Yeah so don't do that.

You are going to run a policy like that. Then you should absol utely run your own validator, hardcode the customers that you are expecting into a SLURM file, or ensure that your customers are not allowed to single home with you

It is a very bad idea to rely on rpki data always returning valid (vs being okay with not found state).

The immediate thing that comes to mind is that if any of your customers are on ARIN signed space, ARIN, for some reason, Will occasionally just turn stuff off to try and see what happens (I am slightly exaggerating. They have a bit of a more scientific reasoning but (in my professional opinion) it's not that much better.)

On Thu, Jul 30, 2026, 20:22 Stefan-Gabriel Lungu <hi@lungustefan.com> wrote:
> 3) A outage on all RTR sessions should ideally not impact you in a
meaningful operational way, RPKI "unknown"/"not-founds" should fail
open, otherwise you are at the mercy of many other possible problems

From downstream customers, RPKI unknowns are dropped.

Thanks,
Stefan.


Sent from Proton Mail for iOS.

-------- Original Message --------
On Thursday, 07/30/26 at 22:15 Ben Cartwright-Cox <ripencc@benjojo.co.uk> wrote:
I know that you have specifically said that you do not want your
routers to depend on the reachability of infrastructure that you
operate yourself, but you really should actually just run a RPKI
Validator yourself.

1) You almost certainly do not have any contractual agreement with
cloudflare that they are going to operate a service that will stay
online and correct (in a way that does not damage your business!)

2) Running such infrastructure is typically quite easy, especially in
the case of Routinator or rpki-client + StayRTR (the latter I'm pretty
sure being what cloudflare uses anyway), I /personally/ wouldn't
recommend FORT

3) A outage on all RTR sessions should ideally not impact you in a
meaningful operational way, RPKI "unknown"/"not-founds" should fail
open, otherwise you are at the mercy of many other possible problems

I do know that this is not the question you're asking but the
existence of this email is provoking further questions about what your
infrastructure is configured to do and what your models of reliability
risk you are running on

Regards

Ben

On Thu, 30 Jul 2026 at 18:47, Stefan-Gabriel Lungu via routing-wg
<routing-wg@ripe.net> wrote:
>
> Hello everyone,
>
> I'm looking for recommendations for reliable public RPKI RTR (RFC 8210) servers, excluding Cloudflare.
>
> I know the common recommendation is to run my own validator, but in my particular case I'd prefer to use one or more independently operated public RTR servers instead.
>
> The main reason is that I don't want my routers to depend on the reachability of infrastructure that I operate myself. I'd rather have RTR connectivity provided by infrastructure that is operationally independent of my own network.
>
> Does anyone know of operators that intentionally provide public RTR servers suitable for production use?
>
> Thank you,
> Stefan
> -----
> To unsubscribe from this mailing list or change your subscription options, please visit: https://mailman.ripe.net/mailman3/lists/routing-wg.ripe.net/
> As we have migrated to Mailman 3, you will need to create an account with the email matching your subscription before you can change your settings.
> More details at: https://www.ripe.net/membership/mail/mailman-3-migration/