Open-source network operations

Network control.
Without the noise.

Portivo brings compatible ALE OmniSwitch fleets into one clear operational workspace for finding devices, diagnosing ports, executing controlled actions and preserving evidence.

Repository PlannedExplore the docs →
AGPL-3.0AOS 6 + AOS 8Windows + LinuxSelf-hosted
PORTIVO / CONTROL CENTERLIVE
Portivo dashboard, live ports and administration interface
FLEET STATUS OperationalLive evidence across every managed site
42K+Source linesMeasured official package
99Code filesApplication and tooling
6Implementation technologiesPython · JS · HTML · CSS · PS · SH
149Catalog actionsRead and controlled change
ONE OPERATIONS WORKSPACE

Built around real network work.

Portivo combines the tasks operators repeat every day while keeping device access, authorization, execution and evidence inside one consistent control path.

01

Know the estate

Maintain a central switch inventory organized by Site and Group. Track management identity, AOS family, availability, stack context and the latest observed state without storing shared credentials for normal user operations.

02

See the physical edge

Open a logical front panel with administrative state, carrier, alias, VLAN, media and PoE information. Supported stack members remain separate so the interface map reflects the actual chassis.

03

Resolve endpoint questions

Search by MAC, IP, hostname, UNP identity or VLAN. Correlate ARP, forwarding, UNP and LLDP evidence, then rank likely edge locations without presenting an upstream observation as a physical endpoint.

04

Diagnose before changing

Collect read-only link, media, error, PoE, MAC, UNP and neighbor evidence for one port. Unknown device output remains unreported instead of being converted into an unsupported conclusion.

05

Execute with boundaries

Resolve actions against the detected AOS family, preview exact target commands, serialize work per switch and preserve a Job record for every target. Different switches can proceed concurrently without overlapping work on one device.

06

Operate beyond switches

Monitor assigned UPS infrastructure through SNMPv3, route confirmed incidents to independent destinations and correlate switch loss with power evidence only when the available telemetry supports it.

THE OPERATIONAL LOOP

From signal to certainty.

One continuous workflow keeps the target, evidence, command preview, execution and audit history connected.

01Find

Locate an endpoint

Search by MAC, IP, hostname, UNP identity or VLAN and correlate live fleet evidence.

→
02Diagnose

Understand the port

Inspect link state, media, counters, PoE, LLDP, MAC and recent activity in one read-only view.

→
03Act

Execute with control

Preview verified catalog actions, choose targets explicitly and keep work inside per-device queues.

→
04Audit

Preserve the evidence

Connect jobs, audit history, fleet findings and PDF reports to the action that created them.

BUILT FOR OPERATORS

The tools that move work forward.

Deep operational support without turning every task into a collection of disconnected utilities.

LP

Live Port Operations

A logical front panel with live state, VLAN, media and controlled port actions.

Learn more →
FD

Find Device

Evidence-led endpoint location with live SSH correlation and edge-port ranking.

Learn more →
FA

Fleet Audits

Nine read-only operational assessments with conservative evidence handling.

Learn more →
AU

Automation

Approved runbooks, variables, target limits, concurrency policy and schedules.

Learn more →
AC

Access Control

Built-in and custom roles with exact capabilities and server-enforced scope.

Learn more →
PW

Power Awareness

SNMPv3 UPS telemetry, incidents and protected-switch correlation.

Learn more →
INTERACTIVE SSH TERMINAL

A full switch console.
Inside the browser.

Portivo also covers the role normally handled by a separate desktop SSH client. Authorized engineers can open a persistent interactive terminal to a scoped switch, work directly with the native AOS CLI and keep device access inside the same secure operational workspace.

  • Personal SSH identityThe terminal uses the signed-in engineer's active SSH session, not a shared operational password.
  • Live, responsive consoleWebSocket transport carries interactive input and output and supports terminal resize events.
  • Device-level coordinationThe terminal and automated Jobs share one per-device lane, preventing overlapping work on the same switch.
  • Controlled accessBackend checks enforce terminal permission and Site or Group scope before the SSH connection opens.
Explore the interactive terminal →
PORTIVO TERMINALCONNECTED

switch-01 login established

> show system

System name: switch-01
AOS family: AOS 8
Operational state: UP

> show interfaces status

Native CLI output streams directly
through the protected browser session.

>

PERSONAL SSH SESSIONDEVICE LANE ACTIVE
CONTROLLED EXECUTION

Every action has a visible lifecycle.

Manual work, automation and audits use the same durable execution model, so operators can distinguish intent, progress, result and configuration persistence.

1

Select

Choose an eligible action, explicit devices and only the parameters required by that action.

2

Preview

Review target-specific commands, compatibility evidence and the number of affected switches before execution.

3

Execute

Create a Job with one item per target. Per-device FIFO coordination prevents overlapping automated or terminal work.

4

Verify

Inspect output and terminal status, then use read-back evidence or a focused diagnostic to confirm the intended state.

5

Persist

Review pending configuration by switch and write to flash deliberately after operational validation.

COMPATIBILITY FIRST

Deep ALE support.
Deliberately focused.

Portivo treats AOS 6 and AOS 8 as independent command families, with dedicated driver identities, compatibility metadata and conservative runtime capability learning.

  • AOS 6 + AOS 8Separate command profiles, not fragile translation.
  • Per-device learningAvoid repeated incompatible attempts.
  • ALE-aware PoESlot-qualified status collection.
ARCHITECTURE / LIVE MAPv2.1.0
Browser UI
PORTIVO
APPLICATION
Authentication
RBAC + Scope
Jobs & Audits
Evidence trail
AOS Drivers
6 + 8
SSH → OmniSwitchSNMPv3 → UPSSQLite → State
A BETTER OPERATING MODEL

Move beyond isolated SSH sessions.

Direct CLI access remains essential. Portivo adds the shared context, safeguards and evidence needed to turn individual commands into a consistent operational process.

Portivo compared with manual SSH-only network operations
Operational requirementManual SSH workflowPortivo
Fleet inventoryLimited

Device lists and operational context are maintained across separate files and sessions.

Integrated

Switches, sites, groups, reachability and current observations share one workspace.

Endpoint locationManual

Engineers search devices one at a time and correlate results by hand.

Correlated

MAC, IP, hostname, UNP and VLAN evidence is searched across the authorized fleet.

Repeatable operationsVariable

Results depend on personal notes, command history and locally maintained scripts.

Catalog-driven

Verified actions define compatibility, required inputs, commands and execution rules.

Change previewOperator-led

Commands and targets are reviewed manually before each session.

Built in

Target-specific commands, compatibility evidence and scope are visible before execution.

Multi-device workScript-dependent

Concurrency, failures and partial completion require custom handling.

Controlled

Jobs, target limits, schedules and per-device queues coordinate fleet work safely.

Audit evidenceFragmented

Terminal history and personal records must be collected and retained separately.

Centralized

Jobs, outputs, activity history, findings and reports preserve operational evidence.

Access controlDevice-level

Authorization is commonly enforced independently on every switch.

Scoped RBAC

Roles, capabilities and Site or Group scope are enforced by the application.

Interactive CLIAvailable

Direct native access through a separate terminal client.

Integrated

A persistent browser terminal keeps native AOS CLI work inside the same controlled workspace.

Portivo complements native CLI expertise. It does not hide the network. It gives operators a consistent way to discover, diagnose, execute and prove what happened.

SELF-HOSTED DEPLOYMENT

Clear components.
Controlled ownership.

Portivo runs as one service on Windows or Linux. It is designed for a protected management network with direct reachability to managed switches and UPS devices.

Application service

A FastAPI service provides the browser interface, authenticated APIs, schedulers, monitoring workers and WebSocket terminal path.

  • Windows service or systemd service
  • Default application listener on TCP 8766
  • Health and build identity endpoints

Managed network paths

Manual and automated switch work uses SSH. Power monitoring uses authenticated and encrypted SNMPv3 profiles.

  • SSH to compatible AOS 6 and AOS 8 switches
  • SNMPv3 authPriv for supported UPS devices
  • HTTPS outbound delivery for configured webhooks

Persistent state

SQLite stores inventory, policy, Jobs, audit history, incidents and latest observations. Full traffic time series remain outside the product data model.

  • Streamed administrative backup
  • Controlled database import
  • Explicit retention and maintenance

Access boundary

Use a trusted reverse proxy for HTTPS and WebSocket forwarding. Restrict browser ingress to authorized management networks.

  • Do not expose TCP 8766 publicly
  • Trust forwarded headers only from known proxies
  • Protect database, secrets and backups
Planning a production deployment?

Start with requirements, network security and the complete installation sequence.

Open deployment guidance →
SECURITY BY DESIGN

Explicit trust boundaries.
Auditable by default.

Self-hosted control stays inside your management boundary, with deliberate safeguards around identity, credentials and action execution.

Read the hardening guide →
01

Personal SSH sessions

User SSH passwords are session-only and never become shared switch credentials.

02

Encrypted automation secrets

Unattended credentials and webhook endpoints are protected by the application secret.

03

Preview before execution

Operational changes remain tied to explicit targets, jobs and activity evidence.

DEPLOYMENT NOTE

Designed for trusted management networks. Terminate TLS at a trusted reverse proxy and never expose TCP 8766 directly to the public Internet.

FREQUENTLY ASKED QUESTIONS

Clear answers before deployment.

Essential product, compatibility and operational guidance for teams evaluating Portivo.

Explore complete documentation →
01Is Portivo genuinely self-hosted?

Yes. The application service, database, inventory, policy, jobs and audit records run inside infrastructure controlled by your organization. Portivo is designed for a protected management network and does not require a hosted control plane.

Review system requirements →
02Which switches are supported?

Portivo is deliberately focused on compatible Alcatel-Lucent Enterprise OmniSwitch environments running AOS 6 or AOS 8. The two command families use separate driver identities and compatibility metadata. Confirm exact device and action coverage before production use.

Review driver coverage →
03Does Portivo require an agent?

No software agent is installed on managed switches. Portivo communicates with compatible network devices over their existing management interfaces, subject to network reachability, credentials and the permissions configured by your organization.

04Does it use SSH or SNMP?

Switch discovery, diagnostics, operations, automation and the interactive terminal use SSH. UPS monitoring uses authenticated and encrypted SNMPv3 profiles. Each protocol has a defined purpose and security boundary.

Review network security →
05Can it operate without Internet access?

Core switch management can operate inside an isolated management network when the Portivo host can reach its managed devices. Features that contact external destinations, such as configured outbound webhooks, require the corresponding network path. Updates and external resources must be handled according to your environment.

06How are backups handled?

Authorized administrators can create a streamed backup of persistent application state and perform a controlled database import. Backups contain operationally sensitive information and must be encrypted, access-controlled, tested and retained according to organizational policy.

Read backup and restore guidance →
07Is Portivo suitable for production?

Portivo is designed for controlled operational use, but production readiness depends on correct deployment. Use a supported host, a trusted HTTPS reverse proxy, restricted management-network access, tested backups, least-privilege roles and validated device compatibility. Begin with read-only workflows and a limited pilot before enabling changes.

Open the hardening guide →
08How do I report a security issue?

Do not publish sensitive vulnerability details in a public issue. Review the security guidance first, then contact the project privately at info@portivo.org with a clear description, affected version, reproduction conditions and potential impact.

Open security documentation →
PORTIVO CONTROL CENTER 2.1.0

Operate the network.
Keep the evidence.

Explore installation, operations, automation, security, drivers and the complete reference.

Open documentation →Source repository Planned
↑