Release
Circuit Breaker v0.3.0
Install this version
curl -fsSL https://raw.githubusercontent.com/BlkLeg/CircuitBreaker/main/install.sh | sudo bash -s -- --version 0.3.0Or pick any method on the download page. The installer verifies every download against the release's checksums.
Downloads
x86_64 (amd64)Your machine
ARM64 (aarch64)Your machine
Checksums, signing key, SBOMs and other files
Checksums
Release signing key
Software bills of materials
Build manifests
Install scripts
- install.sh 14.3 KB
- setup.sh 14.3 KB
From the GitHub release
Tag: v0.3.0
Circuit Breaker v0.3.0
April 3, 2026 · Previous release: v0.2.8
v0.3.0 is a discovery-focused release. The scanner has been significantly upgraded with a built-in OUI knowledge base, smarter host identification, L0 (non-root) scan capabilities, and the first foundations for mobile device awareness. Discovered devices now import into the topology map with automatic relationships and role-aware positioning rather than landing as isolated, unconnected nodes.
🔍 Smarter Scanner — OUI Knowledge Base
Circuit Breaker now ships with an on-device OUI knowledge base. Every MAC address found during a scan is resolved to a vendor and cross-referenced against a hostname table built up over prior scans. Results are richer out of the box — no external lookups, no round-trips.
- Vendor name resolved directly from MAC OUI
- Hostname hints carried forward from previous scan results
- Scan ETA replaced with time elapsed — a more reliable indicator during variable- length nmap passes
- nmap progress bar is now visually responsive to actual probe completion
🕵️ L0 Scanning — No Root Required
Circuit Breaker can now perform a meaningful Layer 0 network scan without elevated
privileges. TCP connect scanning, banner grabbing, and OUI resolution all work under a
standard user account. ARP scanning remains opt-in (disabled by default) and still
requires NET_RAW on Linux.
📱 Mobile Device Detection
Devices advertising randomized MAC addresses — phones, tablets, and laptops in privacy mode — are now flagged as probable mobile devices rather than being silently misidentified as unknown hardware. Mobile discovery behavior is configurable in Settings → Discovery.
🌐 Network Topology Import
Discovered devices no longer arrive as an unconnected cloud of nodes. Circuit Breaker now:
- Infers primary nodes from IP address heuristics (gateway/lowest-host detection)
- Assigns roles at the review queue — the device’s position in the inferred hierarchy sets its initial topology role (router, switch, endpoint)
- Imports with default relationships — discovered peers are linked automatically when LLDP or ARP data confirms adjacency
- Defaults to Tree layout for network-scan imports — produces a readable hierarchy rather than a force-directed hairball on first load
- Persists ad hoc connections — manually drawn edges survive re-sync, reaching near-parity with the Proxmox import experience
🔗 LLDP Physical Topology
Switches and routers that advertise LLDP now surface their neighbor table in the scan results. Port-level adjacency data is stored and feeds directly into the automatic relationship import, giving you a physical wiring map without manual edge drawing.
🔧 OPNsense Integration (Foundation)
The groundwork for OPNsense integration is in place. Circuit Breaker can now store OPNsense connection credentials and will use a read-only API user to enrich scans with DHCP lease and ARP table data — surfacing hostnames and IPs that nmap alone would miss. Full active polling will be wired in a follow-up release.
🖧 Hardware Connection Mapping
Physical port topology is now first-class:
- Hardware entities track connection ports (interface names, types, speeds)
- Peer connections carry a connection type (copper, fibre, DAC, etc.)
- A hardware placeholder flag lets you pre-populate a device in the topology before the physical hardware arrives — useful for planned racks and pre-staged diagrams
- A device roles table (DB-backed) replaces the hardcoded role enum, making roles user-extensible without a code change
🐛 Bug Fixes
- Fixed Proxmox integration failing to connect when the host is configured with an FQDN or HTTPS rather than a bare IP
- Fixed nginx SSL termination on fresh installs under certain certificate configurations
- Fixed migration reruns throwing duplicate-table errors on existing installations
- Fixed silent failures in several frontend async paths that were swallowing errors without surfacing them to the user
⬆️ Upgrading
No manual steps required. All schema changes are additive and run automatically on startup.
docker compose pull && docker compose up -d
Native install:
curl -fsSL https://raw.githubusercontent.com/BlkLeg/circuitbreaker/main/install.sh | bash -s -- --upgrade
Note for ARP scanning users: ARP scanning is now disabled by default. If you rely on it, re-enable it after upgrading in Settings → Discovery → ARP Scanning.
📦 Docker
# Pull latest
docker compose pull && docker compose up -d
Image: ghcr.io/blkleg/circuitbreaker:v0.3.0
Digest: (populated automatically by GitHub Actions on publish)
What’s Coming in v0.4.0
- Rack Editor Phase 2 — cable management, rear view toggle, PNG/PDF export
- OPNsense active polling — live DHCP/ARP enrichment fully wired
- LLDP topology UI — visualize port-level adjacency directly on the map
- Device roles management — UI to create, rename, and reorder roles
- Proxmox observability — sync/poll health surfaced in the Proxmox integration tab
⚠️ Beta Notice — Circuit Breaker has not yet undergone a full security audit. Run it on a trusted local network only. Do not expose it directly to the public internet.
Full changelog: v0.2.8...v0.3.0


