nessi a911d36f34
CI / backend (push) Failing after 2s
CI / frontend (push) Failing after 30s
feat: add comprehensive CRUD endpoints, cluster sync improvements, and firewall orchestration
Add create endpoints for users, roles, tenants, projects, networks, subnets, and security rules with audit logging, implement commit_or_400 helper for IntegrityError handling with 409 responses, enhance cluster sync to populate nodes, workloads, and networks from provider inventory with last_sync_at tracking, add update/delete operations for IP addresses and policies with version tracking, implement IP
2026-07-09 12:33:36 +02:00

NexaFabric

NexaFabric is an open-source SDN-like network and security control plane for Proxmox VE environments. It runs as an external web application and provides inventory, IPAM, security groups, policy simulation, firewall previews, audit trails, and automation without patching Proxmox itself.

What Is Included

  • FastAPI backend with SQLAlchemy 2, Alembic-ready models, JWT auth, RBAC primitives, audit logging, and provider interfaces.
  • React + TypeScript frontend with Vite, Tailwind CSS, TanStack Query, React Router, Zustand, dark/light mode, and production-oriented pages.
  • PostgreSQL, Redis, worker, API, frontend, and reverse proxy through Docker Compose.
  • Demo seed data for clusters, nodes, workloads, networks, tenants, policies, IPAM, jobs, and audit events.
  • Tests, lint/type-check scripts, CI workflow, and operational documentation.

Quick Start

cp .env.example .env
docker compose up --build

Then open:

Demo login:

  • Email: admin@nexafabric.local
  • Password: ChangeMe_UseEnvInstead

Repository Layout

backend/       FastAPI API, models, services, worker entrypoint, tests
frontend/      React application, API client, pages, component tests
docs/          Architecture, operations, security, provider and API docs
nginx/         Reverse proxy example

Safety Model

NexaFabric never applies firewall changes without a preview, validation, and audit record. The included Proxmox provider is designed around read-only inventory first. Write-enabled orchestration is intentionally routed through explicit dry-run and apply workflows.

S
Description
No description provided
Readme
1.2 MiB
Languages
Python 51.6%
TypeScript 45.3%
Go 2.3%
CSS 0.3%
Shell 0.2%
Other 0.2%