From CLI to deployed tool: ReclaimNet gets an API and a face
The engine worked from a terminal. Turning it into something a team can actually run meant wrapping it in a secured REST API and a review-then-apply web GUI — without ever letting it write to your source of truth unattended.
The first version of ReclaimNet lived in a terminal. You pointed it at a prefix, it collected evidence, scored liveness, and printed its verdicts. That was enough to prove the idea — but a tool only one person can run from their laptop isn’t a tool a team can trust.
This is the story of the second half: giving the engine an API and a face, so it runs as a service, configures from a browser, and never touches your source of truth without a human saying yes.
An API around the engine, not bolted through it
The scoring core stayed exactly as it was. The API wraps it — a thin, secured REST layer over the same engine that ran on the command line. Collectors, targets, scores, and the NetBox reconciliation became endpoints; nothing about how liveness is judged had to change.
Secured first, not later. The API authenticates every request, and the destructive operations — anything that writes back to NetBox — sit behind an explicit, separate step. The engine can read and score freely. It cannot change your records on its own.
A face: configure it from the browser
The GUI exists to kill the config file. Before, running ReclaimNet meant editing YAML and SSH-ing onto a box. Now collectors, prefixes, credentials, and schedules are all set from the browser. The barrier to pointing it at a new segment dropped from “edit a file, redeploy” to “fill in a form.”
It’s deliberately plain. This isn’t a dashboard to live in — it’s a control surface you visit, set up, and check on. The interesting work is still the scoring; the GUI just makes it reachable.
Review-then-apply: the part that matters
The whole design rests on one rule: the tool informs; a human decides. ReclaimNet never writes to NetBox automatically.
When it has verdicts to commit — a documented host it’s now confident is dead, or an undocumented one it found alive — it stages them as a proposed change set. You see exactly what it wants to write, IP by IP, before anything happens. Approve, and it applies. Decline, and nothing changes.
- Every write is previewed. No silent edits to your source of truth.
- Changes are explained. Each proposed write carries the evidence and confidence behind it.
- Nothing is automatic. A person approves every change before it touches NetBox.
Packaged to install in minutes
All of it ships as Docker images. A compose file brings up the API and the GUI together; point it at NetBox, open the browser, and you’re configuring collectors a few minutes later. No build step, no dependency hunt — the same deal as everything else out of Nimentus: useful on day one.
ReclaimNet went from a script that proved a point to a service a team can run, with a human in the loop on every change. That’s the line between a clever experiment and a tool you’d actually trust against your source of truth.
Fino alla fine.
ReclaimNet is open source — the engine, the API, and the GUI. If you run NetBox, it’s built to tell you which of your “active” IPs are actually ghosts.