Skip to content

rpkiparrot

A Python library for RPKI payload management and validation, with an optional CLI. It is intended for independent third-party applications, services and tools.

This is the 0.1.0rc1 release candidate, not yet uploaded to PyPI, for Python 3.11 and later. It provides RTR client synchronization, Routinator/rpki-client and custom JSON readers, immutable source snapshots, indexed ROV, experimental ASPA validation, conservative BMP analysis, queries and complete snapshot exchange. Clients support live source and configuration changes. Optional components provide SQLite/DuckDB persistence, SQLite shared readers, an HTTP service and a typed remote SDK. Protocol recording and offline replay help investigate synchronization failures. Candidate acceptance is tied to the exact source commit and artifact hashes in the delivery record.

Routers need a separate RTR server. This package consumes RTR data and exposes library and HTTP APIs; a production RTR server is outside the first-release scope.

ASPA authorization is independent for IPv4 and IPv6. Select an explicit Afi when they differ; an omitted family requires equivalent usable views. RTR v1 is the default. Experimental v2 uses explicitly selected, fixed draft profiles; see the protocol contract for the current 8210bis-27 and historical -10/-13 wire formats.

For development from this checkout:

uv sync --all-extras --group dev
uv run python examples/offline.py
uv run python examples/validation.py
uv run python examples/online_json_source.py --backend trio
uv run python examples/persisted_client.py --database sqlite
uv run python examples/service.py
uv run python examples/ssh.py
uv run rpkiparrot --help
uv run nox -s lint typing docs
uv run nox -s tests-3.11 tests-3.14

The executable offline example constructs a complete source programmatically. Original generation times and explicit freshness policies bound every snapshot; offline evaluation always requires a reference time. An unavailable dataset is an error, distinct from normal notfound or unknown results. Core installation depends directly only on AnyIO; CLI and other components use explicit extras.

To install the delivered candidate wheel with optional components:

python -m pip install './rpkiparrot-0.1.0rc1-py3-none-any.whl[cli,http,sqlite,trio]'

To install from a local checkout without development tools:

python -m pip install '.[cli,http,sqlite,trio]'
Extra Adds
cli Typer/Rich commands and machine-readable output
http HTTP JSON sources and the remote SDK
sqlite SQLite owner persistence; shared readers use standard-library SQLite
duckdb DuckDB owner persistence; other processes query through HTTP
service One asyncio HTTP owner with authentication and bounded requests
trio Trio execution for the core library and remote SDK
ssh Authenticated RTR over SSH, explicit host keys and credentials; asyncio only

The application owns its event loop and task group. The core and SDK run on asyncio or Trio; the optional service and built-in SSH transport run on asyncio. Creating a configuration does not start networking. Source data becomes visible only after a complete, validated transaction, and recovery never refreshes the original expiry time.

Start with the documentation index, usage guide and complete API reference. The API reference expands source signatures and docstrings during the documentation build; GitHub displays only the generation directives. Run uv run --locked nox -s docs to generate the full reference at site/docs/api/index.html. The release notes describe this release candidate and its protocol and deployment boundaries. The design and acceptance contract define the entire M0–M4 scope; planned APIs are distinguished from implemented exports. Running or configuring a check is not evidence that it passed.

The fixed protocol mirror and independent sample index record protocol versions and input provenance. Compatibility and performance claims require actual test evidence. CI runs only on Linux x86_64 with CPython 3.11 and 3.14 on self-hosted runners. Python 3.12/3.13 have manual acceptance commands. Windows 11 x64, macOS x64/ARM64 and Linux ARM64 remain portability targets with local acceptance commands. Unexecuted combinations for the current candidate are reported as unverified.

See CI/CD for checks and artifact acceptance, and PyPI preparation for publishing setup. This task produces release candidates; it does not upload to PyPI.