mechub sovereign network-security automation ← all projects
tool early MIT

srxsync

Golden-source SRX fleet sync

Keeps a fleet of Juniper SRX firewalls in sync with a designated master SRX, with commit confirmed safety rails, drift detection and per-target include lists.

About

srxsync reads selected configuration sections from a master Juniper SRX and pushes them to a list of target devices, so a golden device can drive the rest of the fleet.

Every load is paired with commit confirmed, so a crash or network drop between steps auto-rolls back the SRX.

Features

  • Sync categories: objects, policies, NAT, QoS and zones; interfaces, routing and system are never cross-synced
  • Each target's include list names exactly what it receives, with no implicit inheritance
  • srxsync check reports drift; push supports --replace or --merge and --dry-run
  • Secret providers: env, netrc, keyring and Vault
  • Default PyEZ transport, with an optional Rust-backed rustez transport

Quick start

Install

python -m venv .venv
source .venv/bin/activate
pip install -e .[dev]

Check, then push

srxsync check --inventory inv.yaml --verbose
srxsync push --inventory inv.yaml --merge --commit-confirmed 5

Full instructions in the README ↗