Commit graph

113 commits

Author SHA1 Message Date
79ae5ff31c fix(bastion): use keyboard-interactive auth for protocol-proxy bastions
ZTE-TSM and similar bastions reject standard SSH password auth and require Vault password via keyboard-interactive; connect over an authenticated Paramiko session instead of re-handshaking with Netmiko.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 21:31:46 +08:00
e474c0a431 feat(ume): ne_type filter, rule edit, and pager layout
Match key alerts by optional inventory ne_types, add edit dialog to update device types on existing rules, and keep card pager controls on one row.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 20:44:33 +08:00
d5d6d4eada fix(ume): keep key-alert monitor toggle on one line
Use inline-flex layout for the enabled checkbox so the label no longer wraps to a second row.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 15:02:11 +08:00
17270a26b6 fix(ume): forward stats by rule_key, rule toggle, and list filters
Aggregate push counts per monitor rule, add enabled PATCH and paginated filtered list API/UI so keyword rules show correct stats without deleting.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 14:36:13 +08:00
300fd74565 fix(ume): key-alert DB migration fails on psycopg3 LIKE placeholder
Use starts_with() instead of LIKE kw:% and run each DDL step in its own
transaction so match_type/match_value columns are added reliably.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 19:11:11 +08:00
b54a6e5ad4 fix(ume): global clear-push setting, schema migration, and help hints
Make forward-on-clear a global monitor toggle, run key-alert DDL in an
isolated startup transaction, and fix HelpHint popovers plus API errors
when the server returns non-JSON responses.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 17:26:49 +08:00
34db62c8d2 feat(ume): keyword key-alert rules with label and case-insensitive match
Add description keyword matching alongside notificationId rules, require
per-rule labels, and improve the AI monitor form layout and clear-on-push UX.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 16:48:01 +08:00
99e7b1557f fix(oclaw-bridge): share alarm WSS auth with analyze token
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 11:22:38 +08:00
1f1b42e8bf feat(ume): key alarm forward to OClaw via WSS and AI monitor UI
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 11:17:31 +08:00
9a39ddfcc7 feat(ne-exec): allow ping and ping6 on managed NE CLI path
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 16:14:59 +08:00
06a5615095 feat(managed-ne): tag stats cards and bulk ops by tag
Add tags/remark to import template, stats/ids-by-tag APIs, per-tag overview sub-cards, and bulk proxy/connect-test dialogs filtered by tag.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 16:13:31 +08:00
d23b5b7cb0 revert(managed-ne): keep bulk import NE-only
Remove hop columns from the import template and stop applying hop settings during import; use Batch add proxy instead.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 15:16:12 +08:00
81c028949b ui(managed-ne): replace import hint with help popover
Move bulk import and bastion/jump notes into a toolbar help popover to keep the action bar clean.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 15:00:01 +08:00
7d74e7b3f4 feat(managed-ne): optional password and hop columns in import
Allow creating/importing NEs without target password for bastion-managed workflows, and support optional hop_* columns in bulk import templates.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 11:23:57 +08:00
bac4a609b1 docs(managed-ne): use placeholder IPs in bastion hop examples
Replace real site addresses with 1.1.1.1/2.2.2.2 and generic usernames in i18n hints and tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 10:59:32 +08:00
a69899d146 chore(web): sync package-lock engines field with package.json
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 10:49:11 +08:00
d3d7f62a02 feat(managed-ne): add bastion SSH protocol proxy hop type
Support composite-username bastion login for automated connect-test and exec, with bastion-managed or manual target credential modes.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 10:47:52 +08:00
e62f4f2c74 fix(ume): block WSS until startup REST alarm sync completes
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 21:52:39 +08:00
7a729413ab fix(ume): prefer WSS at boot; defer REST grace and avoid parallel sync
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 21:47:26 +08:00
65e0713e94 fix(startup): defer alarm pull 60s; health probe accepts only HTTP 200
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 21:32:07 +08:00
f562f50953 fix(startup): defer UME alarm sync so /health is ready quickly
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 21:28:57 +08:00
d05b64b4c1 fix(scripts): verify netx API after background start and set PYTHONPATH
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 21:25:58 +08:00
0361472ede fix(ne-exec): allow only show/display CLI and harden agent injection
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 20:51:06 +08:00
1784d996dd fix(ume): dedupe WSS logs on disconnect and unchanged alarms
Throttle repeated connection-state logs, skip unchanged alarm notifications, and suppress duplicate subscription-lost and parse-ignore messages.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-01 19:33:15 +08:00
dba8d38f5c fix(scripts): default Node 24 path and add --api-only
Use /usr/local/nodejs/node-v24.16.0-linux-x64 for web dev by default; add --api-only to start API without Node on the host.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-01 15:53:30 +08:00
f2d686eba8 fix(scripts): set web port 8505 and require Node 20+
Change Linux default web port to 8505, add NODE_CMD/NPM_CMD support with version check, and declare Node 20.19+ in web/package.json engines.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-01 15:15:00 +08:00
823a5819f7 fix(scripts): use host Python and fix Linux start script
Remove venv requirement, default PYTHON_CMD to /usr/local/python_env_new/bin/python3, and fix web startup without bash -lc. Add .gitattributes to keep shell scripts LF.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-01 14:44:35 +08:00
4d4deb51a0 chore(scripts): add Linux start/stop helpers
Add bash scripts to start/stop netx API (8890) and Vite web (8055) with PID/log files under scripts/.run.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-01 11:23:59 +08:00
651ee47842 docs(mcp): clarify oclaw install and same-python self-check
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-30 23:42:44 +08:00
70da26edaa docs(mcp): drop unused branch/tag and private-repo install notes
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-30 15:49:36 +08:00
ec6ef8baaa docs(mcp): document git+pip upgrade path in update section
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-30 15:47:10 +08:00
45ce9d3f7e feat(mcp): add netx-mcp package and HTTP stdio MCP
- Extract installable packages/netx-mcp (12 HTTP tools, mcp.json)

- Delegate netx_api.mcp to netx_mcp; keep legacy db_server shim

- Add docs/MCP.md, install payload, pyproject entry, tests

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-30 15:44:32 +08:00
981347b5b1 feat(ne): add managed NE read-only exec API
Add a guarded managed-ne exec endpoint for oclaw ops tools to login managed devices and run read-only CLI safely.
Include request schema and unit tests for command guardrails and execution flow.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 22:12:50 +08:00
dc17f9d15a feat(ne): connect detail, Huawei/Cisco hop, Cisco hostname probe
Persist full connect test logs (connect_detail) with NE UI detail modal.
Add Huawei/Cisco jump CLI templates and generic CLI hop session path.
Probe Cisco hostname via show configuration | include hostname (60s timeout).

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 21:50:41 +08:00
778442dc57 feat(ne): batch delete selected managed network elements
Add POST /v1/managed-ne/batch-delete and toolbar button with confirmation on NE management page.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 19:02:16 +08:00
d3eae3351c feat(ne): add Linux SSH bastion hop type
Support hop_vendor=linux via Paramiko direct-tcpip tunnel; ZTE CLI hop unchanged. UI hop type selector and distinct list badges.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 17:38:37 +08:00
d395aa7174 feat(ne): batch apply jump proxy on selected NEs
Add POST /v1/managed-ne/batch-hop, shared HopProxyFields form, and toolbar button next to connectivity test.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 17:28:14 +08:00
4575fef523 feat(ne): ZTE jump host for connect test and collection
Add hop fields and encrypted credentials, unified Netmiko session factory with ZTE ssh/telnet CLI templates and secondary auth, wire connect/collect paths, and NE management UI with auto-suggested jump commands.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 17:14:49 +08:00
71ec3385d2 fix(web): display NE tested time in system timezone
Treat timezone-less ISO timestamps from connect_tested_at as UTC before formatting so NE test time renders correctly in the user's system timezone.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 14:39:15 +08:00
5b77c6f327 feat(ume): collapse NE and alarms panels by default
Default the UME NE list and current alarms sections to collapsed state and add explicit expand/collapse toggles for cleaner initial layout.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 14:21:19 +08:00
d512679425 fix(collect): stabilize start flow and default collapse create panel
Avoid false running-state conflicts when starting draft jobs, block overlapping NE runs across jobs, and default the create panel to collapsed for cleaner task-first operation.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 10:58:17 +08:00
52f1b63b18 feat(collect): support batch add in NE picker
Allow selecting multiple eligible NEs and adding them into the selected list in one action, while keeping single-item add for precise control.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 10:47:26 +08:00
f1ed4fe753 feat(collect): draft jobs, merged create UI, and unified start
Create collection jobs without auto-running; add /start for first run and re-run. Merge create form with filterable NE picker and selected list.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 10:36:47 +08:00
fed7f56ad0 fix: collection first-run pending and module tab cross-nav
Defer collection scheduling to BackgroundTasks after commit; claim pending runs atomically with retries. Only handle focus-module broadcasts for the matching moduleId so opening one module does not rewrite other tabs.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 10:22:11 +08:00
3413d5bf32 fix(collection): correct run status during jobs and add retry-failed
Fix pending mislabeled as fail due to timezone and queue stale checks, show full error details, sync live progress counts, and add retry-failed endpoint for failed NEs only.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 10:05:20 +08:00
3024e13812 feat(managed-ne): add bulk import template download with device_type reference sheet
Expose GET /v1/managed-ne/import/template and a workbench button to download xlsx/csv templates listing supported Netmiko device types.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 09:41:25 +08:00
042c015045 feat(ops): add managed NE management and batch CLI collection
Introduce workbench operations for multi-vendor NE CRUD/connect-test and Netmiko batch collection with job lifecycle controls, log downloads, and paginated run filters.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-27 23:34:29 +08:00
282dbe75af feat(web): NetX workbench, UME-only UI, i18n, and header status
- Replace sidebar app with workbench home and module tabs (openOrFocusModule)

- Remove legacy pages; add module registry, shared tab channel, WEB.md

- Add zh/en i18n, global ToastProvider, restore oclaw bridge pill in header

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-27 11:18:30 +08:00
664775927b fix(ume): idle runtime tasks show running with last sync time; English labels and help hint
Show inventory/alarms schedulers as running with DB last_run_at during debounce; English interval labels; subscription help on ? click.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-27 10:15:22 +08:00
6701aee3c7 feat(ume): coordinate WSS with REST sync and sync before WSS on startup
WSS-primary current alarms with upsert/tombstone, skip scheduled REST when WSS active,
safe manual reconcile, startup REST baseline before WebSocket connect.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-27 09:57:33 +08:00