tool
early
MIT
srxsync
Golden-source SRX fleet sync
Keeps a fleet of Juniper SRX firewalls in sync with a designated master SRX, with commit confirmed safety rails, drift detection and per-target include lists.
About
srxsync reads selected configuration sections from a master Juniper SRX and pushes them to a list of target devices, so a golden device can drive the rest of the fleet.
Every load is paired with commit confirmed, so a crash or network drop between steps auto-rolls back the SRX.
Features
- Sync categories: objects, policies, NAT, QoS and zones; interfaces, routing and system are never cross-synced
- Each target's include list names exactly what it receives, with no implicit inheritance
- srxsync check reports drift; push supports --replace or --merge and --dry-run
- Secret providers: env, netrc, keyring and Vault
- Default PyEZ transport, with an optional Rust-backed rustez transport
Quick start
Install
python -m venv .venv
source .venv/bin/activate
pip install -e .[dev]Check, then push
srxsync check --inventory inv.yaml --verbose
srxsync push --inventory inv.yaml --merge --commit-confirmed 5