Skip to content

RPKI ROAs hurt small networks more than help

Networking Locked by wilmaethqn44 24 replies 3.6K views
This thread is locked — new replies are not accepted. (Wrong category — please repost)
2 #11

uma said:
4.7 percent
Versus 0.3 percent

This is the structural story. Large networks have NOC shifts, automated certificate renewal, and integration with their asset management. Small networks have a person who remembers the password. When that person leaves, the ROA expires, and the prefix becomes invalid. The risk is not theoretical; I have seen it in practice.

The RIPE NCC does not provide grace periods — https://www.ripe.net. The moment of expiry is the moment of invalidation.

Neuland. Aber schnell.
#12
Fritz48 said:
RUN THE NUMBERS

I did. My /24 with ROA cost me $38 this year. Same block without ROA going for $11 on LowEndTalk. The market is pricing the headache into the asset.

Hetzner charges nothing extra for RPKI but their panel is cryptic. One wrong click and you're explaining to your users why traceroute dies at AS6939.

world record: 4min Arch install
#13

512MB club checking in. I dont even have a /24, I have a single IPv4 on my €3.50 Hetzner instance. What is ROA going to do for me except make my control panel scarier.

#14
lisbonred said:
4.7 percent feels low

I stand by it. RackNerd's Amsterdam location is fine for latency but their RPKI implementation is basically "check this box and pray." No key rotation notification, no expiry warning. I moved my test prefixes off them after the second silent invalidation.

center807 said:
Enterprise-grade RPKI deployment

Nobody asked. This is a thread about small networks.

#15
Berlin1 said:
Recieved quote from one vendor

Update: vendor came back at $0.08 per prefix per month with 12 month minimum. For my 6 clients thats $5.76/year which is fine but they want API access to my RIPE account and I'm supposed to trust that?? My margins on these Vultr resells are thinner than my patience.

your margin is my opportunity
#16
WalnutLinux said:
Same, my provider also rotated keys without telling me

This is the pattern I am documenting. Provider-managed RPKI is attractive because it offloads complexity, but it creates a dependency on provider communication discipline. In my dataset, 31 percent of small-network invalidations trace to provider-side key events without customer notification.

I am building a public alert feed for this. DM me if you want early access.

436 days. reboot is surrender.
#17
Buenos said:
We have sunday afternoon and hope!

This. I spent my Sunday trying to fix RPKI instead of doing my actual websites. My flower shop orders are down because I was messing with this instead of uploading new arrangements.

Is there a provider that just handles it without me touching anything?? I dont even care about the cost at this point.

frames, tables, still valid HTML
#18

My database replication is more reliable than my ROA renewal and that is saying something. I use Vultr Mexico City and their RPKI is "managed" which apparently means they do it until they dont. No SLA on that part.

#19
diegoracks said:
Same, my provider also rotated keys without telling me

This is why I run five providers. When Hetzner broke my ROA last quarter I shifted traffic to Vultr Singapore — https://www.vultr.com — while I fixed it. Cost me $7 in egress. Insurance, basically.

RPKI is just another failure mode to distribute.

#20
wilmaethqn44 said:
Is there a provider that just handles it without me touching anything??

No. Is always your problem at end. The provider say "managed" but when break is your prefix dead, not theirs. I learn this with RackNerd. Now I check every monday like old man with pills.

Thread closed

Replies are closed on this thread. Wrong category — please repost.