# batfish/batfish

Batfish is a network configuration analysis tool that can find bugs and guarantee the correctness of (planned or current) network configurations. It enables network engineers to rapidly and safely evolve their network, without fear of outages or security breaches.

Repository: https://github.com/batfish/batfish
Canonical: https://ross.abutalabs.com/products/batfish
Homepage: http://www.batfish.org
Language: Java
License: Apache-2.0
License Family: permissive
Topics: network, configuration, configuration-parser, configuration-analysis, network-verification, network-analysis, network-security, network-validation, network-automation
Last push: 2026-08-26T18:44:55+00:00

## Health v2 (maintenance only)
Score: 67/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 8, longevity 100
- inputs: {"age_days": 4291, "days_push": 7, "days_rel": 422, "gap_med": null, "n_releases_24m": 1}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1460, forks 285 (observed 2026-08-28T04:04:47.332917+00:00)

## What it is
Batfish is an open-source network configuration analysis tool that builds complete models of network behavior from device configurations to find bugs and guarantee correctness of planned or current networks. It requires no direct device access and validates security, reliability, and compliance properties before deployment.

## Use cases
- validate network configuration changes before deployment
- find bugs and policy violations in router and firewall configs
- verify end-to-end reachability and failure impact across the network
- check ACL and firewall rule changes cause no collateral damage
- compare configurations from different vendors for functional equivalence
- audit configuration compliance for SSH, AAA, NTP, and MTU settings

## When to choose
- you need pre-deployment validation of network changes in CI/CD workflows
- you want correctness guarantees for reachability, security, and compliance without touching live devices
- you manage multi-vendor networks and need configuration analysis

## When to avoid
- you need real-time traffic monitoring or packet capture rather than configuration analysis
- your network devices' configurations are not available or are heavily generated outside standard vendor syntax

## Facets
- artifact type: service
- maturity: active
- function: security, testing, parser, configuration-management, developer-tools
- domain: networking, security
- platform: jvm, python, self-hosted
- tags: network-verification, network-configuration-analysis, intent-based-networking, pre-deployment-validation, network-automation, automation, devops, docker

## Member repositories
- batfish/batfish (main) score 67

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:47.332917+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:35:23.623473+00:00, confidence not recorded.
  - readme: https://github.com/batfish/batfish (fetched 2026-08-28T04:04:47.332917+00:00, sha c172b65e54fe)
  - homepage: http://www.batfish.org (fetched 2026-08-29T11:44:06.091224+00:00, sha 18af1e818731)
- Data as of 2026-08-30T08:39:29.467469+00:00.
