Skip to main content

Argus server

Python MCP + FastAPI server. NetBox source-of-truth tools for coding agents and the Argus web dashboard. See the top-level README and docs/ARCHITECTURE.md.

Install

python -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]"

Configure

Copy .env.example to .env (or export the vars):

NETBOX_URL=https://netbox.lan
NETBOX_TOKEN=<netbox api token>
NETBOX_VERIFY_SSL=true
HTTP_HOST=0.0.0.0
HTTP_PORT=8080

# Optional — all default to off; see .env.example for the full list.
HTTP_TOKEN=                  # bearer token for /api + /webhooks (unset = open)
NETBOX_WEBHOOK_SECRET=       # verify NetBox X-Hook-Signature HMAC on /webhooks (unset = off)
SCHEDULE_INTERVAL=0          # scheduled drift loop: seconds between cycles (0 = off)
SCHEDULE_COLLECTOR=unifi     # collector the scheduled drift cycle runs
ALERT_WEBHOOK_URL=           # Slack-compatible webhook; alerts on detected drift
NETBOX_TENANT=               # shared-instance: stamp this tenant on objects reconcile creates (unset = single-tenant)

If unset, tools return a clear "NetBox not configured" message instead of erroring.

Run

argus-mcp     # MCP server over stdio (for Claude Code etc.)
argus-http    # FastAPI HTTP server on :8080 (for the web app + webhooks)

argus-maint-mcp  # separate maintenance MCP surface — release preview/verify (devtools; read-only)

The HTTP server also:

  • receives NetBox webhooks at POST /webhooks/netbox — it classifies and structured-logs each change event (observability only; no discovery or reconcile is triggered yet). Set NETBOX_WEBHOOK_SECRET to verify NetBox's X-Hook-Signature HMAC (HMAC-SHA512 of the raw body); a missing or mismatched signature is rejected 401 (unset leaves verification off).
  • runs an optional scheduled drift loop — set SCHEDULE_INTERVAL (seconds) and Argus discovers + diffs on that interval, read-only (never apply). The latest outcome is served at GET /api/drift/status, and setting ALERT_WEBHOOK_URL POSTs a Slack-compatible alert when drift is found.
  • gates /api + /webhooks behind a bearer token when HTTP_TOKEN is set (/health stays public); unset leaves the API open for local/dev use.

Examples

Enable API auth, then call /api/* with the bearer token:

export HTTP_TOKEN="$(openssl rand -hex 32)"
argus-http
curl -H "Authorization: Bearer $HTTP_TOKEN" http://localhost:8080/api/devices

Enable scheduled drift detection (every 5 min) with an optional Slack alert, then read the latest outcome:

export SCHEDULE_INTERVAL=300                                    # 0 = off
export SCHEDULE_COLLECTOR=unifi
export ALERT_WEBHOOK_URL="https://hooks.slack.com/services/…"   # optional
argus-http
curl http://localhost:8080/api/drift/status

Install from PyPI (the published distribution is argus-netbox; the import package stays argus and the console scripts are argus-mcp / argus-http):

pip install argus-netbox
argus-http     # or argus-mcp

Container images are published to GHCR — see the top-level README's Published artifacts.

Develop

ruff check src tests
mypy src           # must pass CI, same as ruff
pytest -v          # offline — NetBox is mocked

Tools

Tool Kind Status
list_devices, get_device, list_prefixes, list_ip_addresses, search read real (needs NetBox)
list_collectors, discovery_scan, network_topology discovery UniFi real — devices + clients + uplink topology (needs UNIFI_*); pfSense/OPNsense real — devices, firmware, role via SSH/SNMP (needs PFSENSE_HOST, PFSENSE_USERNAME, PFSENSE_PASSWORD, optional PFSENSE_USE_SNMP); SNMP/LLDP real for non-UniFi gear (validated via snmpsim replay): devices + LLDP links with local/remote ports, SNMPv2c or SNMPv3 (needs SNMP_TARGETS + argus-netbox[discovery]); list_collectors (also GET /api/collectors) surfaces each vendor pack's manufacturer/transport/capabilities/config_vars
drift_report, reconcile_apply reconcile real — diffs and (on confirm) persists, auto-creating supporting NetBox objects
evaluate_practices practices real — runs a collector's best-practice rules, returning advisory Findings (read-only; also GET /api/practices)
health meta real

Metadata

Release files for argus-netbox 0.2.7

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for argus-netbox 0.2.7
File Size Uploaded
argus_netbox-0.2.7.tar.gz 117.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for argus-netbox 0.2.7
File Interpreter ABI Platform
argus_netbox-0.2.7-py3-none-any.whl Python 3 none any Details

Total release size: 204.8 kB

Release files / argus_netbox-0.2.7.tar.gz

Download URL argus_netbox-0.2.7.tar.gz
Size 117.6 kB
Tags Source
SHA-256 checksum
How to use checksums
9937845ed09e11edafbebdfcd24e92a2c8cc57204c6b73b05ad953212debb60c
BLAKE2b-256 checksum
How to use checksums
f5ec294d4a95d2cab8673d9c6a233d83e2b21f6933b3789262657fd9975ed307
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release files / argus_netbox-0.2.7-py3-none-any.whl

Download URL argus_netbox-0.2.7-py3-none-any.whl
Size 87.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0076516204d40e8a1795252a3d8eeeb9634d135b5d9e00df25e7e754e391d44d
BLAKE2b-256 checksum
How to use checksums
1ab08073b7c87dd7b54436f38b35602ca7b1e914ed0ee62c12cc11f106645133
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release history Release notifications | RSS feed

0.2.8

2 release files

This release

0.2.7 This release

2 release files

0.2.6

2 release files

0.2.5

2 release files

0.2.4

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.7

2 release files

0.1.6

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page