azaks-conn
Fetch AKS kubeconfig and merge into ~/.kube/config by alias
Install
pip install azaks-conn
The package installs two console scripts that point at the same Typer app:
| Command | Use when |
|---|---|
azaks-conn |
Long form, friendly for scripts |
aksc |
Short alias for interactive shell use |
Installing with
pipxdrops the scripts in~/.local/bin. If that directory isn't on yourPATH, runpipx ensurepathand restart your shell.akscprints a one-line reminder to stderr if it detects this situation.
Usage
aksc --help
aksc --version
Four commands cover the alias lifecycle:
| Command | Purpose |
|---|---|
aksc connect CLUSTER [--alias NAME] [--resource-group RG] [--subscription SUB] [--admin] [--overwrite] |
Fetch AKS credentials and merge into ~/.kube/config under the given alias. |
aksc refresh ALIAS |
Re-fetch credentials for an existing alias using its recorded cluster / RG / subscription / admin flag. Useful after CA rotation or kubelogin cache expiry. |
aksc list |
Rich-table inventory of aksc-managed aliases (with provenance metadata). Add --json for machine-readable output, or --no-truncate to keep full column values (auto-enabled when piped). |
aksc verify ALIAS [--timeout N] |
Probe the alias's API server via kubectl cluster-info. |
aksc rm ALIAS [--force] |
Remove the alias from ~/.kube/config, the snapshot directory, and the state file. |
State lives in two places under ~/.kube/azaks-conn/:
<alias>— a single-context kubeconfig snapshot for each managed alias (mode0600)..aliases.json— JSON metadata (cluster, RG, subscription, admin flag, timestamp), used bylistandverify.
Security model
aksc connect shells out to az aks get-credentials. By default this fetches
an Entra ID (AAD) integrated kubeconfig: actual authentication still flows
through kubelogin and your Azure identity, and cluster RBAC applies.
The --admin flag passes through to az aks get-credentials --admin, which
returns a cluster-admin certificate in the kubeconfig. This bypasses Entra
ID and RBAC entirely — anyone with the file is cluster-admin until the
certificate expires (typically months).
aksc makes admin contexts visually obvious so they aren't accidentally
shared, committed, or left lying around:
aksc connect --adminprints a yellowwarning:line citing the bypass.aksc listflags the alias with a redADMINmarker in the Admin column.aksc verify <admin-alias>reprints the warning after each probe.- Both the merged entry in
~/.kube/configand the per-alias snapshot under~/.kube/azaks-conn/are written with mode0600.
Guidance:
- Prefer the default (AAD) flow whenever possible.
- Only use
--adminfor cluster bootstrap / break-glass work. - Treat any
--adminkubeconfig as a high-privilege secret — do not check it into source control, share it over chat, or copy it to shared hosts. aksc rm <admin-alias>is the fastest way to revoke local access; for full revocation, rotate the cluster admin credentials in Azure.
Development
git clone https://github.com/NaeemH/azaks-conn.git
cd azaks-conn
python -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]"
pre-commit install
# Run the standard checks
ruff check . && ruff format --check .
mypy src
pytest -q
Release
Releases are tag-driven. Bump src/azaks_conn/__about__.py, commit, then:
git tag v0.3.2
git push origin v0.3.2
.github/workflows/release.yml builds the sdist + wheel and publishes to PyPI
via Trusted Publishers (OIDC) — no API tokens involved.
License
Metadata
Release files for azaks-conn 0.3.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| azaks_conn-0.3.2.tar.gz | 24.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| azaks_conn-0.3.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 42.1 kB
Release files / azaks_conn-0.3.2.tar.gz
| Download URL | azaks_conn-0.3.2.tar.gz |
|---|---|
| Size | 24.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
238f34a62b6e02881cc2b6abe0e31d35f9e2df9552feab5a5435115a4dff4871
|
|
BLAKE2b-256 checksum How to use checksums |
eeeaec9bee8bca6b907722e87668d2fbe6ebcfca87f18e0285e8957936a53c8a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 26, 2026.
Transparency logRelease files / azaks_conn-0.3.2-py3-none-any.whl
| Download URL | azaks_conn-0.3.2-py3-none-any.whl |
|---|---|
| Size | 17.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0bd797fa2a8133162bbd9aa8daf97a33fd5400b64a240f36b305e0ec1d4586a6
|
|
BLAKE2b-256 checksum How to use checksums |
1e17271b58a978fea749b32b9205012d16fc0f2eb96b43059cede21435a6dc23
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 26, 2026.
Transparency log