Skip to main content

airflow-provider-darkmoon

Apache Airflow provider for Darkmoon, the autonomous AI penetration testing platform. Start a pentest campaign from a DAG, wait for it, and use the findings (or a severity gate) in the rest of your pipeline.

Open source vs Pro. The Darkmoon engine and CLI are open source (GPL-3.0). The Dashboard API this provider talks to is part of Darkmoon Pro and is self-hosted by you: there is no public hosted endpoint. This provider needs a reachable Darkmoon Pro dashboard, a dashboard user, and an Airflow worker that can reach it. If you only run the open-source CLI, use the CLI JSON/SARIF output or the ASCIT31/darkmoon-action GitHub Action instead.

Only run assessments against systems you own or are explicitly authorised to test. Findings can contain false positives and need review by a qualified human. This provider never triggers remediation or merges anything.

Not an Apache Software Foundation provider: it is a community package (airflow-provider-*, see the Airflow ecosystem page).

Install

pip install airflow-provider-darkmoon

Requires Python 3.9+ and Apache Airflow 2.7+ (tested on Airflow 3). Airflow discovers the provider through the apache_airflow_provider entry point.

Connection

Create a connection of type Darkmoon (id darkmoon_default by default):

Field Value
Dashboard API URL (Host) https://darkmoon.example.com
Username / Password a Darkmoon dashboard user
Extra (JSON, optional) {"verify_ssl": true, "timeout": 60}
airflow connections add darkmoon_default --conn-type darkmoon \
  --conn-host https://darkmoon.example.com --conn-login admin --conn-password '***'

What is included

Class Purpose
darkmoon_provider.hooks.darkmoon.DarkmoonHook Login (JWT, auto re-login on 401), run campaign, poll run log, list campaigns, findings, report
darkmoon_provider.operators.darkmoon.DarkmoonRunPentestOperator Start a campaign, optionally wait, return findings via XCom, optional fail_on_severity gate, stops the run on timeout/kill
darkmoon_provider.operators.darkmoon.DarkmoonGetFindingsOperator Fetch findings + severity stats of an existing campaign
darkmoon_provider.sensors.darkmoon.DarkmoonRunSensor Wait for a run to finish (run_completed succeeds, run_error fails); supports mode="reschedule"

Example

import pendulum
from airflow import DAG
from darkmoon_provider.operators.darkmoon import DarkmoonRunPentestOperator

with DAG("darkmoon_staging_pentest", start_date=pendulum.datetime(2026, 1, 1), schedule=None, catchup=False):
    DarkmoonRunPentestOperator(
        task_id="pentest_and_gate",
        target="https://staging.example.com",
        focus="auth, injection",
        fail_on_severity="high",   # fail the task if any finding is high or critical
        timeout=2 * 3600,
    )

The task returns a dict (run_id, campaign_id, total, stats, findings). A complete example, including the start / sensor split, is in darkmoon_provider/example_dags/.

API endpoints used

Same Dashboard API surface as the langchain-darkmoon package: POST /api/v1/auth/login, POST /api/v1/run/campaign, GET /api/v1/run/logs/{run_id}, DELETE /api/v1/run/{run_id}/stop, GET /api/v1/campaigns, GET /api/v1/vulnerabilities?campaign_id=, GET /api/v1/campaigns/{id}/report.

Development

pip install -e '.[test]'
pytest

Tests mock the HTTP layer; no Darkmoon instance is needed.

License

Apache-2.0. Darkmoon itself is GPL-3.0 and is not bundled here.

Metadata

Release files for airflow-provider-darkmoon 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for airflow-provider-darkmoon 0.1.0
File Size Uploaded
airflow_provider_darkmoon-0.1.0.tar.gz 16.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for airflow-provider-darkmoon 0.1.0
File Interpreter ABI Platform
airflow_provider_darkmoon-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 33.5 kB

Release files / airflow_provider_darkmoon-0.1.0.tar.gz

Download URL airflow_provider_darkmoon-0.1.0.tar.gz
Size 16.4 kB
Tags Source
SHA-256 checksum
How to use checksums
0e016fba51c874c5a1bb7b96e3deeaee5608811fd4f77537ab34841dc62613d6
BLAKE2b-256 checksum
How to use checksums
3d95d8ae4950eaf977f6c04e999e0f061580f4d574dfaecc234120e1fa0b985b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.9

Release files / airflow_provider_darkmoon-0.1.0-py3-none-any.whl

Download URL airflow_provider_darkmoon-0.1.0-py3-none-any.whl
Size 17.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e94491ed8f4004dc0b7fea2cd510ac867c0799e378925ba339770538f5fbb7cc
BLAKE2b-256 checksum
How to use checksums
b39b63e34181971be1cb3d29b99d9695a129800ac16bcb179873bdaa4ae88431
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.9

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page