So I spent like 4 days tryign to make both IRR and RPKI work on the same prefix and almsot lost my mind. The documetnation is basically scattered acrss 5 RFCs and 3 differnet RIR wikis that contradict each othr. Heres what I figurd out so you dont cry.
IRR route objects are the old way. You put yr object in whois and peopel filter based on the maintner. Its "trust on first lookup" basically. RPKI ROAs are the cryptographc way. Signed by yr RIR. Validators check the chain. Both can coexist and most big transit now checks BOTH.
Key thing: ROA has maxLength. If you make a /24 ROA with maxLength 24 and annouce a /23, fail. Route object doesnt care about length just prefix. So you need both to match yr actual annoucement or you get "partial valid" which is basically "invalid" in practice.
I made a ROA for /22 with maxLength 22 but my route object said /24. 3 hours of debugign later I found the typo. The existental crisis was real. This guide is how I justify thsoe 3 hours to myslef. Dont be me. Check both.
Anyway IRR is legacy but still requierd for many peers. RPKI is future but not universal. Run both. Keep them syncd. Or youll be the one crying at 3am when yr prefix drops from half the internet.
You figure it out