$npx skillfedfor your agent

castellan

Generic Key Manager interface for OpenStack

With conditionsPyPI CryptographyReleased Jul 2026133.0K downloads / moApache-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — castellan-5.8.0-py3-none-any.whl
v5.8.0 · released 2026-07-10 · Python >=3.11 · 11 runtime deps: pbr, cryptography, python-barbicanclient, oslo.config, oslo.context, oslo.i18n, oslo.log, oslo.utils

Yes, if you are building or operating OpenStack services that need key management. The package is actively maintained, has no known vulnerabilities, and provides genuine value by decoupling your code from a specific key manager. If you are not working within an OpenStack environment or do not need key manager abstraction, it is not relevant.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.11 or later; intended for use within OpenStack environments where a key manager backend is configured and accessible.
  • Low install friction with a pure-Python wheel and active maintenance.
  • The dependency chain includes 11 runtime packages, mostly from the oslo and OpenStack ecosystems; all are standard library-style components with established track records.

License · maintenance · safety

Apache-2.0 (permissive) — Licensed under Apache-2.0 (permissive), allowing commercial and private use with minimal restrictions; suitable for proprietary OpenStack deployments.

last release 2026-07-10 (35 days)

0 known vulnerabilities (OSV.dev, 2026-08-14) · 132,956 downloads/mo, #11,533 on PyPI

Verify before relying

pip install castellan

from castellan import key_manager

manager = key_manager.KeyManager()
key = manager.create_key()
  • Whether the package works standalone or requires a running OpenStack/Barbican deployment
  • Configuration details and environment variables needed to initialize the key manager
  • Supported key manager backends beyond python-barbicanclient
  • Specific key creation and retrieval method signatures and parameters
Same gist for agents: .md · .json

What it is and what it does

Castellan is a generic key manager abstraction layer for OpenStack that provides a consistent Python interface to cryptographic key storage and retrieval. Rather than coupling OpenStack services directly to a specific key manager implementation, Castellan acts as a plugin-based gateway, allowing different backends to be swapped without changing application code.

The package depends on cryptography, python-barbicanclient, and several oslo libraries for configuration, logging, and context management. It uses stevedore for plugin discovery and keystoneauth1 for OpenStack authentication. This makes it suitable for OpenStack operators and developers building services that need to manage secrets securely without hard-coding a particular key manager choice.

Use it for

  • Abstract key manager interactions in OpenStack services so they can work with multiple backends
  • Store and retrieve encryption keys for data protection in OpenStack deployments
  • Integrate with key management systems through a unified API
  • Build OpenStack applications that need cryptographic key management without backend lock-in

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you are building or operating OpenStack services that need key management.

The package is actively maintained, has no known vulnerabilities, and provides genuine value by decoupling your code from a specific key manager. If you are not working within an OpenStack environment or do not need key manager abstraction, it is not relevant.

Install

castellan on PyPI

Before you install

Low install friction with a pure-Python wheel and active maintenance. The dependency chain includes 11 runtime packages, mostly from the oslo and OpenStack ecosystems; all are standard library-style components with established track records.

Requires Python 3.11 or later; intended for use within OpenStack environments where a key manager backend is configured and accessible.

License in practice

Licensed under Apache-2.0 (permissive), allowing commercial and private use with minimal restrictions; suitable for proprietary OpenStack deployments.

Quickstart

pip install castellan

from castellan import key_manager

manager = key_manager.KeyManager()
key = manager.create_key()

Verify before relying

  • Whether the package works standalone or requires a running OpenStack/Barbican deployment
  • Configuration details and environment variables needed to initialize the key manager
  • Supported key manager backends beyond python-barbicanclient
  • Specific key creation and retrieval method signatures and parameters

Package facts

LicenseApache-2.0 permissive
Python supportSupports the current Python release >=3.11
Install frictionLow. Pure-Python wheel
Runtime dependencies
11 packages
pbrcryptographypython-barbicanclientoslo.configoslo.contextoslo.i18noslo.logoslo.utilsstevedorekeystoneauth1requests
MaintenanceActively maintained 35 days since the last release
First released
Downloads132,956 / month, #11,533 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseOperating System :: POSIX :: LinuxProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Typing :: Typed

Evidence: castellan-5.8.0-py3-none-any.whl

Tags

Capabilities
openstack key managementkey manager interfacecryptographic key storageopenstack secrets managementbarbican client wrapperkey manager abstraction layer
Topics
openstackkey-managementcryptography

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “openstack key management”

  • castellanCastellan provides a unified interface for interacting with key…
  • python-barbicanclientPython client library and command-line tool for interacting with…
  • cursiveCursive validates digital signatures using OpenStack-specific logic,…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also keystone · keystoneauth1 · cursive · python-barbicanclient · os-ken · python-swiftclient · oslo.vmware · keystonemiddleware · python-openstackclient · obspec