
button: 'Loslegen →',
|
|
},
|
|
},
|
|
nis2: {
|
|
heading: 'NIS2 & netOrk',
|
|
sub: 'NIS2 Art. 21 definiert zehn Kategorien technischer und organisatorischer Maßnahmen. Einige werden durch das, was netOrk täglich tut, direkt adressiert. Diese Seite ordnet jede Anforderung den aktuellen netOrk-Funktionen zu — ehrlich, einschließlich was teilweise abgedeckt ist und was nicht anwendbar ist.',
|
|
mappingHeading: 'Art. 21 — Anforderung für Anforderung',
|
|
evidenceHeading: 'Was netOrk als Nachweis erzeugt',
|
|
evidenceSub: 'NIS2-Audits erfordern nachweisbare Ergebnisse, keine bloßen Behauptungen. Das erzeugt netOrk automatisch.',
|
|
comingHeading: 'Was kommt',
|
|
coverageLabels: {
|
|
covered: '✓ Abgedeckt',
|
|
partial: '⚠ Teilweise',
|
|
roadmap: '→ Roadmap',
|
|
na: '— N/A',
|
|
},
|
|
legendLabels: {
|
|
covered: 'netOrk deckt dies heute ab',
|
|
partial: 'teilweise abgedeckt — siehe Beschreibung',
|
|
roadmap: 'geplant — siehe Roadmap',
|
|
na: 'außerhalb des Scopes eines Netzwerk-Management-Tools',
|
|
},
|
|
cta: {
|
|
heading: 'Starte mit dem Fundament.',
|
|
body: 'Geräteinventar, kontinuierliches Polling, Drift-Erkennung, RBAC und vollständiges Audit-Log — mit einem Befehl deployt.',
|
|
button: 'Loslegen →',
|
|
},
|
|
},
|
|
glossary: {
|
|
heading: 'Glossar',
|
|
sub: 'Alle Abkürzungen und Fachbegriffe dieser Website an einem Ort. Beim Hovern über einen unterstrichenen Begriff wird überall auf der Seite eine Kurzdefinition angezeigt.',
|
|
},
|
|
}
|
|
|
|
export const translations: Record<Lang, Translations> = { en, de }
|