Skip to main content

azaks-conn

Fetch AKS kubeconfig and merge into ~/.kube/config by alias

Install

pip install azaks-conn

The package installs two console scripts that point at the same Typer app:

Command Use when
azaks-conn Long form, friendly for scripts
aksc Short alias for interactive shell use

Installing with pipx drops the scripts in ~/.local/bin. If that directory isn't on your PATH, run pipx ensurepath and restart your shell. aksc prints a one-line reminder to stderr if it detects this situation.

Usage

aksc --help
aksc --version

Four commands cover the alias lifecycle:

Command Purpose
aksc connect CLUSTER [--alias NAME] [--resource-group RG] [--subscription SUB] [--admin] [--overwrite] Fetch AKS credentials and merge into ~/.kube/config under the given alias.
aksc refresh ALIAS Re-fetch credentials for an existing alias using its recorded cluster / RG / subscription / admin flag. Useful after CA rotation or kubelogin cache expiry.
aksc list Rich-table inventory of aksc-managed aliases (with provenance metadata). Add --json for machine-readable output, or --no-truncate to keep full column values (auto-enabled when piped).
aksc verify ALIAS [--timeout N] Probe the alias's API server via kubectl cluster-info.
aksc rm ALIAS [--force] Remove the alias from ~/.kube/config, the snapshot directory, and the state file.

State lives in two places under ~/.kube/azaks-conn/:

  • <alias> — a single-context kubeconfig snapshot for each managed alias (mode 0600).
  • .aliases.json — JSON metadata (cluster, RG, subscription, admin flag, timestamp), used by list and verify.

Security model

aksc connect shells out to az aks get-credentials. By default this fetches an Entra ID (AAD) integrated kubeconfig: actual authentication still flows through kubelogin and your Azure identity, and cluster RBAC applies.

The --admin flag passes through to az aks get-credentials --admin, which returns a cluster-admin certificate in the kubeconfig. This bypasses Entra ID and RBAC entirely — anyone with the file is cluster-admin until the certificate expires (typically months).

aksc makes admin contexts visually obvious so they aren't accidentally shared, committed, or left lying around:

  • aksc connect --admin prints a yellow warning: line citing the bypass.
  • aksc list flags the alias with a red ADMIN marker in the Admin column.
  • aksc verify <admin-alias> reprints the warning after each probe.
  • Both the merged entry in ~/.kube/config and the per-alias snapshot under ~/.kube/azaks-conn/ are written with mode 0600.

Guidance:

  • Prefer the default (AAD) flow whenever possible.
  • Only use --admin for cluster bootstrap / break-glass work.
  • Treat any --admin kubeconfig as a high-privilege secret — do not check it into source control, share it over chat, or copy it to shared hosts.
  • aksc rm <admin-alias> is the fastest way to revoke local access; for full revocation, rotate the cluster admin credentials in Azure.

Development

git clone https://github.com/NaeemH/azaks-conn.git
cd azaks-conn
python -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]"
pre-commit install

# Run the standard checks
ruff check . && ruff format --check .
mypy src
pytest -q

Release

Releases are tag-driven. Bump src/azaks_conn/__about__.py, commit, then:

git tag v0.3.2
git push origin v0.3.2

.github/workflows/release.yml builds the sdist + wheel and publishes to PyPI via Trusted Publishers (OIDC) — no API tokens involved.

License

MIT

Metadata

Release files for azaks-conn 0.3.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for azaks-conn 0.3.2
File Size Uploaded
azaks_conn-0.3.2.tar.gz 24.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for azaks-conn 0.3.2
File Interpreter ABI Platform
azaks_conn-0.3.2-py3-none-any.whl Python 3 none any Details

Total release size: 42.1 kB

Release files / azaks_conn-0.3.2.tar.gz

Download URL azaks_conn-0.3.2.tar.gz
Size 24.6 kB
Tags Source
SHA-256 checksum
How to use checksums
238f34a62b6e02881cc2b6abe0e31d35f9e2df9552feab5a5435115a4dff4871
BLAKE2b-256 checksum
How to use checksums
eeeaec9bee8bca6b907722e87668d2fbe6ebcfca87f18e0285e8957936a53c8a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 26, 2026.

Transparency log

Release files / azaks_conn-0.3.2-py3-none-any.whl

Download URL azaks_conn-0.3.2-py3-none-any.whl
Size 17.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0bd797fa2a8133162bbd9aa8daf97a33fd5400b64a240f36b305e0ec1d4586a6
BLAKE2b-256 checksum
How to use checksums
1e17271b58a978fea749b32b9205012d16fc0f2eb96b43059cede21435a6dc23
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 26, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.3.2 This release

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.1

2 release files

0.2.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page