Skip to content

feat(canvas): add network terminal workflows and lazy loading (spec 131) - #275

Merged
automateyournetwork merged 3 commits into
automateyournetwork:mainfrom
AdamMason1877:131-canvas-terminal-workflows
Sep 28, 2026
Merged

automateyournetwork merged 3 commits into
automateyournetwork:mainfrom
AdamMason1877:131-canvas-terminal-workflows

Conversation

@AdamMason1877

Copy link
Copy Markdown

Problem and resulting behavior

Adds the NetClaw-focused browser terminal/Canvas workflows developed from the
JackRabbit-style investigation experience, plus the first optimization pass.
This does not add the standalone Electron desktop application.

Freshly fetched upstream main is 40425bb, which already includes the new
function-first HUD and standard Chat/Canvas/OpenClaw switch. This branch is built
on that commit and retains the dashboard, classic view and assessment/session
integration; no older HUD is being restored over the new one.

Included

  • Browser SSH terminal; explicit credentials/host-key handling and legacy-KEX opt-in.
  • Testbed add/edit/remove with revision checks, backups and active-session guards.
  • Terminal selection-to-branch workflow, validated artifacts and local pyATS/Genie JSON.
  • English intent with live execution evidence and explicit, scoped Local/Lab controls.
  • Authorized read-only topology collection, closest-device correlation, contained
    context panes and device/shared topology images with dynamic role markers.
  • Synthetic NetBox/SNOW demo and bounded opt-in Infoblox/ThousandEyes/Kubernetes/
    OTLP groundwork. VMware/ExtraHop remain planned, not claimed as implemented.
  • Modular terminal/backend code and on-demand windows: initial static Canvas JS
    872,406 → 339,917 bytes (~61% reduction). This defers loading, not feature deletion.
  • Web-service startup/parser setup scripts, documentation and synthetic tests.

Private testbeds, credentials, collected data, uploads, build output and the
standalone desktop application's history are excluded.

Numbered Spec Kit specification

Process disclosure: implementation predates these artifacts. They document an
existing contribution for adoption review, not historical spec-first compliance.
The checked-in templates were followed manually; the referenced .claude/commands/
files are absent from this checkout. Spec number/scope need maintainer agreement.

Why draft

Maintainer review is needed for direct browser/API SSH and provider adapters versus
the MCP-native architecture, and for the explicitly scoped Local/Lab audit policy.
Production approval gates and read-only collector scopes are retained. These are
proposed contributions, not declared constitutional exceptions.

Linux full-suite and authorized live acceptance remain outstanding. This is a
loopback, single-operator tool, not enterprise multi-user RBAC or a fleet-scale
distributed collector.

Release

Proposed completed-feature minor release: 1.2.0, to be coordinated against main.
No VERSION/changelog bump is made for this unapproved draft; release preparation
is an explicit task before marking ready/merging.

Validation

  • PASS: 27/27 Canvas suites (synthetic/mock fixtures only).
  • PASS: production build and complete static-import budget (<400 KB).
  • PASS: 10 Python installer mocks and one Genie adapter test.
  • PASS: spec artifacts, catalog coverage, contract manifest/list/matrix.
  • PASS: all six declaration reconciliation surfaces with PYTHONUTF8=1 on Windows.
  • FAIL, known baseline: full upstream suite 255 pass / 15 fail on Windows;
    same POSIX permission/symlink and URL-path failures reproduced on unchanged upstream.
  • Browser smoke: synthetic terminal renders, route context opens, Genie view opens.
  • No live routers/providers, model-backed configuration or actual pyATS install
    validated. Existing WSL unavailability is documented, not counted as a pass.

HUD CI now runs the Canvas family, Python mocks and bundle budget on Linux without
network-device credentials. Security checks were not disabled to make tests pass.

Compatibility, migration and risks

Existing Canvas schema and upstream access/session boundaries are retained.
No instance is restarted by the contribution. Back up operator state before
deployment; rollback by reverting the feature branch to the prior reviewed build.
New feature windows may not render in older builds. See the scope/feature docs
for state retention, authorization and provider limitations.

Contributor checklist

  • Spec existed before implementation and maintainer scope review is complete.
  • Draft spec, research, plan, tasks and verification describe the contribution.
  • Specification artifact and declaration reconciliation checks pass locally.
  • Full Linux and required live acceptance are complete.
  • New test family is registered and covered by the dedicated HUD workflow.
  • Architecture/policy exceptions and final release metadata are approved.
  • No personal credentials, private network configuration or customer topology included.
  • Compatibility and operational limitations are documented.

Adam added 3 commits September 28, 2026 14:37
…ient

Add SSH, structured Genie output, intent execution, topology enrichment, optional observability, and isolated runtime setup to the NetClaw Canvas. Preserve upstream dashboard/security behavior and exclude Electron history and personal inventory. Document validation and pre-existing Windows test limitations.
@automateyournetwork
automateyournetwork marked this pull request as ready for review September 28, 2026 21:28
@automateyournetwork
automateyournetwork merged commit e227ba4 into automateyournetwork:main Sep 28, 2026
26 of 27 checks passed
@automateyournetwork

Copy link
Copy Markdown
Owner

thanks again

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants