Skip to main content

Lanweave

CI License Latest release

Lanweave logo

Lanweave is a local-first, open-source toolkit for managing and observing UniFi Network controllers. It turns a controller into a small, reviewable GitOps project without requiring a cloud service.

The name is intentionally independent from the controller vendor. Lanweave is not affiliated with, endorsed by, or sponsored by Ubiquiti Inc. UniFi is a trademark of Ubiquiti Inc.

Why Lanweave?

Lanweave is aimed at operators who want a safe middle ground between clicking through a controller UI and adopting a complete infrastructure platform:

  • declare networks and WLANs in YAML;
  • validate locally before contacting the controller;
  • inspect a deterministic, redacted plan;
  • apply only after explicit confirmation;
  • export a portable configuration without Wi-Fi passwords;
  • capture a local, secret-redacted backup;
  • expose the same read-only views to an MCP-compatible AI client.

The CLI is the primary interface. MCP is an optional read-only adapter, not a requirement and not a write path around the plan safety boundary.

Status

Lanweave 0.3.0 is the stable adapter and capability release. It preserves the local-first profile behavior tested against simulated controller responses, with read-only and authorized mutation evidence on one designated UniFi OS controller, and adds an explicit, read-only Site Manager cloud adapter. It targets the classic local UniFi Network API used by self-hosted UniFi Network applications and UniFi OS consoles; see compatibility and the apply recovery model for the exact scope, tested matrix and partial-failure behavior. The frozen public surfaces are described in contracts.

Supported resource families in this release:

  • networks;
  • WLANs, including references to environment-provided passwords;
  • local controller/site profiles with explicit target selection;
  • controller health, devices and clients;
  • redacted snapshots of common operational endpoints.

The cloud-site-manager adapter exposes only documented read-only hosts, sites, devices and derived site health. Run lanweave capabilities before selecting a target to inspect its supported operations.

Firewall, DNS, NAT, VPN and device mutation workflows are deliberately not included yet. They need their own fixtures, dependency rules and rollback story before being safe to expose.

Quick start

Requires Python 3.11+ and uv. Install the stable package from PyPI with:

uv tool install lanweave==0.3.0
lanweave --version

For a checkout and development environment:

uv sync --extra dev
uv run lanweave init
cp .env.example .env
uv run lanweave validate

See release verification for checksums, provenance and attestation verification.

Edit config/network.yaml and provide secrets only through the environment:

wlans:
  - name: Home
    ssid: Home
    network: Home
    security: wpapsk
    password_env: WIFI_HOME_PASSWORD

Use a local API key when possible. TLS verification is enabled by default; set UNIFI_VERIFY_TLS=false only when the controller's certificate cannot be verified and the risk is understood.

Command surface

lanweave init                    # create a generic config
lanweave doctor                  # check credentials and TLS settings
lanweave doctor --check          # also perform one health request
lanweave validate                # validate YAML locally
lanweave profiles list           # list sanitized local targets
lanweave profiles validate       # validate profiles without contacting UniFi
lanweave capabilities --output json # inspect selected adapter capabilities
lanweave export --out live.yaml # export secret-free desired-state YAML
lanweave plan                    # show create/update/delete operations
lanweave plan --output json      # machine-readable, redacted plan
lanweave apply                   # interactive, explicitly confirmed apply
lanweave apply --yes             # non-interactive apply after review
lanweave backup                  # write a 0600 redacted local snapshot
lanweave status                  # health and device summary
lanweave clients --filter phone  # connected-client view

--prune is opt-in. It never targets the controller's WAN or Default network, and it requires a separate DELETE confirmation in interactive mode. Non-interactive mutation requires --yes; there is no implicit apply. If an apply stops part-way through, review a fresh plan before retrying; see apply recovery.

MCP adapter

Install the optional dependency and run the server over local stdio:

uv sync --extra mcp
uv run lanweave-mcp

The server exposes health, devices, clients, secret-free export, local validation and redacted planning. It intentionally exposes no apply or delete tool. A desktop MCP client should launch lanweave-mcp from this checkout (or from the installed package) with the required UNIFI_* environment variables. The tool names, parameters and error codes are frozen in the MCP contract.

Configuration and credentials

Copy .env.example to .env, or export the variables in the process environment. .env is ignored by Git. API keys provide read-only access to the local Integration API; username and password session authentication are required for declarative mutations.

Lanweave rejects literal WLAN passwords in YAML and refuses unresolved op://... secret-manager references. This keeps the public configuration portable and makes the secret boundary explicit.

Development

uv sync --extra dev --extra mcp
uv lock --check
uv run ruff check .
uv run ruff format --check .
uv run pytest
uv build

Unit tests use simulated HTTP responses and never need a real controller. Hardware compatibility tests must run against disposable or explicitly designated controllers. See contributing, security and the design notes.

License

Apache-2.0. See LICENSE.

Project links

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

lanweave-0.3.0.tar.gz (141.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

lanweave-0.3.0-py3-none-any.whl (43.5 kB view details)

Uploaded Python 3

File details

Details for the file lanweave-0.3.0.tar.gz.

File metadata

  • Download URL: lanweave-0.3.0.tar.gz
  • Upload date:
  • Size: 141.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for lanweave-0.3.0.tar.gz
Algorithm Hash digest
SHA256 9b3a7e2266e178c6a2bce91279ad248177a1912cd07a71266d0afd04a244c8fb
MD5 53ecee03cb020d1b581a7e19540195e2
BLAKE2b-256 f64584fac40121c3f92b7d69b91fe80b4ac9bda413ef84845a58f497fc89b88a

See more details on using hashes here.

Provenance

The following attestation bundles were made for lanweave-0.3.0.tar.gz:

Publisher: release.yml on Opperiesen/lanweave

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file lanweave-0.3.0-py3-none-any.whl.

File metadata

  • Download URL: lanweave-0.3.0-py3-none-any.whl
  • Upload date:
  • Size: 43.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for lanweave-0.3.0-py3-none-any.whl
Algorithm Hash digest
SHA256 00ad475ecec4cd6a5260d30f4e91aef2842c16aa0f5eb88db2a56bd2ce5432fc
MD5 77f772fa98b6b317a1ce3cac4eb2855a
BLAKE2b-256 1e5ee728c690237e27ef6840e6d8abfea5cd23777238e1f5800ac2fb7764a4fc

See more details on using hashes here.

Provenance

The following attestation bundles were made for lanweave-0.3.0-py3-none-any.whl:

Publisher: release.yml on Opperiesen/lanweave

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page