Skip to main content

Argus server

Python MCP + FastAPI server. NetBox source-of-truth tools for coding agents and the Argus web dashboard. See the top-level README and docs/ARCHITECTURE.md.

Install

python -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]"

Configure

Copy .env.example to .env (or export the vars):

NETBOX_URL=https://netbox.lan
NETBOX_TOKEN=<netbox api token>
NETBOX_VERIFY_SSL=true
HTTP_HOST=0.0.0.0
HTTP_PORT=8080

# Optional — all default to off; see .env.example for the full list.
HTTP_TOKEN=                  # bearer token for /api + /webhooks (unset = open)
NETBOX_WEBHOOK_SECRET=       # verify NetBox X-Hook-Signature HMAC on /webhooks (unset = off)
SCHEDULE_INTERVAL=0          # scheduled drift loop: seconds between cycles (0 = off)
SCHEDULE_COLLECTOR=unifi     # collector the scheduled drift cycle runs
ALERT_WEBHOOK_URL=           # Slack-compatible webhook; alerts on detected drift
NETBOX_TENANT=               # shared-instance: stamp this tenant on objects reconcile creates (unset = single-tenant)

If unset, tools return a clear "NetBox not configured" message instead of erroring.

Run

argus-mcp     # MCP server over stdio (for Claude Code etc.)
argus-http    # FastAPI HTTP server on :8080 (for the web app + webhooks)

argus-maint-mcp  # separate maintenance MCP surface — release preview/verify (devtools; read-only)

The HTTP server also:

  • receives NetBox webhooks at POST /webhooks/netbox — it classifies and structured-logs each change event (observability only; no discovery or reconcile is triggered yet). Set NETBOX_WEBHOOK_SECRET to verify NetBox's X-Hook-Signature HMAC (HMAC-SHA512 of the raw body); a missing or mismatched signature is rejected 401 (unset leaves verification off).
  • runs an optional scheduled drift loop — set SCHEDULE_INTERVAL (seconds) and Argus discovers + diffs on that interval, read-only (never apply). The latest outcome is served at GET /api/drift/status, and setting ALERT_WEBHOOK_URL POSTs a Slack-compatible alert when drift is found.
  • gates /api + /webhooks behind a bearer token when HTTP_TOKEN is set (/health stays public); unset leaves the API open for local/dev use.

Examples

Enable API auth, then call /api/* with the bearer token:

export HTTP_TOKEN="$(openssl rand -hex 32)"
argus-http
curl -H "Authorization: Bearer $HTTP_TOKEN" http://localhost:8080/api/devices

Enable scheduled drift detection (every 5 min) with an optional Slack alert, then read the latest outcome:

export SCHEDULE_INTERVAL=300                                    # 0 = off
export SCHEDULE_COLLECTOR=unifi
export ALERT_WEBHOOK_URL="https://hooks.slack.com/services/…"   # optional
argus-http
curl http://localhost:8080/api/drift/status

Install from PyPI (the published distribution is argus-netbox; the import package stays argus and the console scripts are argus-mcp / argus-http):

pip install argus-netbox
argus-http     # or argus-mcp

Container images are published to GHCR — see the top-level README's Published artifacts.

Develop

ruff check src tests
mypy src           # must pass CI, same as ruff
pytest -v          # offline — NetBox is mocked

Tools

Tool Kind Status
list_devices, get_device, list_prefixes, list_ip_addresses, search read real (needs NetBox)
list_collectors, discovery_scan, network_topology discovery UniFi real — devices + clients + uplink topology (needs UNIFI_*); pfSense/OPNsense real — devices, firmware, role via SSH/SNMP (needs PFSENSE_HOST, PFSENSE_USERNAME, PFSENSE_PASSWORD, optional PFSENSE_USE_SNMP); SNMP/LLDP real for non-UniFi gear (validated via snmpsim replay): devices + LLDP links with local/remote ports, SNMPv2c or SNMPv3 (needs SNMP_TARGETS + argus-netbox[discovery]); list_collectors (also GET /api/collectors) surfaces each vendor pack's manufacturer/transport/capabilities/config_vars
drift_report, reconcile_apply reconcile real — diffs and (on confirm) persists, auto-creating supporting NetBox objects
evaluate_practices practices real — runs a collector's best-practice rules, returning advisory Findings (read-only; also GET /api/practices)
health meta real

Metadata

Release files for argus-netbox 0.2.8

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for argus-netbox 0.2.8
File Size Uploaded
argus_netbox-0.2.8.tar.gz 117.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for argus-netbox 0.2.8
File Interpreter ABI Platform
argus_netbox-0.2.8-py3-none-any.whl Python 3 none any Details

Total release size: 204.7 kB

Release files / argus_netbox-0.2.8.tar.gz

Download URL argus_netbox-0.2.8.tar.gz
Size 117.6 kB
Tags Source
SHA-256 checksum
How to use checksums
6cd3f4ca922cbbce4de4c69b9c3e28e511d8b629ced83c521e5a772f06a5ca21
BLAKE2b-256 checksum
How to use checksums
be6f8fc99b8a2fc0591f2f8e1083ce4724ea170ffd682ff5f3f75fd412d3e2a3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release files / argus_netbox-0.2.8-py3-none-any.whl

Download URL argus_netbox-0.2.8-py3-none-any.whl
Size 87.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
39547abc3ee1d9461fd15d3fb4df7de735e352bf725535edda0a28b2070570d2
BLAKE2b-256 checksum
How to use checksums
8456c0ed46fb4c322af720b137e4ddff0bfa618ff376456efaf6163a3283249a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.8 This release

2 release files

0.2.7

2 release files

0.2.6

2 release files

0.2.5

2 release files

0.2.4

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.7

2 release files

0.1.6

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page