So I finally got around to (you know how it goes) updating our IRR objects (because someone (not me (okay maybe me)) let a /24 go stale in RADb) and I am once again (somehow? Again? Why?) doing this by hand via their web form (which, if you have not experienced it (and I envy you), is exactly as pleasant as you would imagine) (very much not pleasant)
Surely someone here has escaped this (hell) (manual hell) and can tell me what I am missing (besides the will to live) (and also besides hiring someone to do this (we tried (they left)))
What do you all use for IRR database management? (please say something other than "the web form" (I beg you))
I am use RADb web form also lah very painpul xixixi but I am buy yesterday a script from priend it is work not API just selenium xixixi very hacky only
You are try RIPE NCC API? They are have good dokumentasi I am hear
RIPE's API is decent if you're only in RIPE region. We have prefixes in APNIC and ARIN too, so that doesn't solve the whole problem. Their IRR is separate from the whois db anyway, you still need to handle RPSL objects somewhere.
I ended up writing Ansible templates that spit out RPSL, then I paste into RADb when I must. Not proud of it.
I am one of the everyone. Last time I looked it was still expecting you to hand-craft the peeringdb-to-IRR pipeline yourself, which is... not the automation I was hoping for.
Has anyone actually gotten irrtoolset to pull from PeeringDB directly? Or do you all maintain your as-set members by hand like cavemen?
at least. I generate prefix lists from IRR, not into it. Different direction.
For writing I use
rtconfig
from irrtoolset when I must, but mostly I avoid RADb entirely. NTTCOM IRR and RIPE are enough for my filters. If someone needs my /24 in RADb they can peer with me in RIPE instead.
This is the real problem. RIPE has one database, RADb has another, APNIC has whois-only for some legacy objects, ARIN has ARIN-NONAUTH which everyone side-eyes. The fragmentation is absurd.
I looked at IRRd for self-hosting but then you are just adding another source that nobody queries. The whole point is publication to the ones people actually check.
We pay PrefixBroker for some prefix management and they include IRR updates in their service. Not cheap but neither is my time. I don't know what they use under the hood, probably the same APIs we all have access to.
How does that work when you need to update an as-set at 2am because your new upstream wants it live before they accept the session? Do you ticket them and wait?
Genuine question, I have considered outsourcing but the latency scares me more than the web form.
They have an emergency contact but I've never used it. Honestly my as-set changes maybe twice a year. If you're adding upstreams that often you have bigger problems than IRR tooling.
For the record I still log into RADb directly for as-set changes. The web form is bad but it's not that bad for two changes a year.
Post a reply
You need an account to reply.
Log in or
register to join the conversation.