Skip to content

0.11.0

Choose a tag to compare

@dsmorgan dsmorgan released this 31 Aug 20:33
· 78 commits to main since this release

The routed view finishes its real-site shakedown, and a security audit hardens every store.

Highlights

  • The routed view discovers the internet uplink — the default route's exit interface resolves to its VLAN's rail: drawn green, named on the drop line ("via VLAN 299"), hover-linked to the cloud. Appliance-style WAN ports keep the plain cloud-to-router drawing; no configuration either way.
  • Rails must participate — IPAM-only supernets, aggregates, and unclaimed VLANs stay on /vlans; the map shows the networks that exist. ADR-0002 is accepted and #17 closed.
  • UniFi device temperature (#40, thanks @slmingol) — the controller's reading lands as a device fact on the detail page, gated on a real sensor and an up device.
  • Security hardening — raw payloads strip credential fields (LibreNMS device rows carry SNMPv3 secrets); firewall-config redaction matches secret tags as substrings and catches OTP seeds; the routed graph JSON is script-escaped; pfSense/phpIPAM keep last good data through failed or empty polls.
  • Targeted deletion — snapshots and stored firewall config revisions can be deleted from the UI.
  • The break-glass snapshot embeds the latest firewall config revision (double-scrubbed), PATCHBAY_SNAPSHOT_AT is editable on /ops, and /configs shows canonical device names.

Upgrading note: stored firewall revisions captured before 0.11.0 predate the wider redaction — use "delete all stored revisions" on the device's config page and let the next poll re-capture.

Full details in the changelog.