Cloud Craft SRLCloud · DevOps · SRE · Infrastructure
EN/RO

Network control plane · DDoS response

Detect the flood. Preview every action. Reroute safely.

Rerouter turns interface and flow telemetry into controlled mitigation workflows for Cisco IOS edge networks. It was designed for the uncomfortable gap between “we see an attack” and “we can change routing without creating a second incident.”

RustReactSNMPNetFlow v9sFlow v5Cisco IOS
Rerouter dashboard showing reachable devices, monitored interfaces, consistent recent alerts, and observe mode
Operator dashboardSanitized consistent demo data · real frontend
Observe firstShips read-only and alert-only
Two telemetry layersSNMP interfaces plus sampled flows
Exact action previewsReview commands and rollback before execution
Fail-closed controlAllowlists, cooldowns, locks, verification
Available engagementArchitecture review, custom deployment, Cisco integration, safety hardening and operational handover. Rerouter is also available as source for technical evaluation.

The operator problem

Traffic incidents move faster than manual coordination.

During volumetric attacks, the hard part is not only detecting a threshold. Operators need current device inventory, a bounded target, a reviewed command set, a reversible action, and a record of what actually happened.

  • Telemetry, detection, routing and audit usually live in separate tools
  • Emergency SSH changes are difficult to review and reconstruct
  • Blind automation can turn a partial outage into a wider one

The engineering response

One deterministic path from signal to mitigation.

Rerouter keeps the decision, command rendering, execution state, verification and rollback in one controller. Every dangerous transition remains explicit, permissioned and attributable.

  • Per-device polling with reachability and freshness gates
  • Preview tokens bound to the exact server-rendered plan
  • Crash recovery that marks ambiguous work uncertain and locks the device

Capabilities

Built for the worst day, not the demo day.

The project combines network engineering, safety-critical backend design, a usable operations interface, and production deployment discipline—exactly the mix required for high-impact infrastructure automation.

01 · TELEMETRY

Interface and flow visibility

SNMP rate derivation, BGP state, NetFlow v9 and sFlow v5 buckets, with stale-data handling and exporter confidence.

02 · DETECTION

Stateful editable rules

Thresholds, duration, consecutive samples, cooldowns and flow selectors avoid firing on a single noisy measurement.

03 · ACTIONS

Allowlisted reroute templates

Typed parameters render bounded Cisco IOS actions for RTBH, BGP peers, route maps and controlled interface workflows.

04 · SAFETY

Observe, enforce and step-up

TOTP, RBAC, manual-only action classes, one-use previews and explicit arming keep execution behind visible gates.

05 · RECOVERY

Verification and rollback

Separate read-only SSH verification, persisted action state and uncertain-state locks make failures diagnosable and recoverable.

06 · OPERATIONS

Alerts and immutable context

Email and Teams delivery, audit views, device health and exact would-run plans give operators usable incident context.

System shape

A small control plane with clear boundaries.

The browser never reaches routers. The Rust controller is the only writer, MariaDB is the system of record, and network actions travel through a narrow, verified device-CLI seam.

Operator SPASession, 2FA, RBAC, previews
Rust controllerTelemetry, detection, state machine
MariaDBInventory, rules, actions, audit
Edge routersSNMP read · SSH apply and verify

What this proves

The same discipline transfers to client systems.

Rerouter is evidence of how Cloud Craft approaches high-risk automation: model the failure states first, keep the operating surface legible, and make every transition observable.

Network automationBGP, routing policy, device enrollment, telemetry and safe orchestration.
Operational softwareRust services and React interfaces designed around real on-call decisions.
Production hardeningLeast exposure, explicit trust boundaries, recovery paths and deployable runbooks.

More projects

Other systems we build and operate.

Routing infrastructure, public network visibility, and broadcast transport—different domains, the same production-first engineering.

Bring us the difficult system

Need safer network automation?

Tell us what you operate, where manual steps are slowing incident response, and which actions cannot be allowed to fail silently. We can help with architecture, implementation, deployment and operational handover.