Skip to main content

Argus server

Python MCP + FastAPI server. NetBox source-of-truth tools for coding agents and the Argus web dashboard. See the top-level README and docs/ARCHITECTURE.md.

Install

python -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]"

Configure

Copy .env.example to .env (or export the vars):

NETBOX_URL=https://netbox.lan
NETBOX_TOKEN=<netbox api token>
NETBOX_VERIFY_SSL=true
HTTP_HOST=0.0.0.0
HTTP_PORT=8080

# Optional — all default to off; see .env.example for the full list.
HTTP_TOKEN=                  # bearer token for /api + /webhooks (unset = open)
NETBOX_WEBHOOK_SECRET=       # verify NetBox X-Hook-Signature HMAC on /webhooks (unset = off)
SCHEDULE_INTERVAL=0          # scheduled drift loop: seconds between cycles (0 = off)
SCHEDULE_COLLECTOR=unifi     # collector the scheduled drift cycle runs
ALERT_WEBHOOK_URL=           # Slack-compatible webhook; alerts on detected drift
NETBOX_TENANT=               # shared-instance: stamp this tenant on objects reconcile creates (unset = single-tenant)

If unset, tools return a clear "NetBox not configured" message instead of erroring.

Run

argus-mcp     # MCP server over stdio (for Claude Code etc.)
argus-http    # FastAPI HTTP server on :8080 (for the web app + webhooks)

argus-maint-mcp  # separate maintenance MCP surface — release preview/verify (devtools; read-only)

The HTTP server also:

  • receives NetBox webhooks at POST /webhooks/netbox — it classifies and structured-logs each change event (observability only; no discovery or reconcile is triggered yet). Set NETBOX_WEBHOOK_SECRET to verify NetBox's X-Hook-Signature HMAC (HMAC-SHA512 of the raw body); a missing or mismatched signature is rejected 401 (unset leaves verification off).
  • runs an optional scheduled drift loop — set SCHEDULE_INTERVAL (seconds) and Argus discovers + diffs on that interval, read-only (never apply). The latest outcome is served at GET /api/drift/status, and setting ALERT_WEBHOOK_URL POSTs a Slack-compatible alert when drift is found.
  • gates /api + /webhooks behind a bearer token when HTTP_TOKEN is set (/health stays public); unset leaves the API open for local/dev use.

Examples

Enable API auth, then call /api/* with the bearer token:

export HTTP_TOKEN="$(openssl rand -hex 32)"
argus-http
curl -H "Authorization: Bearer $HTTP_TOKEN" http://localhost:8080/api/devices

Enable scheduled drift detection (every 5 min) with an optional Slack alert, then read the latest outcome:

export SCHEDULE_INTERVAL=300                                    # 0 = off
export SCHEDULE_COLLECTOR=unifi
export ALERT_WEBHOOK_URL="https://hooks.slack.com/services/…"   # optional
argus-http
curl http://localhost:8080/api/drift/status

Install from PyPI (the published distribution is argus-netbox; the import package stays argus and the console scripts are argus-mcp / argus-http):

pip install argus-netbox
argus-http     # or argus-mcp

Container images are published to GHCR — see the top-level README's Published artifacts.

Develop

ruff check src tests
mypy src
pytest -v          # offline — NetBox is mocked

Tools

Tool Kind Status
list_devices, get_device, list_prefixes, list_ip_addresses, search read real (needs NetBox)
list_collectors, discovery_scan, network_topology discovery UniFi real — devices + clients + uplink topology (needs UNIFI_*); pfSense/OPNsense real — devices, firmware, role via SSH/SNMP (needs PFSENSE_HOST, PFSENSE_USERNAME, PFSENSE_PASSWORD, optional PFSENSE_USE_SNMP); SNMP/LLDP real for non-UniFi gear (validated via snmpsim replay): devices + LLDP links with local/remote ports, SNMPv2c or SNMPv3 (needs SNMP_TARGETS + argus-netbox[discovery]); list_collectors (also GET /api/collectors) surfaces each vendor pack's manufacturer/transport/capabilities/config_vars
drift_report, reconcile_apply reconcile real — diffs and (on confirm) persists, auto-creating supporting NetBox objects
evaluate_practices practices real — runs a collector's best-practice rules, returning advisory Findings (read-only; also GET /api/practices)
health meta real

Metadata

Release files for argus-netbox 0.2.6

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for argus-netbox 0.2.6
File Size Uploaded
argus_netbox-0.2.6.tar.gz 114.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for argus-netbox 0.2.6
File Interpreter ABI Platform
argus_netbox-0.2.6-py3-none-any.whl Python 3 none any Details

Total release size: 201.8 kB

Release files / argus_netbox-0.2.6.tar.gz

Download URL argus_netbox-0.2.6.tar.gz
Size 114.7 kB
Tags Source
SHA-256 checksum
How to use checksums
bb965a962c530704b9b1fa99d363a44888b632f7de27b835d7c4c61764abf396
BLAKE2b-256 checksum
How to use checksums
2ae53ca55fc2c4a8f36e55349438ca1e32d7290be0a0848fb6e03f081bc889ab
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.

Transparency log

Release files / argus_netbox-0.2.6-py3-none-any.whl

Download URL argus_netbox-0.2.6-py3-none-any.whl
Size 87.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e851a5f37df500814903f20fa045cea66214732bebd27b6b1733c25834fac9a3
BLAKE2b-256 checksum
How to use checksums
f52e9007e7b1fb5699a679516794709dc33efae22fb01ac38300f9a26b6bfb0d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.

Transparency log

Release history Release notifications | RSS feed

0.2.8

2 release files

0.2.7

2 release files

This release

0.2.6 This release

2 release files

0.2.5

2 release files

0.2.4

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.7

2 release files

0.1.6

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page