Lanweave
Lanweave is a local-first, open-source toolkit for managing and observing UniFi Network controllers. It turns a controller into a small, reviewable GitOps project without requiring a cloud service.
The name is intentionally independent from the controller vendor. Lanweave is not affiliated with, endorsed by, or sponsored by Ubiquiti Inc. UniFi is a trademark of Ubiquiti Inc.
Why Lanweave?
Lanweave is aimed at operators who want a safe middle ground between clicking through a controller UI and adopting a complete infrastructure platform:
- declare networks and WLANs in YAML;
- validate locally before contacting the controller;
- inspect a deterministic, redacted plan;
- apply only after explicit confirmation;
- export a portable configuration without Wi-Fi passwords;
- capture a local, secret-redacted backup;
- expose the same read-only views to an MCP-compatible AI client.
The CLI is the primary interface. MCP is an optional read-only adapter, not a requirement and not a write path around the plan safety boundary.
Status
Lanweave 0.5.0 is the stable local firewall resource release. It preserves
the local-first profile behavior tested against simulated controller responses,
with read-only and authorized mutation evidence on one designated UniFi OS
controller, adds an explicit, read-only Site Manager cloud adapter, and
manages local DNS policies through the official Integration API. It
targets the classic local UniFi Network API used by self-hosted UniFi Network
applications and UniFi OS consoles; see compatibility
and the apply recovery model for the exact scope, tested
matrix and partial-failure behavior. The frozen public surfaces are described
in contracts.
Supported resource families in this release:
- networks;
- WLANs, including references to environment-provided passwords;
- local DNS
A,AAAAandCNAMErecords; - local firewall zones, address groups, port groups and ordered rules;
- local controller/site profiles with explicit target selection;
- controller health, devices and clients;
- redacted snapshots of common operational endpoints.
The firewall family is limited to the documented local API-key Integration API surface. See firewall, compatibility and the v0.5 roadmap for the exact support boundary.
The cloud-site-manager adapter exposes only documented read-only hosts,
sites, devices and derived site health. Run lanweave capabilities before
selecting a target to inspect its supported operations.
NAT, VPN and device mutation workflows remain outside v0.5.0. They need their own fixtures, dependency rules and rollback story before being safe to expose.
Quick start
Requires Python 3.11+ and uv. Install the stable package from PyPI with:
uv tool install lanweave==0.5.0
lanweave --version
For a checkout and development environment:
uv sync --extra dev
uv run lanweave init
cp .env.example .env
uv run lanweave validate
See release verification for checksums, provenance and attestation verification.
Edit config/network.yaml and provide secrets only through the environment:
wlans:
- name: Home
ssid: Home
network: Home
security: wpa2
password_env: WIFI_HOME_PASSWORD
dns:
- name: printer.home.arpa
type: A
address: 192.0.2.10
ttl_seconds: 300
Use a local API key when possible. TLS verification is enabled by default;
set UNIFI_VERIFY_TLS=false only when the controller's certificate cannot be
verified and the risk is understood.
Command surface
lanweave init # create a generic config
lanweave doctor # check credentials and TLS settings
lanweave doctor --check # also perform one health request
lanweave validate # validate YAML locally
lanweave profiles list # list sanitized local targets
lanweave profiles validate # validate profiles without contacting UniFi
lanweave capabilities --output json # inspect selected adapter capabilities
lanweave export --out live.yaml # export secret-free desired-state YAML
lanweave plan # show create/update/delete operations
lanweave plan --output json # machine-readable, redacted plan
lanweave apply # interactive, explicitly confirmed apply
lanweave apply --yes # non-interactive apply after review
lanweave apply --acknowledge-risk # authorize reviewed firewall/NAT warnings
lanweave backup # write a 0600 redacted local snapshot
lanweave status # health and device summary
lanweave clients --filter phone # connected-client view
--prune is opt-in. It never targets the controller's WAN or Default
network, skips system/unknown-origin DNS policies, and requires a separate
DELETE confirmation in interactive mode.
Firewall and NAT changes with broad, external, privileged-port, shadowing,
reorder or exposure warnings additionally require --acknowledge-risk (the
legacy --acknowledge-firewall-risk alias remains accepted) or the exact
interactive acknowledgement. The flag does not bypass the plan or prune
confirmation.
Non-interactive mutation requires --yes; there is no implicit apply.
If an apply stops part-way through, review a fresh plan before retrying; see
apply recovery.
MCP adapter
Install the optional dependency and run the server over local stdio:
uv sync --extra mcp
uv run lanweave-mcp
The server exposes health, devices, clients, secret-free export, local
validation and redacted planning, including supported NAT state through export
and plans. It intentionally exposes no apply or delete tool. A desktop MCP
client should launch lanweave-mcp from this checkout (or
from the installed package) with the required UNIFI_* environment variables.
The tool names, parameters and error codes are frozen in
the MCP contract.
Configuration and credentials
Copy .env.example to .env, or export the variables in the process
environment. .env is ignored by Git. API keys provide read-only access to
networks and WLANs through the local Integration API, plus the documented DNS
policy create/update/delete endpoint. Username and password session
authentication remains required for network, WLAN and supported NAT mutations.
Lanweave rejects literal WLAN passwords in YAML and refuses unresolved
op://... secret-manager references. This keeps the public configuration
portable and makes the secret boundary explicit.
Development
uv sync --extra dev --extra mcp
uv lock --check
uv run ruff check .
uv run ruff format --check .
uv run pytest
uv build
Unit tests use simulated HTTP responses and never need a real controller. Hardware compatibility tests must run against disposable or explicitly designated controllers. See contributing, security and the design notes.
License
Apache-2.0. See LICENSE.
Project links
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file lanweave-0.6.0.tar.gz.
File metadata
- Download URL: lanweave-0.6.0.tar.gz
- Upload date:
- Size: 217.7 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
83ce79933c30adcb9a9015756f5893a8828d45929983741ac60ce02b8e5817d3
|
|
| MD5 |
bd7798337adfe5015274a0022f21e15a
|
|
| BLAKE2b-256 |
d90e32fa6639fce600c10f48d36883354e0855b3bb01d13300f9d718dee5e63a
|
Provenance
The following attestation bundles were made for lanweave-0.6.0.tar.gz:
Publisher:
release.yml on Opperiesen/lanweave
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
lanweave-0.6.0.tar.gz -
Subject digest:
83ce79933c30adcb9a9015756f5893a8828d45929983741ac60ce02b8e5817d3 - Sigstore transparency entry: 2480023567
- Sigstore integration time:
-
Permalink:
Opperiesen/lanweave@ae0ed8c71401684b64b06dc41ffde0ae52330952 -
Branch / Tag:
refs/tags/v0.6.0 - Owner: https://github.com/Opperiesen
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@ae0ed8c71401684b64b06dc41ffde0ae52330952 -
Trigger Event:
push
-
Statement type:
File details
Details for the file lanweave-0.6.0-py3-none-any.whl.
File metadata
- Download URL: lanweave-0.6.0-py3-none-any.whl
- Upload date:
- Size: 75.5 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
2144ecf5597f35785dc5742bae5d7947b496cb6ce24d7b9b4f4019222e99d610
|
|
| MD5 |
c3ab6e0c6f3bf8ba2d47b2cd25911cae
|
|
| BLAKE2b-256 |
5bb4ed7247ff871c9ea85fa7a3a4ed1e958b73b7d515b727a8ebd297eb3c3273
|
Provenance
The following attestation bundles were made for lanweave-0.6.0-py3-none-any.whl:
Publisher:
release.yml on Opperiesen/lanweave
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
lanweave-0.6.0-py3-none-any.whl -
Subject digest:
2144ecf5597f35785dc5742bae5d7947b496cb6ce24d7b9b4f4019222e99d610 - Sigstore transparency entry: 2480023793
- Sigstore integration time:
-
Permalink:
Opperiesen/lanweave@ae0ed8c71401684b64b06dc41ffde0ae52330952 -
Branch / Tag:
refs/tags/v0.6.0 - Owner: https://github.com/Opperiesen
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@ae0ed8c71401684b64b06dc41ffde0ae52330952 -
Trigger Event:
push
-
Statement type: