Skip to main content

EXTENSIONS

User-built models, drivers, vaults, and reports — the parts that plug into swamp.

Filter by what you need and pull what fits.

Selection
22 results
label:networking

Netgear M4250

@dougschaefer/netgear-m4250 · v2026.05.31.1

Manage a NETGEAR M4250 (AV Line) managed switch over its SSH CLI — capture running-config and device facts, run verification show-commands (VLANs, ports, PoE, MAC table, LLDP, IGMP snooping), apply IGMP-querier and multicast-containment config, and force/restore a port's speed-duplex. Prompt-paced I/O for the M4250's interactive shell, vault-resolved credentials, shells out to OpenSSH.

upd May 310 pullsA100/100

Ruckus

@easel/ruckus · v2026.05.27.3

Sync a Ruckus Unleashed wireless controller into swamp as queryable data. The extension SSHes into the Unleashed master, drives its interactive CLI through a prompt-matching state machine (Unleashed accepts SSH `none` auth and prompts for app-level login on the remote pty, so no `sshpass` or pty wrapper is required), and writes one resource per controller, access point, and WLAN.

upd May 2710 pullsB85/100

Kubernetes

@swamp/kubernetes · v2026.05.27.2

Kubernetes operational toolkit — 15 model types covering pods, deployments, services, RBAC, storage, networking, autoscaling, batch jobs, and more. Includes 14 ready-to-run workflows for namespace debugging, security audits, RBAC analysis, cluster health, and operational diagnostics.

upd May 2715 pullsA100/100

Luxul Switch

@dougschaefer/luxul-switch · v2026.05.27.1

Monitor a Luxul AMS-series managed switch (e.g. AMS-1208P) over SNMP v2c — device facts, per-port link/error telemetry, and PoE main-budget headroom. Built for AV-over-IP racks carrying Crestron NVX endpoints, where PoE budget and link health drive stream reliability. Read-only; vault-resolved SNMP community.

upd May 270 pullsA100/100

Azure

@dougschaefer/azure · v2026.05.27.3

Azure infrastructure management via az CLI — 31 model types covering compute, networking, data, security, RBAC, Azure Policy, Defender for Cloud, Entra directory, monitoring, DNS, DevOps, and subscription-wide topology with Mermaid diagrams and cost estimation.

upd May 2723 pullsA100/100

Opnsense Firewall

@dougschaefer/opnsense-firewall · v2026.05.27.2

Full OPNsense management via REST API — system status, interfaces, DNS, tunables, services, firmware/plugins, firewall states, DHCP leases, ARP table, Tailscale, WireGuard, and raw API passthrough. Replaces MCP server.

upd May 279 pullsA100/100

Eero Network

@dougschaefer/eero-network · v2026.05.27.1

Eero mesh WiFi management via cloud API — network health, per-node status, per-client band/signal/channel diagnostics, speed tests, settings management, and raw API passthrough. Reverse-engineered from the eero mobile app API.

upd May 277 pullsA100/100

Cisco Ios Switch

@dougschaefer/cisco-ios-switch · v2026.05.27.1

Manage a Cisco IOS switch (e.g. Catalyst 2960) over SSH after console bootstrap — capture running-config and device facts, run verification commands, and push idempotent baselines: secure-access hardening, SNMPv2c, and Layer-3/VLAN/access-port config. Shells out to OpenSSH; vault-resolved credentials; live reachability pre-flight check.

upd May 272 pullsA100/100

Tailscale

@keeb/tailscale · v2026.05.25.1

Install Tailscale on remote VMs over SSH and sync tailnet machine inventory from tailscale status JSON into per-machine resources.

upd May 252.4k pullsA100/100

Porkbun

@magistr/porkbun · v2026.05.25.1

Porkbun DNS record management with full CRUD for all common record types

upd May 251 pullsA100/100

Aws Cost Audit

@webframp/aws-cost-audit · v2026.05.24.1

AWS cost audit workflow — identifies infrastructure waste by combining

upd May 2425 pullsA100/100

Nginx

@keeb/nginx · v2026.05.23.1

Configure nginx as a TCP/UDP stream proxy on a remote host over SSH, with bootstrap and per-service proxy configuration.

upd May 2320 pullsA100/100

Dns Policy

@lint/dns-policy · v2026.05.22.1

DNS policy compiler — merge manual vhosts + auto-discovered proxy hosts + static rewrites into a deduped desired list for an internal-DNS reconciler (e.g. AdGuard Home), plus a separate hostname list for public exposure.

upd May 222 pullsA100/100

Nginx Proxy Manager

@lint/nginx-proxy-manager · v2026.05.21.2

Nginx Proxy Manager API wrapper — snapshot proxy hosts / redirection hosts / certificates, upsert proxy hosts idempotently (match by domain set), and delete proxy hosts by id.

upd May 214 pullsA100/100

Adguard

@lint/adguard · v2026.05.21.1

AdGuard Home control-API wrapper — snapshot status/stats/clients/rewrites and reconcile DNS rewrites to a desired set.

upd May 213 pullsA100/100

Pihole

@magistr/pihole · v2026.05.21.1

Pi-hole custom DNS record management for swamp — list, add, delete, and

upd May 214 pullsA100/100

Aws/networking

@webframp/aws/networking · v2026.05.20.1

Inspect VPC networking resources that commonly generate hidden costs:

upd May 2036 pullsA100/100

Ssh

@keeb/ssh · v2026.05.14.1

General-purpose SSH operations — exec, upload, wait for connection (https://github.com/keeb/swamp-ssh)

upd May 1514k pullsA91/100

Tailnet Healthcheck

@bixu/tailnet-healthcheck · v2026.04.23.2

Tailnet health reporting — find devices running outdated Tailscale clients and alert via Slack

upd Apr 233 pullsA100/100

Peplink

@ryan/peplink · v2026.04.10.1

Peplink router management — WAN status, cellular signal diagnostics, band/carrier scanning, SpeedFusion Connect monitoring, Starlink dish control, and raw API passthrough. Works with any Peplink router running firmware 8.5+.

upd Apr 101 pullsunscored

Ports

@keeb/ports · v2026.04.03.1

Scan listening ports with process, framework, project, uptime, and health enrichment — plus cleanup of orphaned listeners

upd Apr 33 pullsunscored

Tailscale

@john/tailscale · v2026.03.02.1

Tailscale tailnet management — 10 model types covering devices, users, ACLs, DNS, auth keys, webhooks, settings, contacts, posture, and log config. 22 workflows for device inventory, user lifecycle, ACL audit, security audit, compliance, incident response, monitoring, and more. Fix: OAuth token cache now keys on credentials so different tailnets/OAuth clients no longer share tokens.

upd Mar 222 pullsunscored