Skip to main content

panorama-super-cli (psc)

PyPI CI Docs License

Agent-friendly object management for Palo Alto Panorama. Find where an IP lives, hunt down duplicate address/service objects, merge them safely (rewriting every group and rule that referenced them), enforce naming conventions, and audit object hygiene — all dry-run by default, with PAN-OS set and JSON output for humans and agents alike.

$ psc --config panorama.xml find ip 10.0.0.10
$ psc --config panorama.xml dedup addresses
$ psc --config panorama.xml dedup merge --keep h-web1 --remove web-primary --apply --out fixed.xml

v1.0.0. From this release psc follows SemVer: the CLI surface, JSON contracts, and exit codes are stable public API. Writes are dry-run by default; nothing touches Panorama without --apply.

Why

Panorama configs rot: the same 10.0.0.10 ends up as h-web1, web-primary, and WEB_PRD_01; services duplicate well-known ports; objects outlive the rules that used them. psc gives you a fast, scriptable, safe way to see and fix that — offline against an exported config, or live against Panorama.

Install

uv tool install panorama-super-cli      # recommended
# or
pipx install panorama-super-cli
# or
pip install panorama-super-cli

Two ways to point it at a config

  • Offline (no credentials, totally safe): psc --config exported.xml <cmd>. Export from Panorama (scp export configuration ... or the GUI) and audit it on your laptop.
  • Live: configure a profile (psc init, psc login) and psc talks the PAN-OS XML API via pan-os-python. Reads are free; writes still require --apply.

What it does

Area Commands
Find / resolve psc find ip <ip>, find ip -e <ip> (exact only), find ip --resolve-fqdn (opt-in DNS), find ip -f ips.txt, find object <name> — listings carry a tags column
Duplicates psc dedup addresses, dedup services, dedup groups, dedup tags, dedup merge (pairwise or --group <value>), dedup merge-group, dedup promote (cross-DG duplicate → shared, incl. tags)
Audit psc audit overlaps (overlapping/contained CIDR ranges), audit services-vs-wellknown
Diff psc diff a.xml b.xml, diff --device-group A --against B
Object CRUD psc set address|address-group|service|service-group|tag ... (create/update with PAN-OS validation)
Import / export psc export <kind> (NDJSON), psc set <kind> -f objs.ndjson (bulk import)
Rule edits psc rule edit-member --rule R --field F --add/--remove M (idempotent)
Decommission / move psc decommission <ip|cidr>... (reference-safe teardown), psc move <kind> <name> --from --to [--cascade]
Naming psc name lint, name apply --object / --all (opt-in templates)
References psc refs used <object>, refs unused [--ignore-disabled], refs dangling (used and dangling rows carry the referrer's tags)
Workbench psc workbench (psc w) — interactive TUI, full CLI parity
Output `--output json

See the docs for the full surface, the safety model, and the agent guide.

Workbench (interactive TUI)

Prefer a cockpit to one-shot commands? psc workbench (alias psc w) is a keyboard-driven Textual TUI at full CLI parity. Search objects, multi-select them into a persistent buffer, route the selection into a spoke (dedup, move, rename, decommission, rule edits, audits, naming, create, group the selection with N, …), and stage plans into a git-like changelist that applies as one batch — as a set script, an offline config write, or a live candidate push (never a commit). Same safety model as the CLI throughout.

psc --config panorama.xml workbench
psc -p prod w --output-mode live-apply

See the Workbench guide.

Safety model

  • Dry-run is the default. Every mutating command prints a plan and exits without touching anything unless you add --apply.
  • Side-effect aware. Merging or renaming an object rewrites every address group, security rule, and NAT rule that referenced it — across shared and device-groups — or refuses and tells you why.
  • --debug streams structured logs to stderr; stdout stays clean for pipes.

For AI agents

psc ships a bundled Agent Skill and emits a stable JSON envelope + exit-code contract. Pass --output json and parse away. Drop the Skill where your harness loads it with psc skill install:

psc skill install --target claude-code --apply   # or codex | gemini | copilot

See Using with AI agents.

License

Apache-2.0.

Metadata

Release files for panorama-super-cli 1.13.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for panorama-super-cli 1.13.0
File Size Uploaded
panorama_super_cli-1.13.0.tar.gz 502.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for panorama-super-cli 1.13.0
File Interpreter ABI Platform
panorama_super_cli-1.13.0-py3-none-any.whl Python 3 none any Details

Total release size: 775.8 kB

Release files / panorama_super_cli-1.13.0.tar.gz

Download URL panorama_super_cli-1.13.0.tar.gz
Size 502.4 kB
Tags Source
SHA-256 checksum
How to use checksums
270d07785860230bffeb9c1d993619bfa337c5dd0adff5f8b7c883d467e8dccc
BLAKE2b-256 checksum
How to use checksums
15c6e1818314dc07b77123790cdccd3f4a3212dce82ea6a8b85fa368ce9835c2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 11, 2026.

Transparency log

Release files / panorama_super_cli-1.13.0-py3-none-any.whl

Download URL panorama_super_cli-1.13.0-py3-none-any.whl
Size 273.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ebcce9098d6b3b1d5c0a3e6544d7e8e7242329be6141e1c8559122be5b137eef
BLAKE2b-256 checksum
How to use checksums
13ba3e687e347025476e20dd8f9c3af50462d6cec32e0763d24167eb5b4c681f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 11, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.13.0 This release

2 release files

1.12.1

2 release files

1.12.0

2 release files

1.11.0

2 release files

1.10.0

2 release files

1.9.0

2 release files

1.8.0

2 release files

1.7.0

2 release files

1.6.0

2 release files

1.5.1

2 release files

1.5.0

2 release files

1.4.0

2 release files

1.3.1

2 release files

1.3.0

2 release files

1.2.0

2 release files

1.1.2

2 release files

1.1.1

2 release files

1.1.0

2 release files

1.0.0

2 release files

0.5.0

2 release files

0.4.3

2 release files

0.4.2

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.6

2 release files

0.2.5

2 release files

0.2.4

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page