The agent reads your NetBox, Nautobot, and live CLIs — read-only — and builds runnable labs from real data.
Describe a network — or point the agent at your NetBox — and get a running multi-vendor lab you can SSH into.
Trusted by network engineers worldwide
Several do, by different routes. The open-source path exports your source of truth into a topology file you deploy yourself; NetPilot connects to your MCP server and lets the agent build the lab. Here is the honest comparison.
| Platform | How it reads NetBox / Nautobot | Real NOS images | Assembly required |
|---|---|---|---|
| NetPilot | Built-in read-only MCP connectors — point one at your NetBox or Nautobot MCP server and the agent queries it directly | ✅ | An MCP server you host; no exporter pipeline |
| Containerlab | NetBox only — via netreplica/nrx, which exports a NetBox site to Containerlab topology files | ✅ | You run the exporter and maintain the pipeline |
| Cisco Modeling Labs | NetBox only — nrx exports to CML format; Cisco also publishes tooling to sync CML topologies back into NetBox | ✅ | Export step, plus CML licensing |
| NVIDIA Air | NetBox only — nrx exports to NVIDIA Air format | ✅ | Export step; Cumulus and data-center fabrics |
| EVE-NG | No widely used first-party path — teams write their own API glue | ✅ | Custom scripting end to end |
| GNS3 | No widely used first-party path — teams write their own API glue | ✅ | Custom scripting end to end |
Credit where it is due: the source-of-truth-to-lab pattern was proved in the open-source community by netreplica/nrx and Containerlab. If you want maximum control and are happy to maintain the pipeline, that stack is a genuinely good answer. NetPilot removes the assembly, not the credit.
Three MCP connectors ship in the product — read-only by design, wired for the change-rehearsal loop.
The agent is granted an allow-list of read tools — exact names, never a wildcard. Write and delete tools are never attached.
The alternative
DIY agent wiring hands the model a full API token and hopes the system prompt says “don't write.”
NetBox/Nautobot records become a deployed multi-vendor lab you can SSH into — rehearse the change before production.
The alternative
Topology exporters hand you YAML to maintain; model-based twins can't run a single show command.
show-command access via Nornir with credentials brokered from your Nautobot at call time — NetPilot never stores them.
The alternative
Homegrown scripts with device passwords in env vars and nothing between the model and enable mode.
NetBox, Nautobot, and Nornir ship in-product on every plan. Any MCP-enabled tool connects on Signature & Enterprise.
The alternative
Point integrations cover one inventory tool; every new system in your stack means more glue code for your team.
Every connector exposes a curated, read-only tool surface to the agent — nothing more.
Speaks to the official read-only NetBox MCP server you host: devices, sites, prefixes, object search, and changelogs. Ask “what changed this week?” or “build a lab from site DC-East” — the agent reads the records and does the rest.
The full read surface of your Nautobot MCP server: devices, interfaces, racks, IPAM, circuits, tenants, GraphQL queries, and job logs. The mutating tools — create, update, delete, run-job — are never attached.
Live read-only CLI access to your real network: show commands only, enforced server-side. Inventory and credentials are brokered from your Nautobot at call time and executed in your environment — NetPilot never stores them.
These three are the starting point, not the list. With Signature & Enterprise, NetPilot connects to anything MCP-enabled — and every integration is custom-built to fit your workflow: if it has an API, NetPilot connects to it. Talk to us about your stack →
The agent turns source-of-truth data into a deployed, verifiable lab — and checks it against reality.
Devices, interfaces, prefixes, free IPs, changelogs — the agent queries your NetBox or Nautobot directly in chat and designs the matching topology from what's really there.
The agent deploys the twin on real network OSes (12+ and growing) and runs the verification itself — and every device stays a normal SSH target, so you can check the routing table by hand.
Snapshot and diff lab state, spot-check the live network with read-only show commands, and catch drift between intended and actual before it bites a change window.
Ask in plain English — the agent picks the right read-only tools, and everything it builds is verifiable on real CLIs.
“Build a lab from my NetBox site DC-East” — the agent pulls devices, interfaces, and prefixes, then deploys a matching multi-vendor lab on real NOSes.
Free /28s, available IPs, VLAN and VRF lookups straight from Nautobot — asked and answered in the same chat that builds the lab.
Pull the affected segment from your source of truth, deploy the twin, apply the candidate change, and diff pre/post state — before production.
Compare intended state (NetBox/Nautobot records) against live state (show-command output) in one conversation and get the delta.
“Run show ip bgp summary on core-rtr-01” — Nornir executes read-only show commands with credentials brokered from your Nautobot, never stored.
“What changed in NetBox this week?” — the agent reads changelogs and job logs, without the ability to run or modify anything.
The honest comparison: exporter scripts and hand-wired MCP servers work — they just cost engineering time NetPilot spends for you.
Verdict:DIY wins for hands-on control and zero budget; NetPilot wins when the goal is rehearsing real changes from real data — connected, deployed, and validated in one conversation.
How teams connect their source of truth to NetPilot — safely
Rehearse BGP, ACL, and routing changes on a runnable mirror before production.
A twin you can actually run — built from your source of truth, real CLIs via SSH.
Two-way MCP, custom integrations, on-prem options, and founder-led onboarding.
Talk to us about wiring NetPilot into your stack — or add a NetBox, Nautobot, or Nornir connector yourself and ask the agent what's really in your network.
Bigger stack? Talk to us about custom MCP integrations