Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

Azurator

Azurator rotates shared-key credentials for Azure services and updates supported places where they are stored.

[!WARNING] Azurator is pre-alpha. Key rotation changes Azure and cannot be rolled back. Review the displayed changes before confirming them.

Installation

Python installations require Python 3.10 or newer. The default login uses the Azure CLI.

pipx install azurator

Other install paths:

  • pip install azurator
  • prebuilt archives from the latest release
  • nix run github:janthmueller/azurator -- --help

The optional SOPS workflow also requires SOPS 3.13.x. See the installation guide for details.

Quick Start

Rotate keys already stored in a dotenv file:

azurator login
azurator rotate --env-file .env

Azurator matches the file values to supported Azure keys, shows every planned change, asks once for confirmation, rotates the keys, and updates the file and supported Azure configuration that stores the same values.

Inspect or preview first when needed:

azurator match --env-file .env
azurator plan --env-file .env

Other Workflows

  • azurator rotate selects keys interactively.
  • azurator rotate --sops-file secrets.enc.env updates a SOPS-encrypted dotenv file.
  • azurator export --sops-out azure-keys.enc.env creates a new SOPS-encrypted dotenv file.
  • azurator export --out azure-keys.env creates a new dotenv file from selected keys.
  • azurator discover lists supported key resources without retrieving key values.

Current Scope

Azurator rotates Storage Account keys and the Key1 and Key2 credentials exposed by Azure AI, Cognitive Services, and Azure OpenAI. When the same key is stored in a selected dotenv file, a supported Foundry project connection, or an App Service application setting, Azurator can update that configuration during the rotation.

Azurator checks only the documented configuration types. It does not discover every Azure secret or prove that a running workload uses a key.

See Supported Key Resources and Bindings for the exact current coverage.

Shared Keys and Microsoft Entra ID

Shared keys are useful for prototypes and existing integrations, but they must be stored, distributed, and rotated. Prefer Microsoft Entra ID when the service and workload support it. Use Azurator when shared keys remain the practical choice.

Read Microsoft's guidance for secretless authentication, Foundry authentication, and Azure Storage Shared Key.

Documentation

See the documentation for setup, supported workflows, and recovery.

Contributing

See CONTRIBUTING.md.

License

MIT

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

azurator-0.1.0a1.tar.gz (168.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

azurator-0.1.0a1-py3-none-any.whl (111.0 kB view details)

Uploaded Python 3

File details

Details for the file azurator-0.1.0a1.tar.gz.

File metadata

  • Download URL: azurator-0.1.0a1.tar.gz
  • Upload date:
  • Size: 168.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for azurator-0.1.0a1.tar.gz
Algorithm Hash digest
SHA256 6adacd30997b13a4728acc4250764786b1ec537758be3ad4742955ecb0640f42
MD5 0996c35bcea88a163b3bcb49e7d913ba
BLAKE2b-256 c8629e38ed8158801919535e383b3cb996ddef83f408ab1aaac8706c24b8e391

See more details on using hashes here.

Provenance

The following attestation bundles were made for azurator-0.1.0a1.tar.gz:

Publisher: release.yml on janthmueller/azurator

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file azurator-0.1.0a1-py3-none-any.whl.

File metadata

  • Download URL: azurator-0.1.0a1-py3-none-any.whl
  • Upload date:
  • Size: 111.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for azurator-0.1.0a1-py3-none-any.whl
Algorithm Hash digest
SHA256 fd93d2d339f539bb7de5ef43f4349b2c04fd84746c4a9080b7b58a82539c24e7
MD5 2374a7531f567cda760d557f84fa02d2
BLAKE2b-256 a9a521f565e53508d7419b190efd8ff86d59ee7858144f511eb208af2e9bf0be

See more details on using hashes here.

Provenance

The following attestation bundles were made for azurator-0.1.0a1-py3-none-any.whl:

Publisher: release.yml on janthmueller/azurator

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

0.1.0a1 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page