Nimentus
← Writing
Jun 2026ReclaimNet · build in public

From CLI to deployed tool: ReclaimNet gets an API and a face

The engine worked from a terminal. Turning it into something a team can actually run meant wrapping it in a secured REST API and a review-then-apply web GUI — without ever letting it write to your source of truth unattended.

The first version of ReclaimNet lived in a terminal. You pointed it at a prefix, it collected evidence, scored liveness, and printed its verdicts. That was enough to prove the idea — but a tool only one person can run from their laptop isn’t a tool a team can trust.

This is the story of the second half: giving the engine an API and a face, so it runs as a service, configures from a browser, and never touches your source of truth without a human saying yes.

An API around the engine, not bolted through it

The scoring core stayed exactly as it was. The API wraps it — a thin, secured REST layer over the same engine that ran on the command line. Collectors, targets, scores, and the NetBox reconciliation became endpoints; nothing about how liveness is judged had to change.

Secured first, not later. The API authenticates every request, and the destructive operations — anything that writes back to NetBox — sit behind an explicit, separate step. The engine can read and score freely. It cannot change your records on its own.

ReclaimNet dashboard showing live liveness verdicts
The dashboard — live verdicts at a glance, one host scored dead against an active NetBox record.

A face: configure it from the browser

The GUI exists to kill the config file. Before, running ReclaimNet meant editing YAML and SSH-ing onto a box. Now collectors, prefixes, credentials, and schedules are all set from the browser. The barrier to pointing it at a new segment dropped from “edit a file, redeploy” to “fill in a form.”

It’s deliberately plain. This isn’t a dashboard to live in — it’s a control surface you visit, set up, and check on. The interesting work is still the scoring; the GUI just makes it reachable.

Review-then-apply: the part that matters

The whole design rests on one rule: the tool informs; a human decides. ReclaimNet never writes to NetBox automatically.

When it has verdicts to commit — a documented host it’s now confident is dead, or an undocumented one it found alive — it stages them as a proposed change set. You see exactly what it wants to write, IP by IP, before anything happens. Approve, and it applies. Decline, and nothing changes.

  • Every write is previewed. No silent edits to your source of truth.
  • Changes are explained. Each proposed write carries the evidence and confidence behind it.
  • Nothing is automatic. A person approves every change before it touches NetBox.
ReclaimNet review-then-apply panel showing proposed NetBox writes awaiting approval
Review-then-apply — every NetBox write is shown and approved by a human first.

Packaged to install in minutes

All of it ships as Docker images. A compose file brings up the API and the GUI together; point it at NetBox, open the browser, and you’re configuring collectors a few minutes later. No build step, no dependency hunt — the same deal as everything else out of Nimentus: useful on day one.

ReclaimNet went from a script that proved a point to a service a team can run, with a human in the loop on every change. That’s the line between a clever experiment and a tool you’d actually trust against your source of truth.

Fino alla fine.

ReclaimNet is open source — the engine, the API, and the GUI. If you run NetBox, it’s built to tell you which of your “active” IPs are actually ghosts.