Topology
Four views, layout, exports and sharing
Edit this pageOn this page
Four views over the same inventory, each answering a different question. They are generated snapshots, not live queries — which is what makes a 5 000-node graph render in under two seconds, and what makes your manual layout survive.
The four views
| View | Question it answers | Built from |
|---|---|---|
| L2 physical | What is plugged into what? | Interfaces, LLDP/CDP neighbours, LAG groups |
| L3 logical | How does traffic route? | Addresses, subnet membership, routing tables |
| Workloads | What runs inside what? | Host parent/child relationships |
| Application | What talks to what? | Observed flows, or co-hosting as a fallback |
L2 physical
Interfaces grouped by host, with adjacencies drawn from LLDP and CDP. This view is only as good as your SNMP coverage: without credentials for the switches, there are no neighbour tables and the view degrades to hosts with no edges between them.
L3 logical
Hosts and subnets, with membership edges and routing edges. This one works without SNMP — address and subnet data comes from discovery itself — but routing edges need routing tables, which come from SNMP.
Workloads
Physical hosts, virtual machines and containers as a hierarchy. Populated by host parent/child relationships: Docker discovery on a daemon, Kubernetes discovery in the control plane, or hypervisor identity from SNMP.
Application
Service-to-service dependencies. This is the view most worth reading carefully, because it has two very different modes:
With flow data, edges are real observed dependencies — this service
connected to that one, within the window set by
LOOMSCOPE_DEPENDENCY_WINDOW_HOURS (default 24).
Without flow data, Loomscope draws lighter co_hosted edges between
services on the same host. That is a placeholder, not a claim that they
communicate. It is drawn because an empty graph reads as "nothing depends on
anything", which is a worse lie than an obviously provisional one.
Point your switches and routers at the daemon's NetFlow listeners and the placeholders are replaced by real edges. See Discovery.
Regenerating
Views are generated, so they reflect the inventory as of the last regeneration. Regenerate rebuilds from current inventory; if a site is selected in the header, only that site's view is rebuilt.
A topology.dependencies job also runs hourly to refresh application-view
edges from recent flows.
Layout is yours
Drag a node and its position is saved. A regeneration preserves it — which is the whole reason positions are stored rather than recomputed, since an operator who has arranged a datacentre by rack will not do it twice.
Locking a topology stops regeneration from moving anything at all. Use it for a diagram that has become the reference drawing.
Nodes without a saved position are placed by dagre, which produces a hierarchical layout that is readable at the sizes this has to work at.
Exports and sharing
| Format | For |
|---|---|
| Mermaid | Dropping into a Markdown document, a wiki, or a pull request |
| draw.io | Editing by hand — an architecture diagram that starts from reality |
| Share link | A read-only URL that needs no account |
A share link is the answer to "the auditor wants to see the network but is not getting a login". It is revocable, and it carries no ability to do anything but look.
Reading a topology honestly
Three things worth keeping in mind:
Absence of an edge is not absence of a connection. It means nothing was observed. A firewall that drops the probes, a switch with no SNMP credentials, or a service that talks over a path no collector sees all produce silence rather than an error.
A co_hosted edge is not a dependency. It is drawn in the lighter style
for exactly that reason.
The graph is as fresh as its last regeneration. The timestamp is shown. If it looks wrong after a change window, regenerate before investigating.
Performance
The design target is a 5 000-node topology rendered in under 2 seconds, using React Flow with dagre layout. Above that, scope by site — which is usually the honest thing to do anyway, since a diagram nobody can read is not a diagram.