panda-rpki-oss/docs/getting-started.md
Panda RPKI OSS Local 277cbca878
Some checks failed
ci / rust (push) Has been cancelled
ci / docker (push) Has been cancelled
初始化 Panda RPKI v0.1.0 开源候选版本
2026-09-09 18:01:15 +08:00

2.8 KiB

Getting started

Panda RPKI v0.1.0 is a Linux command-line application. You can use Docker without installing Rust, or build a native binary. It requires outbound HTTPS to RPKI repositories, a writable state directory, and enough disk space for repository objects and outputs. Resource use depends on the selected trust anchors.

Prepare trust anchors

A trust anchor defines what you trust. Obtain its TAL from the responsible RIR and obtain the current DER certificate from a certificate URI in that TAL. Panda RPKI checks that the certificate matches the TAL public key. It takes both files as explicit inputs; it does not refresh the supplied TA file for you.

For example, the RIPE NCC trust-anchor page publishes the RIPE NCC TAL. From the project root:

mkdir -p input
curl --fail --location --proto '=https' --proto-redir '=https' \
  --connect-timeout 15 --max-time 120 \
  https://tal.rpki.ripe.net/ripe-ncc.tal -o input/anchor.tal
curl --fail --location --proto '=https' --proto-redir '=https' \
  --connect-timeout 15 --max-time 120 \
  https://rpki.ripe.net/ta/ripe-ncc-ta.cer -o input/anchor.cer

Check the TAL's current certificate URI before downloading. The RIR trust-anchor directory links the other regional anchors. Use their official TALs and corresponding certificate locations when preparing a multiple-anchor deployment. Store inputs outside version control, keep TA certificates current, and retain local policy files alongside the appropriate TALs. For all five RIRs, use the complete five-RIR input guide, including official sources, download commands, input checks, and the filenames used by Compose.

Docker first run

Follow the README Quick start. It creates output/summary.json, output/vrps.csv and output/result.ccr. State is retained under state/repository-db/. View warnings in the terminal and inspect the summary to distinguish rejected objects from successful repository updates.

Build from source

Install Rust 1.92 or newer. On Debian/Ubuntu, native build dependencies include:

sudo apt-get update
sudo apt-get install --no-install-recommends build-essential clang libclang-dev \
  pkg-config ca-certificates rsync time
cargo build --locked --release
target/release/panda-rpki --help

Run with the same inputs:

target/release/panda-rpki validate \
  --tal input/anchor.tal --ta input/anchor.cer \
  --rrdp-state-dir state --out output/native \
  --ccr-out output/native/result.ccr

For tests, install python3-cryptography and openssl. See Development and Usage for next steps.