Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

Azurator

PyPI Latest Release Pepy Total Downloads GitHub License

Azurator rotates shared-key credentials for Azure services and updates supported places where they are stored.

[!WARNING] Azurator is pre-alpha. Key rotation changes Azure and cannot be rolled back. Review the displayed changes before confirming them.

Installation

Python installations require Python 3.10 or newer. The default login uses the Azure CLI.

pipx install azurator

Other install paths:

  • pip install azurator
  • prebuilt archives from the latest release
  • nix run github:janthmueller/azurator -- --help

The optional SOPS workflow also requires SOPS 3.13.x. See the installation guide for details.

Quick Start

Rotate keys already stored in a dotenv file:

azurator login
azurator rotate --env-file .env

Azurator matches the file values to supported Azure keys, shows every planned change, asks once for confirmation, rotates the keys, and updates the file and supported Azure configuration that stores the same values.

Inspect or preview first when needed:

azurator match --env-file .env
azurator plan --env-file .env

Other Workflows

  • azurator rotate selects keys interactively.
  • azurator rotate --sops-file secrets.enc.env updates a SOPS-encrypted dotenv file.
  • azurator export --sops-out azure-keys.enc.env creates a new SOPS-encrypted dotenv file.
  • azurator export --out azure-keys.env creates a new dotenv file from selected keys.
  • azurator match --sops-file secrets.enc.env --key-map-out azurator.keys.json saves mappings for azurator export --key-map azurator.keys.json --sops-out recreated.enc.env.
  • azurator refresh --key-map azurator.keys.json --sops-file secrets.enc.env updates the mapped existing assignments with their current Azure values.
  • azurator discover lists supported key resources without retrieving key values.

Current Scope

Azurator rotates Storage Account keys and the Key1 and Key2 credentials exposed by Azure AI, Cognitive Services, and Azure OpenAI. When the same key is stored in a selected dotenv file, a supported Foundry project connection, or an App Service application setting, Azurator can update that configuration during the rotation.

Azurator checks only the documented configuration types. It does not discover every Azure secret or prove that a running workload uses a key.

See Supported Key Resources and Bindings for the exact current coverage.

Shared Keys and Microsoft Entra ID

Shared keys are useful for prototypes and existing integrations, but they must be stored, distributed, and rotated. Prefer Microsoft Entra ID when the service and workload support it. Use Azurator when shared keys remain the practical choice.

Read Microsoft's guidance for secretless authentication, Foundry authentication, and Azure Storage Shared Key.

Documentation

See the documentation for setup, supported workflows, and recovery.

Contributing

See CONTRIBUTING.md.

License

MIT

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

azurator-0.1.0a3.tar.gz (185.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

azurator-0.1.0a3-py3-none-any.whl (119.6 kB view details)

Uploaded Python 3

File details

Details for the file azurator-0.1.0a3.tar.gz.

File metadata

  • Download URL: azurator-0.1.0a3.tar.gz
  • Upload date:
  • Size: 185.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for azurator-0.1.0a3.tar.gz
Algorithm Hash digest
SHA256 13bfc364fbde6d43f7bfeec1a6d5a23704924efc9e31a1d328184cae04ce767b
MD5 a420523e75094efb93c3045e90ab08e3
BLAKE2b-256 db8ff782e0c8bec3e0a1ffbfba30a8f44b571a8bf4a4adc85f3f9c3b7e0c1d81

See more details on using hashes here.

Provenance

The following attestation bundles were made for azurator-0.1.0a3.tar.gz:

Publisher: release.yml on janthmueller/azurator

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file azurator-0.1.0a3-py3-none-any.whl.

File metadata

  • Download URL: azurator-0.1.0a3-py3-none-any.whl
  • Upload date:
  • Size: 119.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for azurator-0.1.0a3-py3-none-any.whl
Algorithm Hash digest
SHA256 ccb588313c8ecfb6b057204fe79608137df218b2cef24ec9439e2085fdf96579
MD5 1c32152b12d87b73bab913adc425fc76
BLAKE2b-256 d6f63cff9c1fcb669fa859790f0cea2a39c52f13a95732b833a72468b470e8e5

See more details on using hashes here.

Provenance

The following attestation bundles were made for azurator-0.1.0a3-py3-none-any.whl:

Publisher: release.yml on janthmueller/azurator

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

0.1.0a3 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page