π¨π΄ EspaΓ±ol
A universal Network Automation / DevNet / NetDevOps Docker image built to keep tooling consistent, portable, and production-ready β for both commercial and open-source NOS.
β Python Network Automation + β Ansible (pipx) + β Multi-vendor Collections + β Troubleshooting tools
π¦ Docker Hub: andersonmavi30/docker_network_automation π¦ GitLab mirror: gitlab.com/andersonmavi30/docker_network_automation
- Provide a single Docker image with common network automation tooling.
- Keep dependency isolation clean:
- Ansible via
pipx - Python libraries in
/opt/venv
- Ansible via
- Support multi-vendor automation workflows across commercial vendors (Cisco, Arista, Juniper, Aruba/HPE, Dell, Allied Telesis, Extreme, Huawei, HP/H3C) and open-source NOS (VyOS, Cumulus Linux, SONiC, FRRouting).
Note: As of v3.0.0 this image focuses on network switching/routing. Firewall vendors (Fortinet, Palo Alto, Check Point) were removed and will live in a dedicated image.
Includes libraries for:
- HTTP/API:
requests,httpx - CLI/SSH automation:
netmiko,scrapli - Network abstraction:
napalm - Orchestration:
nornir - NETCONF:
ncclient,scrapli-netconf - gNMI (SONiC / modern telemetry):
pygnmi - CLI parsing:
textfsm+ntc-templates(500+ multi-vendor templates) - Source of truth:
pynetbox - SNMP:
pysnmp - Testing:
pytest
- Ansible is isolated from the Python venv.
- Collections are installed from
collections.yml.
| Vendor | Collections | Platforms |
|---|---|---|
| Cisco | cisco.ios, cisco.nxos, cisco.asa |
IOS/IOS-XE, NX-OS, ASA |
| Arista | arista.eos |
EOS |
| Juniper | junipernetworks.junos |
Junos |
| Aruba / HPE | arubanetworks.aoscx, arubanetworks.aos_switch |
Aruba CX (8360, 6300, 6400...), ArubaOS-Switch / ProVision (2530, 2930, 5400R...) |
| Dell | dellemc.os10, dellemc.os9, dellemc.os6 |
SmartFabric OS10, legacy OS9, legacy OS6 (N-series) |
| Allied Telesis | alliedtelesis.awplus |
AlliedWare Plus (x220, x330, x530, x950...) |
| Extreme / Huawei / HP-H3C | community.network |
EXOS (exos_*), CloudEngine (ce_*), Comware (comware_*) |
| NOS | Collections | Notes |
|---|---|---|
| VyOS | vyos.vyos |
Open-source router/firewall (rolling + LTS) |
| Cumulus Linux | nvidia.nvue |
NVIDIA Cumulus 5.x via NVUE REST API |
| SONiC | dellemc.enterprise_sonic |
Enterprise SONiC; community SONiC via gNMI (pygnmi) |
| FRRouting | frr.frr |
Open-source routing stack (BGP, OSPF, IS-IS) β used under the hood by SONiC, Cumulus and VyOS |
Plus community.general for general-purpose modules.
For pure-Python SSH automation, use these device_type values:
| Vendor / NOS | Netmiko device_type |
|---|---|
| Cisco IOS/IOS-XE | cisco_ios |
| Cisco NX-OS | cisco_nxos |
| Cisco ASA | cisco_asa |
| Arista EOS | arista_eos |
| Juniper Junos | juniper_junos |
| Aruba CX / ProVision | aruba_os / aruba_procurve |
| Dell OS10 | dell_os10 |
| Huawei | huawei |
| HP Comware / ProCurve | hp_comware / hp_procurve |
| Extreme EXOS | extreme_exos |
| Allied Telesis AW+ | allied_telesis_awplus |
| VyOS | vyos |
| Cumulus / FRR (Linux shell) | linux |
Includes tools like:
curl, wget, git, jq, ssh, ping, dig, traceroute, nc, tcpdump, iproute2, rsync, vim, nano, less, yq.
Dockerfileβ image definitionrequirements.txtβ Python dependenciescollections.ymlβ Ansible Galaxy collections.github/workflows/docker.ymlβ CI/CD (build, smoke test, publish to Docker Hub)README.mdβ project documentation
docker pull andersonmavi30/docker_network_automation:3.0.0docker run --rm -it andersonmavi30/docker_network_automation:3.0.0 bashInside the container:
ansible --version
ansible-galaxy collection list | head
python -c "import netmiko, napalm, nornir, scrapli, ncclient, pygnmi, textfsm; print('OK')"
yq --versiondocker run --rm -it \
-v "$PWD:/workspace" \
-w /workspace \
andersonmavi30/docker_network_automation:3.0.0 bashdocker build -t andersonmavi30/docker_network_automation:3.0.0 .Publishing to Docker Hub is automated: pushing a git tag
v*triggers the GitHub Actions workflow, which builds (amd64 + arm64), smoke-tests and pushes the image with semver tags (3.0.0,3.0,latest).
Requires your own inventory and credentials.
ansible -i inventories/lab.yml all -m ansible.netcommon.cli_command -a "command='show version'"from netmiko import ConnectHandler
with ConnectHandler(device_type="aruba_os", host="10.0.0.1",
username="admin", password="secret") as conn:
# use_textfsm=True parses the output with ntc-templates automatically
interfaces = conn.send_command("show interfaces", use_textfsm=True)
print(interfaces)from pygnmi.client import gNMIclient
with gNMIclient(target=("10.0.0.2", 8080), username="admin",
password="secret", insecure=True) as gc:
result = gc.get(path=["openconfig-interfaces:interfaces"])
print(result)inventories/
playbooks/
group_vars/
host_vars/
scripts/
templates/
All changes go through a feature branch β never commit directly to main:
# Create a feature branch
git checkout -b feature/my-change
# Make edits, then verify
git status
# Commit
git add .
git commit -m "feat: describe your change"
# Push branch
git push -u github feature/my-changeThen open a Pull Request (GitHub) or Merge Request (GitLab) with:
- What changed
- Why
- How it was validated
After merging, clean up locally:
git checkout main
git pull github main
git branch -d feature/my-change
git fetch --prune
git push gitlab main # keep the GitLab mirror in syncgit tag -a v3.0.0 -m "Release 3.0.0"
git push github v3.0.0
git push gitlab v3.0.0The CI workflow builds and publishes the image to Docker Hub automatically.
Older Docker/kernels may fail to build due to seccomp/kernel syscall limitations.
Recommended workflow:
- Build on a modern host.
- Push image to Docker Hub.
- Pull/run in PNetLab/EVE-NG.
docker pull andersonmavi30/docker_network_automation:3.0.0
docker run --rm -it andersonmavi30/docker_network_automation:3.0.0 bashUse this image as an automation jumpbox to manage lab nodes. VyOS, FRR and SONiC VS images work great as lab targets.
- Add Python libraries: edit
requirements.txtand rebuild. - Add Ansible collections: edit
collections.ymland rebuild.
docker system df
docker builder pruneThe Dockerfile already handles pre-existing UID/GID values to prevent build failures.
- Runs as non-root user (
netops) by default. - Ansible installed via
pipx. - Python libs installed in
/opt/venv.
- Add sample playbooks and inventories per vendor.
- Add more smoke tests during CI (per-vendor Ansible module checks).
- Dedicated firewall image (Fortinet, Palo Alto, Check Point).
MIT License (see LICENSE).
LinkedIn: https://www.linkedin.com/in/anderson-martinez-virviescas-b5b79b106/