azaks-bastion
Open an Azure Bastion tunnel to a private AKS API server or jump host.
Install
pip install azaks-bastion
The package installs two console scripts that point at the same Typer app:
| Command | Use when |
|---|---|
azaks-bastion |
Long form, friendly for scripts |
aksb |
Short alias for interactive shell use |
Usage
aksb --help
aksb --version
Discover Bastion hosts
# Table of Bastion hosts in the current subscription
aksb list
# Machine-readable, never truncated (good for scripts / piping)
aksb list --json
aksb list -s my-subscription
Open a tunnel to a private AKS jump host or API server
aksb tunnel wraps az network bastion tunnel, forwarding a local port to a
target's port through a Standard-SKU Bastion host. The target may be a full ARM
resource id or a VM name (with --target-rg).
# SSH jump host: forward an OS-assigned local port to the VM's port 22
aksb tunnel --bastion prod-hub-bastion --bastion-rg prod-hub-neu-rg \
--target jump-vm --target-rg prod-jump-rg
# Private API server: pin a local port and forward to 443
aksb tunnel -b prod-hub-bastion --bastion-rg prod-hub-neu-rg \
-t /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Compute/virtualMachines/jump \
--resource-port 443 --local-port 8443
The command runs in the foreground and prints the local endpoint
(127.0.0.1:<port>); press Ctrl-C to close the tunnel.
Development
git clone https://github.com/NaeemH/azaks-bastion.git
cd azaks-bastion
python -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]"
pre-commit install
# Run the standard checks
ruff check . && ruff format --check .
mypy src
pytest -q
Release
Releases are tag-driven. Bump src/azaks_bastion/__about__.py, commit, then:
git tag v0.1.0
git push origin v0.1.0
.github/workflows/release.yml builds the sdist + wheel and publishes to PyPI
via Trusted Publishers (OIDC) — no API tokens involved.
License
Metadata
Release files for azaks-bastion 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| azaks_bastion-0.1.0.tar.gz | 13.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| azaks_bastion-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 24.3 kB
Release files / azaks_bastion-0.1.0.tar.gz
| Download URL | azaks_bastion-0.1.0.tar.gz |
|---|---|
| Size | 13.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
68053402117eec0cbda1677e82e06d7d12a5b291760a03bacad61b01624e8428
|
|
BLAKE2b-256 checksum How to use checksums |
83070c09113678a814f2801805139eba72525b23534d018e3d0f0227de032919
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 27, 2026.
Transparency logRelease files / azaks_bastion-0.1.0-py3-none-any.whl
| Download URL | azaks_bastion-0.1.0-py3-none-any.whl |
|---|---|
| Size | 11.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
ac1c15eacd63beed6f2e62d1038f0ddb01a7528c733c915bb42a8cebabb42771
|
|
BLAKE2b-256 checksum How to use checksums |
cb521bee42ab1bba82474dd7dde8b9f6d532f7b9887accc6da476989af3e7373
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 27, 2026.
Transparency log