castellan
Generic Key Manager interface for OpenStack
Decision gist · record as of 2026-08-14
Yes, if you are building or operating OpenStack services that need key management. The package is actively maintained, has no known vulnerabilities, and provides genuine value by decoupling your code from a specific key manager. If you are not working within an OpenStack environment or do not need key manager abstraction, it is not relevant.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.11 or later; intended for use within OpenStack environments where a key manager backend is configured and accessible.
- Low install friction with a pure-Python wheel and active maintenance.
- The dependency chain includes 11 runtime packages, mostly from the oslo and OpenStack ecosystems; all are standard library-style components with established track records.
License · maintenance · safety
Apache-2.0 (permissive) — Licensed under Apache-2.0 (permissive), allowing commercial and private use with minimal restrictions; suitable for proprietary OpenStack deployments.
last release 2026-07-10 (35 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 132,956 downloads/mo, #11,533 on PyPI
Alternatives
Verify before relying
pip install castellan
from castellan import key_manager
manager = key_manager.KeyManager()
key = manager.create_key()- Whether the package works standalone or requires a running OpenStack/Barbican deployment
- Configuration details and environment variables needed to initialize the key manager
- Supported key manager backends beyond python-barbicanclient
- Specific key creation and retrieval method signatures and parameters
What it is and what it does
Castellan is a generic key manager abstraction layer for OpenStack that provides a consistent Python interface to cryptographic key storage and retrieval. Rather than coupling OpenStack services directly to a specific key manager implementation, Castellan acts as a plugin-based gateway, allowing different backends to be swapped without changing application code.
The package depends on cryptography, python-barbicanclient, and several oslo libraries for configuration, logging, and context management. It uses stevedore for plugin discovery and keystoneauth1 for OpenStack authentication. This makes it suitable for OpenStack operators and developers building services that need to manage secrets securely without hard-coding a particular key manager choice.
Use it for
- Abstract key manager interactions in OpenStack services so they can work with multiple backends
- Store and retrieve encryption keys for data protection in OpenStack deployments
- Integrate with key management systems through a unified API
- Build OpenStack applications that need cryptographic key management without backend lock-in
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are building or operating OpenStack services that need key management.
The package is actively maintained, has no known vulnerabilities, and provides genuine value by decoupling your code from a specific key manager. If you are not working within an OpenStack environment or do not need key manager abstraction, it is not relevant.
Install
castellan on PyPI
Before you install
Low install friction with a pure-Python wheel and active maintenance. The dependency chain includes 11 runtime packages, mostly from the oslo and OpenStack ecosystems; all are standard library-style components with established track records.
Requires Python 3.11 or later; intended for use within OpenStack environments where a key manager backend is configured and accessible.
License in practice
Licensed under Apache-2.0 (permissive), allowing commercial and private use with minimal restrictions; suitable for proprietary OpenStack deployments.
Quickstart
pip install castellan
from castellan import key_manager
manager = key_manager.KeyManager()
key = manager.create_key()
Verify before relying
- Whether the package works standalone or requires a running OpenStack/Barbican deployment
- Configuration details and environment variables needed to initialize the key manager
- Supported key manager backends beyond python-barbicanclient
- Specific key creation and retrieval method signatures and parameters
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.11 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 11 packagespbrcryptographypython-barbicanclientoslo.configoslo.contextoslo.i18noslo.logoslo.utilsstevedorekeystoneauth1requests |
| Maintenance | Actively maintained 35 days since the last release |
| First released | |
| Downloads | 132,956 / month, #11,533 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseOperating System :: POSIX :: LinuxProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Typing :: Typed |
Evidence: castellan-5.8.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “openstack key management”
- castellanCastellan provides a unified interface for interacting with key…
- python-barbicanclientPython client library and command-line tool for interacting with…
- cursiveCursive validates digital signatures using OpenStack-specific logic,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also keystone · keystoneauth1 · cursive · python-barbicanclient · os-ken · python-swiftclient · oslo.vmware · keystonemiddleware · python-openstackclient · obspec