Commit graph

68 commits

Author SHA1 Message Date
633a9d55bd Harden auth scopes, SQL/WebCRT gates, and per-install JWT secrets.
Add capability RBAC, Alembic bootstrap, optional worker schedulers, and close public docs by default so lab installs stay usable without shared signing keys.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-02 16:24:34 +08:00
3908b78dbb Add ops task overview, chart ahead window, and WebCRT lifecycle status.
Unify live runners in /audit/tasks (including UME sync and connect tests), extend port-traffic compare past now via ahead_hours, and distinguish WebCRT connecting/ready/detached.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-02 14:05:59 +08:00
hansjone
a6c7267b47 Add config-sync cycle retention alongside config history keep.
Mirror LLDP job retention so finished sync cycles are pruned by policy while keeping per-NE config version history separate.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-02 03:44:35 +00:00
a5a3a4f156 Add topology classify inventory, fabric lifecycle, and broader collect targets.
Treat Fabric as an inventory sheet for role/region tagging and slices; detach fabric links on managed/UME delete instead of cascading map deletes. Extend collection to all managed and UME NEs, show NE source in management, and refine canvas vendor icon tones.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-02 11:09:58 +08:00
e7f97b7cf6 Harden LLDP collect ops: edge list, job reclaim, and schedule hygiene.
Add fabric link browsing, conservative job retention, hour-based intervals, multi-worker start locking, and trim canvas discover UI in favor of the LLDP page.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-02 03:58:03 +08:00
d05ba0f1f7 Add LLDP collect page with conservative fabric edge lifecycle.
Move scheduled discovery under Network → LLDP links, mark absent edges missing after one successful scan, purge only after four miss cycles, and expose unmatched/raw job detail.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-02 03:39:15 +08:00
f6b399e03e Improve WebCRT new-session flow for SecureCRT-like SSH/Telnet use.
Add quick-connect sessions with credential retry, raw interactive drivers, bootstrap banner replay, Huawei telnet prompt cleanup, and session rename/delete in the tree.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-01 22:52:31 +08:00
8cf1696d8c Improve topology discovery UX with review modals and live search.
Report unmatched/stub neighbors and matched links, move result lists into detail dialogs, deep-link edges to port traffic, and add fuzzy type-ahead canvas/palette NE search.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-01 13:35:52 +08:00
99fce837f0 Industrialize topology editor and add customizable edge styles.
Add tool modes, layouts, and per-edge/default style overrides with a cleaner toolbar and context menus.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-01 12:31:06 +08:00
653baa1b9f Add period and cross-task interface compare for port traffic wall.
Compare by interface target_id with optional mapped baseline (same window or time-shifted), keep chart samples on target_row_id, and unify UI wording to interface.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-31 22:53:26 +08:00
efe8f58cd2 Add ZTE-first port traffic monitoring with task wizard and ops wall.
Collect interface bit/s via CLI on a schedule, store samples in Postgres, and chart trends with uPlot.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-31 14:56:50 +08:00
f5b4a14c0f Harden config sync defaults, crash resume, and network nav collapse.
Disable auto-sync by default, enforce single-flight cycles with crash requeue, delay new scheduled runs after restart, and make the network sidebar collapsible.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-31 10:43:01 +08:00
0eead0e662 Add industrial config sync separate from collection tasks.
Periodic vendor-aware CLI sync stores zlib snapshots in Postgres with dashboard, retry, and config viewer under Network Management.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-31 10:25:36 +08:00
hansjone
6d4cd741ef feat(auth): add local login, audit, API keys, and system admin UI
Gate netx Web/API/WebCRT with JWT and per-user API tokens, bootstrap an admin with forced password change, and expose users/audit/API-key management under a System section. MCP can reuse data/auth/mcp_token without extra env for local labs.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-30 02:34:25 +00:00
dc805c2086 Add topology maps with LLDP discovery and React Flow canvas.
Includes map CRUD, graph save, neighbor discover, and UI controls for labels, sidebar, and edge flow.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-29 23:53:06 +08:00
873f2bfe34 feat(webcrt): add CRT-style browser terminal for managed and UME NEs
Ship an ops WebCRT module with xterm.js UI, WebSocket session bridge reusing hop/bastion login, searchable paged targets, and session audit limits.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-29 17:23:45 +08:00
572b0cfd9d Add UME-managed NE sync and batch account tools.
Sync UME inventory into managed NE with source-aware dedupe and cleanup, add one-click account updates for selected or tagged NEs, and expose the new managed NE actions in the web UI while keeping bulk bastion flows compatible with optional target passwords.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-02 10:52:54 +08:00
38a1c7f3a9 feat(cli): UME lazy exec via shared profiles and ume_ne_id MCP support
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-26 17:13:49 +08:00
ba1a40f725 feat(ume): OClaw forwarder runtime task and i18n status codes
Register oclaw_alarm_forwarder in background tasks with pause/resume, emit rt:/ws:/fwd: codes for last_error, and translate them in the UI for English and Chinese.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-24 10:29:10 +08:00
e474c0a431 feat(ume): ne_type filter, rule edit, and pager layout
Match key alerts by optional inventory ne_types, add edit dialog to update device types on existing rules, and keep card pager controls on one row.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 20:44:33 +08:00
17270a26b6 fix(ume): forward stats by rule_key, rule toggle, and list filters
Aggregate push counts per monitor rule, add enabled PATCH and paginated filtered list API/UI so keyword rules show correct stats without deleting.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 14:36:13 +08:00
300fd74565 fix(ume): key-alert DB migration fails on psycopg3 LIKE placeholder
Use starts_with() instead of LIKE kw:% and run each DDL step in its own
transaction so match_type/match_value columns are added reliably.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 19:11:11 +08:00
b54a6e5ad4 fix(ume): global clear-push setting, schema migration, and help hints
Make forward-on-clear a global monitor toggle, run key-alert DDL in an
isolated startup transaction, and fix HelpHint popovers plus API errors
when the server returns non-JSON responses.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 17:26:49 +08:00
34db62c8d2 feat(ume): keyword key-alert rules with label and case-insensitive match
Add description keyword matching alongside notificationId rules, require
per-rule labels, and improve the AI monitor form layout and clear-on-push UX.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 16:48:01 +08:00
1f1b42e8bf feat(ume): key alarm forward to OClaw via WSS and AI monitor UI
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 11:17:31 +08:00
d3d7f62a02 feat(managed-ne): add bastion SSH protocol proxy hop type
Support composite-username bastion login for automated connect-test and exec, with bastion-managed or manual target credential modes.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 10:47:52 +08:00
e62f4f2c74 fix(ume): block WSS until startup REST alarm sync completes
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 21:52:39 +08:00
7a729413ab fix(ume): prefer WSS at boot; defer REST grace and avoid parallel sync
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 21:47:26 +08:00
65e0713e94 fix(startup): defer alarm pull 60s; health probe accepts only HTTP 200
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 21:32:07 +08:00
f562f50953 fix(startup): defer UME alarm sync so /health is ready quickly
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 21:28:57 +08:00
dc17f9d15a feat(ne): connect detail, Huawei/Cisco hop, Cisco hostname probe
Persist full connect test logs (connect_detail) with NE UI detail modal.
Add Huawei/Cisco jump CLI templates and generic CLI hop session path.
Probe Cisco hostname via show configuration | include hostname (60s timeout).

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 21:50:41 +08:00
4575fef523 feat(ne): ZTE jump host for connect test and collection
Add hop fields and encrypted credentials, unified Netmiko session factory with ZTE ssh/telnet CLI templates and secondary auth, wire connect/collect paths, and NE management UI with auto-suggested jump commands.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 17:14:49 +08:00
042c015045 feat(ops): add managed NE management and batch CLI collection
Introduce workbench operations for multi-vendor NE CRUD/connect-test and Netmiko batch collection with job lifecycle controls, log downloads, and paginated run filters.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-27 23:34:29 +08:00
664775927b fix(ume): idle runtime tasks show running with last sync time; English labels and help hint
Show inventory/alarms schedulers as running with DB last_run_at during debounce; English interval labels; subscription help on ? click.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-27 10:15:22 +08:00
6701aee3c7 feat(ume): coordinate WSS with REST sync and sync before WSS on startup
WSS-primary current alarms with upsert/tombstone, skip scheduled REST when WSS active,
safe manual reconcile, startup REST baseline before WebSocket connect.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-27 09:57:33 +08:00
fb374a9c36 feat(ume): handle server-side subscription loss with local cleanup confirm
Detect missing UME subscriptions from WSS/DELETE errors, stop stale reconnects, and prompt to clear local state before re-establishing.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-25 16:50:37 +08:00
31e745ef95 fix(ume): show WSS connection state separately from alarm activity
Track ws_connection for UI pills, stop overwriting runtime last_error on alarm events, and wire pause/resume to reconnect WSS.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-23 11:19:00 +08:00
5bd83c58dc feat(ume): expose WSS runtime logs on subscription status UI
Ring-buffer ws_logs API, alarm raise/clear labels with alarmkey, and scrollable log panel on UME page.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-22 21:15:15 +08:00
4f8735a83f feat(ume): real-time current alarms via WebSocket subscription
Add WS consumer, persisted subscription store, manual subscribe/cancel APIs, and UI controls; extend sync and tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-22 20:27:43 +08:00
21f7cfba41 feat(ume): denormalize host_name onto alarms for display and grouping
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-20 00:05:10 +08:00
95db646403 feat(ume): English protocol bucket labels via lang query param
Share protocol classification helpers and return en labels for diagnostics when lang=en.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-19 23:35:47 +08:00
47033f14ab fix(netx): order current alarms by time_created desc
Sort UME current alarms by time_created descending (newest first) with last_seen_at and alarm_key as tie-breakers to keep offset/limit pagination stable. Apply the same default ordering in the MCP tool listing.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-13 17:28:52 +08:00
67f7e48597 fix(netx): surface scheduler startup init failures
Log startup exceptions for UME scheduler threads and set runtime task status to error with startup_thread_init_failed details instead of silently swallowing exceptions. This prevents tasks from staying in init without actionable diagnostics.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-13 16:05:05 +08:00
eebfbf25fa fix(netx): avoid alarm sync failures from long UME fields
Store UME alarm payload fields as TEXT and run startup ALTER COLUMN upgrades so large alarm records no longer fail with StringDataRightTruncation. Keep full values during sync while hashing only pathological ultra-long alarm keys to preserve idempotent primary keys.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-13 15:59:20 +08:00
b253ee7bff fix(netx): do not put debounce wait text in runtime last_error
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-12 11:36:30 +08:00
666541266b fix(netx): separate scheduler interval vars to avoid closure overwrite
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-12 11:25:03 +08:00
17cd469b1a netx: log netx.ume.schedule/sync INFO to stderr for prod log files
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-12 11:18:32 +08:00
936cee1aa2 UME scheduler: resume wakes debounce sleep + skip wait; pause clears hints; loop tick logs
- Event.wait debounce sleep so 开始 interrupts long interval wait\n- resume sets skip+event; wake path discards skip to avoid double-sync\n- pause clears skip/wake; boot resets debounce via _reset_runtime_pause_flags\n- loop tick + thread is_alive logging for netx.ume.schedule

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-12 11:10:07 +08:00
b17aef0eae UME schedule: interval from any finished job; drop trailing sleep; stale running cleanup; paging logs
- Use last ended_at (done or failed) for debounce; remove duplicate time.sleep after sync\n- On startup mark running+no ended_at jobs failed (crash/interrupt) so interval logic is not fooled\n- Log marker page progress every 25 pages\n- Log when alarm/inventory scheduler threads start

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-12 10:51:47 +08:00
7a9921b45b UME schedule: reset pause flags on boot; defer sync from DB last done time
- _reset_runtime_pause_flags() after create_all so pause state cannot survive process restart in memory\n- Before each alarms/inventory auto sync, wait until interval elapsed since last status=done job ended_at (any trigger); honor pause during wait\n- Helps avoid immediate duplicate sync on restart when DB was recently updated

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-12 10:35:38 +08:00