Skip to content

Repository files navigation

NetCore banner

NetCore

AI-powered network switch management — multi-vendor SSH and serial access, 50+ Jinja2 templates, an AI agent, and security auditing for mixed network fleets.

Stars Last commit License Python FastAPI Electron desktop

NetCore screenshot

Quick Start

git clone https://github.com/OneByJorah/NetCore.git
cd NetCore
cp .env.example .env   # set OPENAI_API_KEY and SSH credentials
docker compose up -d

Open http://localhost:3000 for the web UI, or http://localhost:8000/docs for the API docs.

What This Is

NetCore is a full-stack platform for managing network switches and routers across vendors. It connects over SSH or a serial console, generates configs from templates, parses existing running-configs into structured data, runs AI-assisted operations, and enforces change discipline through an approval workflow. It is built for network engineers and MSPs who manage heterogeneous hardware and want an audit trail behind every change.

Note

This project has been consolidated from nethermind legacy codebase. NetCore represents the evolution and modernization of the original nethermind platform.

Features

  • Multi-vendor support — Cisco IOS/XR/NX-OS, HP ArubaOS-Switch (ProCurve), Juniper JunOS, Arista EOS, and Linux.
  • SSH and serial console — Netmiko for SSH, pyserial for RS-232/USB out-of-band access, plus Telnet deploy.
  • 50+ Jinja2 templates — built-in configuration templates for Aruba, Cisco, and generic devices.
  • Config parser — turn existing running-config text into structured data for editing and re-rendering.
  • AI chat assistant — OpenAI-powered agent with tool calling for natural-language operations.
  • IRIS-style workflow engine — disciplined config change management with approval gates.
  • Security auditing — CVE scanning, AAA checks, and CIS/NIST compliance findings.
  • Config diff and rollback — compare versions and restore previous configs.
  • Device health monitoring — CPU, memory, and interface status metrics.
  • Immutable audit trail — every action logged with actor, target, and timestamp.
  • Desktop app — an Electron package bundles backend and frontend into one installer.

Architecture

┌─────────────────────────────────────────────────┐
│                   Frontend                       │
│          Next.js + TypeScript + Tailwind         │
│   Dashboard │ Switches │ Configs │ Templates     │
│   Chat │ Workflows │ Security │ Topology         │
└──────────────────────┬──────────────────────────┘
                       │ REST API
┌──────────────────────▼──────────────────────────┐
│                    Backend                       │
│              FastAPI + SQLAlchemy                 │
│                                                  │
│  ┌─────────────┐  ┌──────────────┐  ┌────────┐ │
│  │ Netmiko SSH │  │ Serial/COM   │  │ AI     │ │
│  │ Client      │  │ Client       │  │ Agent  │ │
│  └─────────────┘  └──────────────┘  └────────┘ │
│  ┌─────────────┐  ┌──────────────┐  ┌────────┐ │
│  │ Template    │  │ Config       │  │Workflow│ │
│  │ Engine      │  │ Parser       │  │ Engine │ │
│  └─────────────┘  └──────────────┘  └────────┘ │
│  ┌─────────────┐  ┌──────────────┐  ┌────────┐ │
│  │ Deployer    │  │ Security     │  │Audit   │ │
│  │             │  │ Auditor      │  │Trail   │ │
│  └─────────────┘  └──────────────┘  └────────┘ │
└──────────────────────┬──────────────────────────┘
                       │
              ┌────────▼────────┐
              │   SQLite / PG   │
              │   Database      │
              └─────────────────┘

API Endpoints

Method Endpoint Description
GET /api/switches/ List all switches
POST /api/switches/ Add a new switch
POST /api/switches/{id}/backup Pull running config via SSH
GET /api/configs/{id} Get a config backup
POST /api/config/parse Upload .txt config → structured JSON
POST /api/config/validate Validate a config before deploy
POST /api/config/render Render config to CLI text
POST /api/config/deploy Deploy config to a switch
GET /api/templates/ List config templates
POST /api/templates/render Render a template with variables
POST /api/chat/ Chat with the AI assistant
GET /api/workflows/ List workflows
GET /api/security/ Security findings
GET /api/system/serial-ports List serial ports
GET /health Health check

Configuration

Copy .env.example to .env and set real values:

Variable Default Description
DATABASE_URL sqlite:///./switches.db Database connection string
OPENAI_API_KEY (empty) OpenAI API key for the AI agent
OPENAI_MODEL gpt-4o Model used by the AI agent
SSH_USERNAME admin Default SSH username for switches
SSH_PASSWORD (empty) Default SSH password
SECRET_KEY change-me Application secret key
LOG_LEVEL INFO Log verbosity
CORS_ORIGINS http://localhost:3000,http://localhost:5173 Allowed frontend origins
NEXT_PUBLIC_API_URL http://localhost:8000 Frontend → backend API base URL

Warning

SSH passwords are stored encrypted at rest, but the default SECRET_KEY and SQLite database are development defaults. Set a strong SECRET_KEY, uncomment the PostgreSQL service, and switch DATABASE_URL before production use.

CLI

NetCore also ships a CLI for quick config operations:

cd scripts
python cli.py render --hostname MY-SW --mgmt-ip 192.168.1.10
python cli.py parse /path/to/running-config.txt
python cli.py deploy --transport telnet --host 192.168.1.1 --port 9023

Local Development

# Backend
cd backend
python -m venv .venv
source .venv/bin/activate          # Windows: .venv\Scripts\activate
pip install -r requirements.txt
uvicorn main:app --reload --port 8000

# Frontend
cd frontend
npm install
npm run dev

Desktop App

An Electron package bundles the backend and frontend into a single app. Build with desktop/build-win.bat (Windows) or desktop/build-linux.sh (AppImage/deb/rpm), or run from source with npx electron . from desktop/.

Use Cases

  1. Network engineers — manage and back up a mixed-vendor fleet from one UI.
  2. MSPs — standardize config generation and keep an audit trail per customer.
  3. Lab engineers — pair with containerlab topologies for testing.
  4. Security teams — run repeatable CVE/AAA/compliance audits.

Tech Stack

FastAPI, SQLAlchemy, Netmiko, pyserial, Jinja2, OpenAI SDK, Next.js 16 (TypeScript), Tailwind CSS, Electron, SQLite/PostgreSQL, Docker Compose, uv/Ruff/pytest.

Screenshots

View Preview
Dashboard Dashboard
Switches Switches
Configs Configs
Templates Templates
AI chat AI chat
Workflows Workflows
Security Security
Topology Topology
Metrics Metrics
API docs API docs

Project Structure

NetCore/
├── backend/                 # FastAPI app (routers, services, models)
├── frontend/                # Next.js dashboard
├── desktop/                 # Electron desktop packaging
├── scripts/                 # cli.py + helper scripts
├── templates/               # Config templates
├── docker-compose.yml       # Backend + frontend deployment
├── manifest.json            # Repo metadata
├── pyproject.toml           # Ruff + pytest config
├── install.sh / install.ps1
└── docs/                    # Architecture + assets

Contributing

Contributions are welcome. Please read CONTRIBUTING.md and CODE_OF_CONDUCT.md, then open an issue or a pull request.

License

MIT — see LICENSE.

Connect

About

AI-powered network switch management — multi-vendor SSH + serial, Jinja2 templates, Hermes AI, security auditing.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages