Project

Every feature Ze ships.

51 shipped features plus the planned roadmap.

Each card's color is its category: how the feature fits into the system. Solid cards are shipped; dashed cards are experimental; blueprint cards at the bottom are specs, not code. Everything shipped runs in both daemon and appliance modes unless a card says otherwise. Click a category to filter, click again to show everything.

Built for demanding operators.

Ze starts with a configuration and protocol engine. The shipped network operating system adds BGP, interface management, FIB programming, plugins, operator tools, a minimal appliance runtime, and diagnostics as one product.

Automate

AI Tool Interfaces

MCP Generated AI tools
  • MCP exposes CLI/API commands
  • AI tools read structured output
  • Plugins expose discoverable tools
Operate

SSH CLI

Built-in SSH RBAC
  • Manage Ze without OS shell accounts
  • Profiles, audit, and accounting
  • commit, rollback, diff, completion
Operate

YANG Configuration

YANG ExaBGP
  • Schema-driven validation
  • One model feeds every surface
  • Plugin defined config and commands
Operate

Output Formatting

Shell-like pipes Offline
  • table, json, yaml, ndjson
  • match, count, first/last
  • Offline via ze format
Operate

Web Workbench

HTMX SSE
  • YANG-driven config tree
  • Same CLI grammar in browser
  • Live updates via SSE
Operate

Looking Glass

Routes Topology Birdwatcher
  • Peer and route viewer
  • Topology graph
  • SSE streaming for live state
Operate

System Readiness

ze doctor ze explain
  • Offline pre-start checks
  • Health, warnings, and errors
  • Structured remediation with ze explain
Routing

Native BGP Engine

BGP IPv4/IPv6 FlowSpec
  • Full implementation in Go
  • Lazy parsing, buffer-first encoding
  • Negotiated capabilities
Routing

Static Routes

ECMP BFD PBR
  • Named tables, policy routing
  • BFD-tracked failover
  • Multi-path ECMP groups
Routing

BFD

RFC 5880 Auth
  • Single-hop and multi-hop
  • GTSM, jitter, BGP integration
  • SHA1/MD5 auth, echo mode
Routing

MRT Recording

RFC 6396 Analysis
  • Updates, messages, RIB snapshots
  • Strftime file rotation
  • Show, inject, replay, filter
Services

DNS Resolver

Cache Pipes
  • Built-in cached resolver
  • | resolve and | origin pipe operators
  • No external daemon needed
Automate

Plugin System

ExaBGP RPKI Policy
  • Plugins add commands, RPCs, events
  • YANG roots join CLI and web
  • Independent, composable
Automate

Programmable

REST gRPC gNMI
  • REST API, gRPC, gNMI
  • Shared engine for identical output
  • Automate from any language
Automate

AI-First Design

Self-describing Skills
  • Self-describing command catalogue from the live binary
  • Every command is an automation surface
  • Structured diagnostics and repair plans
Automate

MCP Integration

MCP OAuth 2.1
  • Streamable HTTP transport, OAuth 2.1 resource server
  • Server-initiated elicitation, task-augmented tool calls
  • MCP Apps UI with embedded panels
Automate

ExaBGP Compatibility

Migration Bridge
  • Automatic config migration
  • Plugin bridge for existing workflows
  • Migration path for existing scripts
Observe

Evidence Over Claims

Fuzz Interop Docker
  • Unit, functional, fuzz, chaos
  • Performance benchmarks
  • Interop vs FRR, BIRD, GoBGP
Observe

Development Activity

Heatmap Live data
  • A year of commits and added lines, at a glance
  • Built from git history each time
  • Current Go code composition
Observe

Prometheus Telemetry

Netdata Prometheus
  • 138 metrics from /proc and /sys
  • Netdata naming, drop-in replacement
  • Existing Grafana dashboards keep working
Observe

Health Registry

HTTP 503
  • /health HTTP endpoint
  • Per-component status checks
  • BGP, FIB, IPsec, L2TP, VPP
Observe

Host Inventory

CPU NIC SMART
  • CPU, NIC, DMI, memory, thermal
  • SMART disk health and self-tests
  • JSON output for pipelines
Observe

Crash Capture

Panic Syslog
  • Automatic panic stack traces
  • Ring buffer context (last 64 entries)
  • show crashes CLI command
Observe

Tech-Support Bundle

Offline JSON
  • 20 modules, pure Go, no shell-outs
  • Structured JSON per module
  • Privacy-by-default, gokrazy-safe
Observe

Production Diagnostics

CLI MCP
  • 11 built-in tools replacing ss, dmesg, lsof
  • tcpdump, traceroute, ping, mtr
  • All exposed via MCP for AI debugging
Secure

Secure by Default

SSH RBAC RPKI ASPA
  • SSH access to the CLI
  • RPKI route origin validation
  • No other daemons needed
Secure

TACACS+ AAA

RFC 8907 Accounting
  • SSH login via TACACS+
  • Command accounting START/STOP
  • Server failover, local fallback
Secure

Audit Trail

Commits Auth
  • Config commit, discard, and reload
  • Failed auth on every interface
  • Filter by action, actor, and time
Secure

PKI Store

X.509 TLS
  • YANG-modelled certificate management
  • Chain validation, expiry checks
  • Shared by IPsec, TLS, mutual auth
Platform

Minimal Appliance Mode

Appliance Server
  • Kernel, init, Ze runtime
  • No package manager or general shell
  • ISO/PXE bare-metal install
  • Linux server with systemd
Platform

Runs Itself

Update Systemd
  • Binary self-update
  • Built-in readiness checks
  • No orchestrator needed
Platform

Docker Support

Daemon only Scratch Compose
  • Static binary on scratch base
  • Compose support included
  • Optional build tags
Platform

Feature Gates

36 subsystems Default on
  • Compile out whole subsystems, BGP included
  • Smaller binary, smaller attack surface
  • Config fails closed on blocks the build lacks

Experimental and growing.

Implemented and tested, still waiting for production evidence.

These still need deployment evidence or hardening before production claims. Configuration may change.

Services Experimental

IPsec VPN

IKEv2 X.509 EAP
  • Full IKEv2 engine, rekeying, DPD
  • NAT-T, keepalive, XFRM interfaces
  • EAP-MSCHAPv2, EAP-TLS, road warrior
Services Experimental

L2TPv2 BNG

PPP RADIUS CQM
  • RFC 2661 LNS and LAC with PPP
  • RADIUS auth, accounting, CoA
  • CQM monitoring, shaping, web UI
Services Experimental

PPPoE Access

RFC 2516 PPP
  • Access concentrator with discovery FSM
  • Shared PPP driver with L2TP
  • HMAC-SHA256 cookie, rate limiting
Services Experimental

Interface Management

Netlink DHCP
  • Ethernet, VLAN, bridge, WireGuard
  • 8 tunnel kinds, DHCP client
  • NTP sync, offload tuning, mirroring
Services Experimental

Firewall

nftables NAT
  • 15 match types, 19 actions
  • SNAT, DNAT, masquerade
  • FlowSpec-to-firewall bridge
Services Experimental

Policy Routing

nftables PBR
  • L3/L4 match criteria
  • Table steering, next-hop actions
  • TCP-MSS clamping, interface wildcards
Services Experimental

VPP Data Plane

DPDK GoVPP
  • FIB programming via GoVPP
  • MPLS label operations
  • Per-interface Prometheus metrics
Routing Experimental

MPLS / LDP / RSVP-TE

Labels Signaling
  • Kernel MPLS FIB, push/swap/pop
  • LDP discovery and sessions
  • RSVP-TE ERO, bandwidth admission
Routing Experimental

OSPFv2 / OSPFv3

RFC 2328 RFC 5340 ECMP
  • One ospf engine, IPv4 and IPv6 address families
  • SPF/ABR, NSSA, virtual links, NBMA/P2MP
  • Redistribution, SR, BFD, graceful restart
Routing Experimental

IS-IS

ISO 10589 Dual-stack
  • L1/L2 link-state IGP over Layer 2
  • RFC 5304/5310 authentication, key chains
  • Dual-stack IPv6, redistributes with BGP
Routing Experimental

VRRP

RFC 9568 RFC 3768 Virtual MAC
  • First-hop gateway redundancy, IPv4 and IPv6
  • Per-group virtual-MAC macvlan for L2 failover
  • keepalived interop, compile-out
Observe Experimental

Flow Export

sFlow NetFlow IPFIX
  • sFlow v5, NetFlow v9, IPFIX
  • Packet sampling, conntrack flows
  • BGP next-hop enrichment
Platform Experimental

ISO and PXE Install

PXE ISO
  • PXE bare-metal provisioning
  • Installer ISO media
  • Local systemd install and uninstall
Platform Experimental

Kernel Tunables

Sysctl Profiles
  • Three-layer precedence
  • Named profiles (DSR, router, hardened)
  • Originals restored on stop
Services Experimental

AS112 Anycast DNS

AS112 Anycast
  • Authoritative sink zones on four fixed anycast addresses (RFC 7534/7535)
  • Conditional BGP origination via healthcheck-gated watchdog
  • Anycast IPs bound on lo automatically, never operator-typed
Routing Experimental

Segment Routing

SAFI 73 SRv6
  • SR-Policy NLRI (RFC 9830), SAFI 73
  • MPLS and SRv6 binding SID, tunnel encap
  • ExaBGP bridge for SR-Policy migration
Automate Experimental

Fleet Management

Managed config TLS hub
  • Per-client configuration and authentication
  • Cached config with reconnect and heartbeat
  • Version hashing and two-phase fetch
Secure Experimental

IRR Route Filtering

IRR as-set
  • Prefix-lists from IRR data, live in the engine
  • Sourced from PeeringDB and RADB
  • Opt-in per peer, group or global filter chain

Specified, not built.

Aspirations with written, reviewed specs. Nothing here is usable today.

Every card links to a pending spec in the main repo's plan/ directory. Captured intent moves from skeleton, to design, to ready, to in progress. A spec is deleted only when the work ships.

Routing Spec'd

OSPF L3VPN PE-CE

RFC 4576 RFC 4577 L3VPN
  • PE-CE DN bit loop prevention
  • Domain ID, route type, VPN route tag
  • Blocked on VRF/MPLS L3VPN infrastructure
Routing Spec'd

VRF

VRF L3VPN
  • VRF as a first-class concept
  • Per-VRF BGP stacks, YANG config
  • Kernel VRF devices, table binding
Secure Spec'd

Kernel Lockdown

Lockdown Integrity
  • Kernel lockdown integrity mode
  • Blocks unsigned modules, kexec, /dev/mem
  • Design reviewed, waiting for schedule
Platform Spec'd

Cloud-Init Provisioning

Cloud-init User-data
  • Appliance identity from cloud metadata
  • SSH keys and config via user-data
  • No pre-baked seed image needed