What is wanted
Scan the open ports of discovered network devices, so that what a device exposes becomes part
of what opencmdb observes about it.
Requested by the maintainer on 2026-07-28.
This is already in the plan — recorded here so the plan has a requester behind it
prd.md places "port/service scanning + service-fingerprint identity signal" in Phase 2
(Growth), twice (prd.md:839 and prd.md:1054). This issue does not open new scope; it records
that the item has a real asker, which is the difference between a roadmap line and a requirement.
It also carries a sequencing constraint the PRD states explicitly and that must not be lost:
the MVP signal set is hardware address + hostname + IP/lease history + connection topology, with
service fingerprint sequenced alongside Growth's service scanning — "a coherence dependency,
not an effort cut." (prd.md:829-831)
So the two halves ship together or not at all: a port scanner whose results never reach the identity
engine is inventory decoration, and a service-fingerprint signal with no scanner behind it has no
input.
Open questions, not decided here
Not proposed for MVP
Epic 5 (interface identity) is in progress and the MVP signal set is closed. This belongs to Growth,
after the identity engine exists — the PRD's sequencing is the reason, not capacity.
What is wanted
Scan the open ports of discovered network devices, so that what a device exposes becomes part
of what opencmdb observes about it.
Requested by the maintainer on 2026-07-28.
This is already in the plan — recorded here so the plan has a requester behind it
prd.mdplaces "port/service scanning + service-fingerprint identity signal" in Phase 2(Growth), twice (
prd.md:839andprd.md:1054). This issue does not open new scope; it recordsthat the item has a real asker, which is the difference between a roadmap line and a requirement.
It also carries a sequencing constraint the PRD states explicitly and that must not be lost:
So the two halves ship together or not at all: a port scanner whose results never reach the identity
engine is inventory decoration, and a service-fingerprint signal with no scanner behind it has no
input.
Open questions, not decided here
Fact-shaped(a positive statement about a device), but it is also volatile in a way a MAC or a hostname is
not: a service stopping is not a device changing. D35 forbids a
Factvariant meaning"absent/gone", so a closed port cannot be expressed as an observation — only the open set at a
given poll.
operator may not own the right to probe (issue network_mode: host makes the ICMP scan impossible — the reference deployment ships blind #8's lesson: the reference deployment shipped blind
because the network mode made ICMP impossible — an assumption about what the container may emit).
The default must be conservative and configurable; this lands on the same surface as Scan tuning belongs in the web UI, not in environment variables #11 (scan
tuning belongs in the web UI) and Configure scan CIDRs from the web UI — multiple subnets of heterogeneous sizes (replace OPENCMDB_SCAN_CIDR) #3/Manage scan subnets (multiple CIDRs) from the web UI #4 (CIDR management in the UI).
scan needs no privilege; a SYN scan does. Which one is the floor?
port sweep over that is the same defect as The ping scan is sequential: a /24 takes 3m33s where it could take seconds #10 (a sequential /24 ping taking 3m33s).
Not proposed for MVP
Epic 5 (interface identity) is in progress and the MVP signal set is closed. This belongs to Growth,
after the identity engine exists — the PRD's sequencing is the reason, not capacity.