Contact Request a demo
Self-hosted · Cisco ACI control plane

Your Cisco ACI fabric, finally under control.

Day2Fabric is a self-hosted layer on top of APIC: operate the fabric, deploy changes safely and design what comes next — with every ACI concept explained in plain words, so the whole team can work, not just the one expert. It ships as a containerized stack on Docker Compose, with an offline bundle for air-gapped sites.

For the whole teamNot just the one ACI expert.
The full lifecycleOperate, deploy & design in one workspace.
Self-hostedYour infrastructure, your data.
app.day2fabric.com / operate / endpoint · Policy Verifier live
Day2Fabric Policy Verifier — Reachability Matrix showing permitted and blocked flows between EPGs
Policy Verifier · Matrix mode — actual product screen, v1.21
One platform · the full lifecycle

Operate, deploy and design — one workspace, three sections

The workspace mirrors how the fabric is actually run. Each section is a menu in the product, not a marketing phase — and every role finds its place.

Operate

See what the fabric is doing

Faults with root-cause hints, live topology with a node inspector, live traffic, endpoint lookup and the Policy Verifier — plus read views of every tenant, VRF, bridge domain, EPG, contract and L3Out.

For Ops Team
Deploy

Ship changes safely

A guided Getting Started, one page per ACI object with an explanation on every field, naming conventions enforced at creation, bulk import from CSV with automatic rollback, and a scheduler for change windows. Read-only and demo modes keep you safe.

For Network Engineer
Design

Plan what comes next

Capacity Planning with real port headroom, policy-TCAM limits, what-if projections and reservations; unused-port detection; and an Application Onboarding wizard that turns an app into tenant, EPGs, BDs and contracts — previewed as a reachability matrix before any APIC write.

For Network Architect · Capacity Planning
Safe by design

It can't break your fabric unless you let it

Every fabric is read-only by default. Write capability is detected from APIC roles, never tested. Demo mode fakes writes; Simulated mode needs no APIC at all. You decide when Day2Fabric is allowed to touch production.

RORead-only
default
SIMNo APIC
required

Fabric modes

Read-only
Demo
Simulated
Write capability detected from APIC roles at connection time — never by test writes.
Real screens, not renders

See it in action

Straight from the product — these are actual screens, not marketing mock-ups.

Shipped & in production

What Day2Fabric already does

Not a roadmap deck — these are the capabilities running today.

SHIPPED

Policy Verifier

Answer “can A talk to B?” the way the fabric decides — contracts, vzAny, Preferred Groups, Taboo, unenforced VRFs — in Matrix or Flow mode.

SHIPPED

Simulated Fabric Mode

A realistic, fully synthetic fabric from a seed — no APIC. Demo, train and build against it; writes persist, reset wipes them in one click.

SHIPPED

Dashboards & health

Super Admin and per-org Workspace dashboards: weighted health score, fault counts by severity, unreachable-APIC detection and an in-app notification center — platform-wide for MSPs.

See the dashboard →
SHIPPED

Activity Monitor & audit

Every platform event logged and correlated to the session that caused it. Who did what, when and from where — with a Sessions page and configurable retention.

SHIPPED

Schedule Activities

Plan change windows: add/remove ports to EPGs, modify contracts, with bell notifications to the right roles at the right time.

SHIPPED

Asset Inventory

Every node — ID, name, fabric, location, model, serial, OOB IP, software — in one filterable table, exportable to XLSX.

SHIPPED

Organization Standards

Org-level standards that every deploy respects: naming conventions enforced per object, hardware catalog and fabric sizing, and a deployment approach — network-centric, application-centric or per location — with per-location overrides.

SHIPPED

Application Onboarding

A four-step wizard that turns an application into tenant, EPGs, BDs and contracts — previewed as a reachability matrix before any APIC write, deployable now or scheduled.

SHIPPED

Bulk config & rollback

Define changes from a CSV or a guided template — full stack, EPG clone — and apply them atomically: if one object fails, everything already written is rolled back.

SHIPPED

Endpoint Search

Find any IP or MAC and see exactly where it lives — tenant, app profile, EPG, VRF, contracts and DN — then pivot to it as source or destination.

SHIPPED

Capacity Planning

Interface occupancy per leaf and vPC pair with spine uplinks excluded, policy-TCAM limits per node, what-if projections, reservations with approval — and a list of ports that have sat unused for too long.

SHIPPED

Multi-fabric, Locations & RBAC

Organizations, locations and fabrics under one platform, with roles scoped by organization, location or fabric and per-org workspaces — the foundation for MSP and large-team use.

SHIPPED

Help center

A persistent in-app help drawer with 22 guides in 5 sections, contextual to the page you are on. Four guided paths check your fabric live as you go: connect a fabric, verify a policy, deploy objects, configure interfaces.

SHIPPED

Universal search

Press ⌘K and find any tenant, EPG, endpoint, VRF, bridge domain, contract, policy, L3Out, interface or device across your fabrics — verified live before you jump to it.

SHIPPED

Topology & node inspector

The fabric as a graph or as an asset table, and a node inspector with hardware, interfaces, port-channels, metric history and counter baselines — with shut / no-shut for operators.

See the full ACI & NX-OS coverage matrix →

Enterprise bundle

Built for larger, regulated networks

Everything in the platform, plus the capabilities bigger teams and security-led organizations ask for first — some shipped, some on the roadmap, and we say which.

Talk to us about Enterprise

NX-OS support Extension · monitoring

Standalone Nexus 9000 alongside ACI, in the same workspace: devices, interfaces, VLANs, VRFs, CDP/LLDP neighbors and health today — provisioning on the roadmap, validation on physical Nexus pending.

see the ACI & NX-OS coverage matrix →

Priority support & SLA Enterprise

A direct line to the people who build Day2Fabric: priority response, defined SLAs and guided onboarding — plus an enforced read-only service account and air-gapped offline licensing. Kubernetes packaging on request (roadmap).

SSO Enterprise · roadmap

Single Sign-On through your identity provider — OIDC, SAML and LDAP (Authentik-ready). Central identity, no local accounts to manage, with a platform admin always available.

Zero Trust Enterprise · roadmap

Least-privilege segmentation you can prove: contract-by-contract verification across tenants, with continuous posture checks and drift alerts on the roadmap.

LLM Gateway Enterprise · roadmap

On-prem AI assist, model-agnostic — Anthropic, Azure OpenAI, Bedrock or a local Ollama. ACI context is injected into the prompt; your data stays in your environment.

Audited jump-host Enterprise · roadmap

A browser-based, audited SSH gateway to the fabric — credential brokering and full session recording. For environments where direct OOB access is locked down and every keystroke must be accountable.

Questions, answered

The things people ask first

Do I have to give it access to my APIC?
No — to try it, use Simulated Fabric Mode, which needs no APIC at all. For a real fabric, Day2Fabric starts in read-only and detects write capability from your APIC roles. You flip it to read-write only when you're ready.
Does my data leave my network?
No. Day2Fabric is self-hosted: it runs on your infrastructure, keeps data in your own database, and sends no telemetry anywhere.
Does it replace APIC?
No. It's a control, comprehensibility and guardrail layer on top of APIC — not a substitute. The expert still has somewhere to go deep; everyone else gets to work safely.
How is it licensed?
Per managed fabric, across Starter, Business and Enterprise tiers. Licensing is offline and signed, so it works in air-gapped environments. Simulated fabrics don't count against your quota.
What's in the Enterprise bundle?
Priority support with defined SLAs, air-gapped offline licensing and the NX-OS extension (monitoring today, provisioning on the roadmap). On the roadmap for the same tier: SSO (OIDC/SAML/LDAP), Zero-Trust posture checks, an on-prem LLM Gateway and an audited jump-host. Talk to us to map it to your environment.
How do I install it?
A Docker Compose stack with an initial setup wizard, plus an offline bundle (images, TLS via Caddy, install script) for air-gapped sites. No Kubernetes required. Fonts and help content are bundled, so nothing is fetched from the internet at runtime.
Request a demo

See it on a real example

Tell me what's painful about your current setup and I'll tailor the walkthrough around it — on a simulated fabric, or a screen-share of yours. No slides.

  • Book a slot and tell us what you want to solve.
  • We demo it live on a realistic fabric — no setup or APIC access needed.
  • You keep the sandbox afterwards to explore on your own.
What's on your plate right now?

Got it — talk soon.

We'll reach out to schedule your demo.