services/Network Automation

Run a large network with a small team.

Every device configured by hand is a chance for drift, inconsistency and an undocumented change. We automate the work that should never vary, using Python, Ansible and your devices' own APIs, so a small team can run a large, consistent network.

site-baseline.yml — automation run ANSIBLE
ansible-playbook site-baseline.yml
PLAY RECAP — multi-vendor fleet
cisco-core-01ok=14 changed=2
cisco-dist-02ok=13 changed=0
mikrotik-site-07ok=11 changed=1
extreme-edge-03ok=12 changed=0
hirschmann-rsp-05ok=10 changed=1
infoblox-syncok=9 changed=0
mikrotik-site-08running…
240 hosts · one source of truth · 0 configuration drift
[ Why it matters ]

Manual configuration stops being slow and starts being a risk.

Automation earns its place when manual work can no longer keep up with scale, consistency, or the number of systems that have to agree. That pressure shows up two ways: many sites that should be identical, and single environments complex enough that their tools drift apart.

01

Many sites, one standard

Dozens or hundreds of locations that should match. Configured by hand, each one takes hours and quietly diverges from the rest.

02

A complex environment, many tools

One campus or data centre where network, access control and address management live in separate systems that get reconciled by hand.

03

Config drift you can't see

Devices that started identical have diverged through local fixes and undocumented changes, with no reliable way to detect it.

04

A team too small for manual work

A handful of engineers cannot touch every device by hand. Automation lets a small team operate at a much larger scale.

[ What we automate ]

What we automate.

We automate the repetitive, error-prone work and leave the judgement to your engineers. We build in Python and Ansible, against the APIs and CLIs of the gear you already run: Cisco, MikroTik, Extreme, Infoblox, and our own products where they fit.

A · SITE PROVISIONING

Configs from a template

Complete device configs generated from a template. Ship the hardware, plug it in, done. Zero-touch.

B · FIRMWARE MANAGEMENT

Staged, validated rollouts

Firmware rolled out in stages across the fleet, with automated validation before and after each step.

C · COMPLIANCE AUDITS

Checked against the baseline

Automated checks against your standards. Drift is detected and surfaced, not discovered during an incident.

D · CONFIG MANAGEMENT

Versioned and reversible

Version-controlled configurations: backups, diffs and a clean roll-back when a change goes wrong.

E · INTEGRATION & SYNC

Systems that agree

Network, access control and address management kept in sync automatically. We connect tools like Infoblox, Extreme and Cisco so host data flows between them without manual comparison.

F · SELF-SERVICE & APIs

Requests handled at source

Portals and APIs that let the people making a request fulfil it themselves, instead of a ticket queue.

[ The toolchain ]

Real tools, not a black box.

We automate with the open, standard tools your engineers can read, run and own. Python for the logic, Ansible for orchestration, a source of truth for the data, version control for history, and the devices' own APIs and CLIs underneath.

That keeps the automation portable and vendor-neutral. It stays yours after we hand it over, and it plugs into whatever you already run.

 nwos toolchain
toolchain
├─ logic            Python - Jinja
├─ orchestration    Ansible - Nornir
├─ source-of-truth  NetBox - Nautobot - OpsMill - Infoblox
├─ interfaces       REST - gNMI - NETCONF - SSH
└─ history          Git
# your devices; any vendor, API or CLI
 
[ How we engage ]

Built on your environment, not a rip-and-replace.

We build automation on top of what you already run, then hand it over so your team can carry it.

1

Assess the current state

Understand the devices, vendors, site types and workflows, and find the automation that pays back fastest.

2

Define the standards

Establish templates, naming conventions and configuration baselines for each device and site type.

3

Build the workflows

Build provisioning, firmware, compliance and integration workflows in Python and Ansible, against your devices' own APIs and CLIs, whatever the vendor.

4

Hand it over

Documented, version-controlled workflows plus training, so your team can maintain, extend and evolve the automation independently.

sciCORE data center, high-performance computing

«sciCORE, the scientific high-performance computing center of the University of Basel, depends on a stable and reliable network infrastructure. Working with narrowin helps us to ensure this.»

Martin Jacquot Head of Technology and Operations · sciCORE, University of Basel
ansible-mikrotikthe RouterOS automation we run, open-sourced · apache-2.0

In practice: the Ansible automation we developed with sciCORE has been released as open source.

[ Proof ]

Automation across very different networks.

Three networks, three automation problems: scaling many sites, integrating a campus, and standardising a research fabric.

Telecom · broadband

Breitband Lörrach

From 20 to 2,000+ sites with template-based config generation and zero-touch deployment at telecom scale.

Education · campus

University of Basel

Infoblox, Extreme XMC and the Cisco WLC integrated into one automation layer, with a self-service portal that lets a small team run a large campus.

Research · computing

sciCORE · University of Basel

A standardised, lab-validated network fabric for high-performance computing that stays consistent and manageable as it grows.

[ Frequently asked ]

The specifics.

What do you build automation on?

Your existing stack. We work in Python and Ansible against your devices' APIs and CLIs, with a source of truth such as NetBox, Nautobot or Infrahub at the centre. The toolchain is vendor-neutral: if a device exposes an API or a CLI, we can automate it. Our own products plug in where they help, never as a requirement.

Can you automate our existing vendor gear?

Almost certainly, and no rip-and-replace. We have shipped automation across a wide range of platforms, from core switching and routing to firewalls, wireless and industrial gear. Anything reachable over an API, NETCONF or SSH is in scope.

How do you handle exceptions?

Templates support site-specific parameters and overrides. Not every site is identical, but the structure should be. Exceptions are documented and tracked, not hidden in local configs.

What skills does our team need?

We build the automation and hand it over documented and version-controlled, with training. Day-to-day operation does not require deep scripting. Extending it benefits from basic Python and Ansible familiarity, which the training covers.

[ Related work ]

Automation, in practice.

How automated operations play out on real customer networks.

Let a small team run a large network.

If manual configuration is holding you back, let's find the automation wins that pay back fastest.

Discuss automation