yuyr 5d18fa8992
Some checks failed
ci / public-tree (push) Has been cancelled
ci / docs (push) Has been cancelled
ci / rust (push) Has been cancelled
ci / docker-runtime (push) Has been cancelled
20260903 同步 RRDP RFC9674 同源防护
2026-09-03 12:10:57 +08:00
2026-09-01 12:13:53 +08:00
2026-09-01 12:13:53 +08:00

panda-rpki

panda-rpki is an RPKI synchronization and validation runtime written in Rust. The first component, panda-rpki-validator, fetches RPKI repositories through RRDP or rsync, validates the resulting object graph, and writes a structured run directory containing reports, payload CSV files, and canonical artifacts.

The project is currently a pre-release. Its command-line interface, output directory contract, container runtime, and supported deployment practices are documented in the Sphinx source tree at docs/source. The source is provided under the BSD 3-Clause License; public support and release policies will be published before a production release.

Quick start

Build and test the validator from a checkout:

cargo build --locked -p panda-rpki-validator
cargo test --locked -p panda-rpki-validator
cargo fmt --all --check
cargo clippy --locked -p panda-rpki-validator --all-targets -- -D warnings

Build a local amd64 runtime image:

./scripts/docker/build_image.sh --arch amd64 --allow-dirty
./scripts/docker/verify_image.sh \
  --image panda-rpki-validator:0.1.0-dirty-amd64

The checked-in TAL and trust-anchor files are bootstrap inputs, not a bundled offline repository snapshot. A deterministic offline run requires a reviewed replay archive supplied by the operator. The runtime wrapper writes normal run artifacts below RUN_ROOT/runs/run_0001.

Documentation

The documentation website is built with Sphinx and the Read the Docs Sphinx Theme. Before the hosted site is configured, build it locally:

python -m pip install -r docs/requirements.txt
sphinx-build -W --keep-going -b html docs/source docs/_build/html

Start with docs/source/getting-started.rst. It links to configuration, CLI, operations, testing, development, architecture, and output-contract material.

This project is licensed under the BSD 3-Clause License.

Safety and support

RPKI inputs are network- and attacker-controlled data. Run the validator with a dedicated writable data directory and follow the resource and retention guidance in the operations documentation. Do not place credentials, production state, or private trust-anchor material in this repository or a container image.

The public security-reporting and support channels are not yet assigned. Until they are published, do not disclose a suspected vulnerability in a public issue or commit.

Description
No description provided
Readme BSD-3-Clause 1.5 MiB
Languages
Rust 97.6%
Shell 2%
Python 0.2%
Dockerfile 0.2%