Commit graph

28 commits

Author SHA1 Message Date
3a0de0d7fb Scale biz_state collects with dedicated workers and non-blocking UI poll.
Add PG claim/NE mutex, persist pool, and biz_state_worker replicas; fix double-SSH and row-count bugs; stop 32m collectNow while-loop from freezing page switches.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 17:00:37 +08:00
b9be545a75 Add opt-in per-NE CLI exec_policy for MCP/API exec.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 09:27:40 +08:00
0a4561f385 Remove legacy OClaw alarm WSS and fix key-alert rules table layout.
Key alerts now deliver only via the DSH hub; Modal Body no longer flex-shrinks the rules rows to empty.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-15 23:10:26 +08:00
cd7d1fc6e7 Wait indefinitely for UME topology dumps while the connection stays up.
Default topology read timeout to 0 (no deadline) and extend stale-running reap to 24h so long TopoNodes/TopologicalLinks pulls are not killed mid-stream.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-06 19:04:13 +08:00
4fcec36514 Fix UME topology sync stuck running and unique-key flush failures.
Use savepoint upserts with payload dedupe, finalize jobs on a fresh sibling session, serialize concurrent topology syncs, and reap stale running rows so the scheduler does not keep spawning orphans.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-06 18:42:02 +08:00
fe483f51cc Add UME TopoNodes/TopologicalLinks daily sync into local tables.
Phase-1 docks both topology APIs without writing Fabric; expose a 24h topology_auto_sync task and domain=topology manual sync for later LLDP alignment.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-06 18:17:45 +08:00
6eeaa457b8 Default UME TLS verify off for lab self-signed certs.
Restore ume_verify_tls=false so onsite UME login works without a .env override; production should set NETX_UME_VERIFY_TLS=true or pin a CA.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-06 15:15:48 +08:00
0ebf137776 Clarify lab UME TLS verify after default flipped to true.
Point .env.example at NETX_UME_VERIFY_TLS=false for self-signed UME and surface the same hint on certificate verify login failures.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-06 15:11:21 +08:00
f64835749a Expose worker scheduler health via heartbeat and isolate WebCRT IO.
API /metrics and /health/ready now read a worker heartbeat when collectors are split out; WebCRT blocking I/O uses a dedicated executor so session pumps do not starve the default pool.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-02 18:37:06 +08:00
f1263b0848 Start API and collector worker together from one-click scripts.
Default start_netx.ps1/sh now set NETX_RUN_INLINE_SCHEDULERS=false and launch netx_api.worker; stop scripts tear the worker down with the API.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-02 18:20:13 +08:00
96be90bd1a Harden retention under one-click start: UME raw caps and collection TTL.
Keep inline schedulers as the start_netx.ps1 default while bounding UME raw_json and pruning old NE collection dirs on startup.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-02 18:16:30 +08:00
e0503df8a5 Raise runtime defaults for multi-user shared-server deployments.
Size DB pool, CLI budget, and WebCRT session caps for concurrent operators while keeping hard ceilings and env overrides.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-02 18:11:12 +08:00
fa577aa3bd Adopt production-safe runtime defaults and forwarder retry limits.
Lower CLI/WebCRT/audit caps, log startup capacity warnings, and bound oclaw requeues so reconnect storms cannot thrash memory.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-02 18:08:28 +08:00
d56020d84c Harden runtime budgets: DB pool, CLI concurrency, timeouts, and metrics.
Add shared CLI budget/timeout with force-close, parallel port-traffic dispatch, unified shutdown, bounded audit queue, output/log caps, and /metrics probes.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-02 18:02:43 +08:00
b03c92bdef Default collectors inline with the API again.
Frontend+backend start is enough; external worker remains an optional production split.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-02 16:55:46 +08:00
136f40cdae Split WebCRT and API startup; default collectors to worker process.
Extract channel/session modules and CLI guard, move UME sidebands out of main, and default NETX_RUN_INLINE_SCHEDULERS off so ops run python -m netx_api.worker.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-02 16:50:52 +08:00
57b3faf9fb Move schema evolution to Alembic with auto-upgrade on API start.
Extract shared brownfield patches, add the legacy revision, and default to upgrade-head plus skip of duplicate inline DDL (with legacy fallback if Alembic fails).

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-02 16:41:56 +08:00
633a9d55bd Harden auth scopes, SQL/WebCRT gates, and per-install JWT secrets.
Add capability RBAC, Alembic bootstrap, optional worker schedulers, and close public docs by default so lab installs stay usable without shared signing keys.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-02 16:24:34 +08:00
hansjone
6d4cd741ef feat(auth): add local login, audit, API keys, and system admin UI
Gate netx Web/API/WebCRT with JWT and per-user API tokens, bootstrap an admin with forced password change, and expose users/audit/API-key management under a System section. MCP can reuse data/auth/mcp_token without extra env for local labs.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-30 02:34:25 +00:00
88479245bb feat(ne-exec): make max CLI commands configurable and allow traceroute
Add NETX_NE_EXEC_MAX_COMMANDS (default 5, cap 50) and whitelist traceroute/tracert/trace/trace6 prefixes for lab/ops use.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-28 10:57:55 +08:00
99e7b1557f fix(oclaw-bridge): share alarm WSS auth with analyze token
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 11:22:38 +08:00
1f1b42e8bf feat(ume): key alarm forward to OClaw via WSS and AI monitor UI
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 11:17:31 +08:00
042c015045 feat(ops): add managed NE management and batch CLI collection
Introduce workbench operations for multi-vendor NE CRUD/connect-test and Netmiko batch collection with job lifecycle controls, log downloads, and paginated run filters.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-27 23:34:29 +08:00
6701aee3c7 feat(ume): coordinate WSS with REST sync and sync before WSS on startup
WSS-primary current alarms with upsert/tombstone, skip scheduled REST when WSS active,
safe manual reconcile, startup REST baseline before WebSocket connect.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-27 09:57:33 +08:00
4f8735a83f feat(ume): real-time current alarms via WebSocket subscription
Add WS consumer, persisted subscription store, manual subscribe/cancel APIs, and UI controls; extend sync and tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-22 20:27:43 +08:00
84cf70cde3 feat(UME): 增加后台任务监控并启用5分钟告警自动同步
新增当前告警自动同步后台线程(默认300s一次)并提供开关配置;在 /v1/ume/sync/status 返回 runtime_tasks,前端“当前任务”面板展示保活与自动同步运行状态;同时隐藏历史告警UI但保留后端能力。

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-08 22:40:02 +08:00
7f2e4ec393 feat(UME): 增加RESTCONF对接与可视化运维页
- 支持 token 获取/续约/断开、DB共享缓存与跨进程单飞锁、keepalive 保活

- 新增 inventory/current/history 告警同步入库与查询接口,前端增加 UME 对接页面与分页

- 修复 stop_netx.ps1 在部分 PowerShell 版本下 Stop-Job -Force 报错

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-08 01:36:53 +08:00
f49c0b5bad feat: initialize netx ops tool repository
Set up netx as a standalone git-managed project with isolated Python dependencies, alarm ingestion/query APIs, oclaw bridge integration, and ops-focused UI enhancements including history and raw field access.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-03 23:43:21 +08:00