Exposure, tenancy and device-robustness fixes from the review (v0.24.47)
Outside review follow-up: P2-35, P2-23, P2-19, J4, P2-17, P2-20, P2-21, P2-4.
Exposure
- BIND_ADDRESS / NETFLOW_BIND_ADDRESS publish the UI and collector on one
host address (default unchanged: every interface). Docs: Network exposure,
including Docker bypassing ufw and DOCKER-USER rules. - NetFlow refuses flows from non-device sources by default on new installs;
existing installs keep their setting. Public sources are always refused.
NetFlow page: "Accept flows from unidentified exporters" switch (fleet
admins) and a list of refused sources.
Tenancy
- Serial numbers pinned and checked right after login; a different device at
the address stops the connection before anything is read or written, alerts,
and offers "This is the new device". - Neighbour resolution, MAC-scan IP fill, reverse DNS and discovery alerts
stay within the device's site. - NetFlow matches clients within the exporter's site and stores traffic per
site (Influx site_id tag, client_traffic_daily site_id). Traffic analytics
filters by site and is available to site-scoped accounts again. - Client rename/category/notes only touch records in writable sites; WoL
checks the client is in view; per-device counter deltas on client traffic. - Insight dismissals keyed by site view; dismissed list scoped.
- Report top clients no longer multiplied by the number of devices.
Device robustness
- Linear LTE carrier split and bounded roaming patterns; log messages and
topics capped. - Device strings fit their columns; per-row error handling in client and
wireless collectors. - Failed reads no longer delete clients, neighbours, STP, certificates, IP
cache or CAPsMAN inventory (RouterOSTrapError distinguishes "no such menu"
from a timeout). - Streaming cancel drains by tag until both !done replies arrive, else drops
the connection; a streaming deadline no longer poisons the connection.
Docs: configuration.md, traffic.md, sites.md, security.md, alerting.md.
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Container images (published once CI passes):
ghcr.io/2gt-media-group-llc/mikrotik-manager-backend:0.24.47-betaghcr.io/2gt-media-group-llc/mikrotik-manager-nginx:0.24.47-beta
Documentation: https://2gt-media-group-llc.github.io/mikrotik-manager/