Network Probe
A headless discovery daemon that maps what is on a site network.
Category: Network
The Network Probe is Fireball's own discovery agent (probe and chart version 1.5.0). It runs on an edge node, looks for hosts on the subnets you give it, works out what each one probably is, and reports the devices and a topology snapshot back to EmberCORE.
Unlike EmberNet's industrial collectors, which only read what you configure, the probe sends traffic to every address in the subnets you list. List only networks where active discovery is permitted, and never a control network whose owner has not approved it.
What it does
Every scan cycle, five minutes apart by default, the probe:
- Sends ICMP echo requests across the subnets you listed, and reads the node's ARP table to match addresses to MAC addresses.
- Tries a TCP connection to ports 22, 80, 443, 502 (Modbus), and 4840 (OPC UA) on each host that answered.
- Fetches the page title from any web interface it found.
- If you gave it SNMP credentials, reads each host's SNMP system name, description, and object ID. That is a single read, never a write or a walk.
- Classifies each device from what it learned and reports the devices and the topology to EmberCORE.
It scans only what you give it. There are no default subnets. With an empty list the probe scans nothing at all and says so in its log. There is no default SNMP community either: without credentials, it sends no SNMP.
Optionally, it can also list the containers running on its host through the Podman or containerd socket. That is off by default.
When to use it
Use the probe to build a first inventory of a site you are bringing onto EmberNet, where it is acceptable to sweep the network. To monitor a device you already know about, add it in EmberCORE and use SNMP or an industrial collector instead.
Installing from the App Store
When you deploy the probe, the App Store asks for two things before it installs:
- Subnets. IPv4 subnets in CIDR form, such as
10.0.1.0/24, one per line. Nothing wider than/16is accepted; split a larger network into/16or narrower. Leave the list empty and the probe scans nothing. - SNMP. Off, v2c with a community string, or v3 with a username, a security level (noAuthNoPriv, authNoPriv, or authPriv), and the auth and privacy protocols and passphrases that level needs.
The App Store checks the subnets the same way the probe does, so a typo or an oversized range is caught before the install, not discovered later in a log.
The SNMP community string and v3 passphrases are kept in a Kubernetes Secret in your organization's namespace, never in the app's install values, where anyone who can read those values could read them.
Its own token, bound to your organization
Each probe you install from the App Store gets its own reporting token, issued
for your organization at install time. EmberCORE keeps only a hash of it, and
the token itself goes into the same Secret, <release>-probe-auth.
EmberCORE takes your organization from that token. A report that claims to be from any other organization is refused, and so is one that tries to write to a probe another organization already owns. Uninstalling the probe revokes its token and deletes the Secret. There is nothing to copy or set up by hand.
Running on EmberNet
- Headless. The probe listens on no port and has nothing to open; its card shows it running.
- Host network and raw sockets. It runs on the node's own network with the
NET_RAWandNET_ADMINcapabilities, because it needs layer 2 presence to see neighbors' MAC addresses. It is not privileged. - External clusters. A probe on a cluster you connected as an external tenant reports over Flux and needs a Flux identity, which the App Store cannot give it. The App Store therefore does not accept subnets or SNMP settings for a probe on an external cluster, and says why. Talk to Fireball to set one up there.
- Small footprint. It requests 50m of CPU and 64 MiB of memory.