Commit graph

248 commits

Author SHA1 Message Date
873f2bfe34 feat(webcrt): add CRT-style browser terminal for managed and UME NEs
Ship an ops WebCRT module with xterm.js UI, WebSocket session bridge reusing hop/bastion login, searchable paged targets, and session audit limits.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-29 17:23:45 +08:00
88479245bb feat(ne-exec): make max CLI commands configurable and allow traceroute
Add NETX_NE_EXEC_MAX_COMMANDS (default 5, cap 50) and whitelist traceroute/tracert/trace/trace6 prefixes for lab/ops use.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-28 10:57:55 +08:00
a6a5abc9ef fix(ne-exec): allow no-more in managed NE CLI pipe whitelist
Support Huawei-style display ... | no-more alongside existing read-only pipe filters.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-14 16:49:44 +08:00
33af0efc98 fix(ne-exec): allow read-only pipe filters in managed NE CLI
Whitelist include/exclude/begin/section/count/match/grep/one-line after show/display pipes while blocking redirect/append/tee/send.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-14 16:24:47 +08:00
c5973eec69 fix(managed-ne): prevent ume-sync route conflicts and prefer host_name
Ensure fixed managed-ne paths are matched before /{ne_id} so deleting UME-synced NEs no longer triggers managed_ne_not_found, and use UME host_name as the synced display name to align managed NE naming with inventory host identity.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-02 14:24:19 +08:00
3a35b54f0e fix(managed-ne): keep API list behavior for UI while MCP remains restricted
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-02 11:24:49 +08:00
987b501e53 fix(managed-ne): require filters for listManagedNe and tighten pagination
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-02 11:07:47 +08:00
38a1c7f3a9 feat(cli): UME lazy exec via shared profiles and ume_ne_id MCP support
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-26 17:13:49 +08:00
5a00736f23 fix(bastion): subclass netmiko driver class on Python 3.14
ConnectHandler is a factory function in current Netmiko; subclass the CLASS_MAPPER driver (e.g. ZteZxrosSSH) when wrapping a pre-authenticated Paramiko session.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 22:35:37 +08:00
088e920f9d fix(bastion): match OpenSSH username parsing for protocol-proxy hop
OpenSSH treats the last @ as user/host separator, so the SSH username must be hop@target@ip without duplicating hop_host. Legacy templates with {hop_host} are stripped automatically; connect logs now show bastion_ssh_cli for comparison with manual ssh.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 21:49:43 +08:00
79ae5ff31c fix(bastion): use keyboard-interactive auth for protocol-proxy bastions
ZTE-TSM and similar bastions reject standard SSH password auth and require Vault password via keyboard-interactive; connect over an authenticated Paramiko session instead of re-handshaking with Netmiko.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 21:31:46 +08:00
e474c0a431 feat(ume): ne_type filter, rule edit, and pager layout
Match key alerts by optional inventory ne_types, add edit dialog to update device types on existing rules, and keep card pager controls on one row.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 20:44:33 +08:00
b54a6e5ad4 fix(ume): global clear-push setting, schema migration, and help hints
Make forward-on-clear a global monitor toggle, run key-alert DDL in an
isolated startup transaction, and fix HelpHint popovers plus API errors
when the server returns non-JSON responses.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 17:26:49 +08:00
34db62c8d2 feat(ume): keyword key-alert rules with label and case-insensitive match
Add description keyword matching alongside notificationId rules, require
per-rule labels, and improve the AI monitor form layout and clear-on-push UX.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 16:48:01 +08:00
1f1b42e8bf feat(ume): key alarm forward to OClaw via WSS and AI monitor UI
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 11:17:31 +08:00
9a39ddfcc7 feat(ne-exec): allow ping and ping6 on managed NE CLI path
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 16:14:59 +08:00
06a5615095 feat(managed-ne): tag stats cards and bulk ops by tag
Add tags/remark to import template, stats/ids-by-tag APIs, per-tag overview sub-cards, and bulk proxy/connect-test dialogs filtered by tag.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 16:13:31 +08:00
d23b5b7cb0 revert(managed-ne): keep bulk import NE-only
Remove hop columns from the import template and stop applying hop settings during import; use Batch add proxy instead.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 15:16:12 +08:00
7d74e7b3f4 feat(managed-ne): optional password and hop columns in import
Allow creating/importing NEs without target password for bastion-managed workflows, and support optional hop_* columns in bulk import templates.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 11:23:57 +08:00
bac4a609b1 docs(managed-ne): use placeholder IPs in bastion hop examples
Replace real site addresses with 1.1.1.1/2.2.2.2 and generic usernames in i18n hints and tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 10:59:32 +08:00
d3d7f62a02 feat(managed-ne): add bastion SSH protocol proxy hop type
Support composite-username bastion login for automated connect-test and exec, with bastion-managed or manual target credential modes.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 10:47:52 +08:00
0361472ede fix(ne-exec): allow only show/display CLI and harden agent injection
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 20:51:06 +08:00
1784d996dd fix(ume): dedupe WSS logs on disconnect and unchanged alarms
Throttle repeated connection-state logs, skip unchanged alarm notifications, and suppress duplicate subscription-lost and parse-ignore messages.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-01 19:33:15 +08:00
45ce9d3f7e feat(mcp): add netx-mcp package and HTTP stdio MCP
- Extract installable packages/netx-mcp (12 HTTP tools, mcp.json)

- Delegate netx_api.mcp to netx_mcp; keep legacy db_server shim

- Add docs/MCP.md, install payload, pyproject entry, tests

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-30 15:44:32 +08:00
981347b5b1 feat(ne): add managed NE read-only exec API
Add a guarded managed-ne exec endpoint for oclaw ops tools to login managed devices and run read-only CLI safely.
Include request schema and unit tests for command guardrails and execution flow.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 22:12:50 +08:00
dc17f9d15a feat(ne): connect detail, Huawei/Cisco hop, Cisco hostname probe
Persist full connect test logs (connect_detail) with NE UI detail modal.
Add Huawei/Cisco jump CLI templates and generic CLI hop session path.
Probe Cisco hostname via show configuration | include hostname (60s timeout).

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 21:50:41 +08:00
3413d5bf32 fix(collection): correct run status during jobs and add retry-failed
Fix pending mislabeled as fail due to timezone and queue stale checks, show full error details, sync live progress counts, and add retry-failed endpoint for failed NEs only.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 10:05:20 +08:00
042c015045 feat(ops): add managed NE management and batch CLI collection
Introduce workbench operations for multi-vendor NE CRUD/connect-test and Netmiko batch collection with job lifecycle controls, log downloads, and paginated run filters.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-27 23:34:29 +08:00
6701aee3c7 feat(ume): coordinate WSS with REST sync and sync before WSS on startup
WSS-primary current alarms with upsert/tombstone, skip scheduled REST when WSS active,
safe manual reconcile, startup REST baseline before WebSocket connect.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-27 09:57:33 +08:00
fb374a9c36 feat(ume): handle server-side subscription loss with local cleanup confirm
Detect missing UME subscriptions from WSS/DELETE errors, stop stale reconnects, and prompt to clear local state before re-establishing.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-25 16:50:37 +08:00
31e745ef95 fix(ume): show WSS connection state separately from alarm activity
Track ws_connection for UI pills, stop overwriting runtime last_error on alarm events, and wire pause/resume to reconnect WSS.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-23 11:19:00 +08:00
5bd83c58dc feat(ume): expose WSS runtime logs on subscription status UI
Ring-buffer ws_logs API, alarm raise/clear labels with alarmkey, and scrollable log panel on UME page.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-22 21:15:15 +08:00
635cd52d4f fix(ume): accept empty JSON body on successful delete-subscription
Parse 204/empty UME responses without JSONDecodeError; improve request error messages and orphan-delete failure reporting.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-22 21:01:24 +08:00
a8b359f60d fix(ume): cancel alarm subscription with DELETE and surface failures
Use DELETE delete-subscription, refresh token before cancel, recover orphan subs on establish, and keep local state when UME delete fails.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-22 20:47:59 +08:00
4f8735a83f feat(ume): real-time current alarms via WebSocket subscription
Add WS consumer, persisted subscription store, manual subscribe/cancel APIs, and UI controls; extend sync and tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-22 20:27:43 +08:00
21f7cfba41 feat(ume): denormalize host_name onto alarms for display and grouping
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-20 00:05:10 +08:00
95db646403 feat(ume): English protocol bucket labels via lang query param
Share protocol classification helpers and return en labels for diagnostics when lang=en.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-19 23:35:47 +08:00
16607db3cd fix(netx): prefer UUID net_id from ME{} in objectName
Only treat UUID-like values as net_id. Prefer extracting ME{uuid} from objectName and ignore ME{numeric} wrappers found in alarmkey so alarms join inventory correctly.

Also constrain legacy alarmkey split formats (#, csv, space) to UUID-like prefixes.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-13 17:11:58 +08:00
15d9cb5db3 fix(netx): derive ne_id from objectName ME{net_id}
When alarmkey does not contain a net_id, fall back to extracting ME{net_id} from objectName so alarms can join inventory correctly. Add regression coverage for the ME{} objectName pattern.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-13 17:02:46 +08:00
626bb2b02e fix(netx): parse space-separated net id from alarmkey
Support UME alarmkey values like "<net_id> <x> <y>" when deriving ne_id so current alarms can join inventory correctly. Add regression coverage for hash, csv, and space-delimited alarmkey formats.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-13 16:29:19 +08:00
340fc8ee7d Reconcile UME inventory and current alarms with full snapshot
After a complete marker pull (is_end_of_reply, no iterator/dup abort), delete local NE/holders and current alarms not present in this batch. Replace 48h-only current-alarm expiry. Flush before bulk delete to avoid ORM stale updates. Job/batch JSON records deleted counts and reconcile flags.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-11 18:31:04 +08:00
ea0d324624 feat(UME): add raw query, flexible aggregate, and safe SQL endpoint
- Add /v1/ume/alarms/fields and /v1/ume/alarms/raw (select_fields + meta)
- Add /v1/ume/alarms/aggregate/raw with filter/meta echo
- Add /v1/sql/ume_query with table allowlist and optional statement_timeout
- Update README and expand UME regression tests

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-09 00:06:21 +08:00
d0994f6e53 feat(UME): 完善网元字段注释并补齐IPv6地址字段
为 ume_inventory_ne 的关键字段补充建表注释并在启动时执行 COMMENT ON 同步历史库结构,同时新增 ipv6_address 字段并完成入库映射、接口返回与前端类型定义对齐。

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-08 22:19:06 +08:00
037873423d feat(UME): 网元与告警统一marker分页能力
将 marker 分页逻辑抽象为通用流程并同时应用于网元和告警同步,默认按 limit+marker 拉取全量数据,统一处理 is-end-of-reply、缺失marker和重复页保护。

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-08 21:44:21 +08:00
00afaaae3d fix(UME): 兼容首批无marker场景并补充回归测试
告警分页在响应头缺失 marker 时直接结束迭代,避免首批已全量却重复翻页;同时补充对应单测并保持 HTTPTransport 传输方式与现网一致。

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-08 20:13:10 +08:00
267eddb273 feat(UME): 切换marker分页并简化告警表字段
告警同步改为按响应头 marker 连续迭代,支持 iterator is null 的500尾页兜底,同时移除告警表中的 ne_name/user_label 冗余字段,统一在查询层与网元表 join 补齐展示信息。

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-08 18:58:24 +08:00
3ea4f08bea feat(UME): 完善网元元数据入库并增强告警/前端展示
补齐 ume_inventory_ne 的关键元数据字段并在同步时结构化落库,支持从 alarmkey 推导 ne_id、告警查询连表补齐 user_label/ne_name,同时优化 UME 页面分页显示与网元展开详情,提升运维排障可读性。

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-08 17:02:57 +08:00
7f2e4ec393 feat(UME): 增加RESTCONF对接与可视化运维页
- 支持 token 获取/续约/断开、DB共享缓存与跨进程单飞锁、keepalive 保活

- 新增 inventory/current/history 告警同步入库与查询接口,前端增加 UME 对接页面与分页

- 修复 stop_netx.ps1 在部分 PowerShell 版本下 Stop-Job -Force 报错

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-08 01:36:53 +08:00