This release is a pre-release and may not be stable for production use.
Azurator
Azurator rotates shared-key credentials for Azure services and updates supported places where they are stored.
[!WARNING] Azurator is pre-alpha. Key rotation changes Azure and cannot be rolled back. Review the displayed changes before confirming them.
Installation
Python installations require Python 3.10 or newer. The default login uses the Azure CLI.
pipx install azurator
Other install paths:
pip install azurator- prebuilt archives from the latest release
nix run github:janthmueller/azurator -- --help
The optional SOPS workflow also requires SOPS 3.13.x. See the installation guide for details.
Quick Start
Rotate keys already stored in a dotenv file:
azurator login
azurator rotate --env-file .env
Azurator matches the file values to supported Azure keys, shows every planned change, asks once for confirmation, rotates the keys, and updates the file and supported Azure configuration that stores the same values.
Inspect or preview first when needed:
azurator match --env-file .env
azurator plan --env-file .env
Other Workflows
azurator rotateselects keys interactively.azurator rotate --sops-file secrets.enc.envupdates a SOPS-encrypted dotenv file.azurator export --sops-out azure-keys.enc.envcreates a new SOPS-encrypted dotenv file.azurator export --out azure-keys.envcreates a new dotenv file from selected keys.azurator match --sops-file secrets.enc.env --key-map-out azurator.keys.jsonsaves mappings forazurator export --key-map azurator.keys.json --sops-out recreated.enc.env.azurator refresh --key-map azurator.keys.json --sops-file secrets.enc.envupdates the mapped existing assignments with their current Azure values.azurator discoverlists supported key resources without retrieving key values.
Current Scope
Azurator rotates Storage Account keys and the Key1 and Key2 credentials
exposed by Azure AI, Cognitive Services, and Azure OpenAI. When the same key is
stored in a selected dotenv file, a supported Foundry project connection, or an
App Service application setting, Azurator can update that configuration during
the rotation.
Azurator checks only the documented configuration types. It does not discover every Azure secret or prove that a running workload uses a key.
See Supported Key Resources and Bindings for the exact current coverage.
Shared Keys and Microsoft Entra ID
Shared keys are useful for prototypes and existing integrations, but they must be stored, distributed, and rotated. Prefer Microsoft Entra ID when the service and workload support it. Use Azurator when shared keys remain the practical choice.
Read Microsoft's guidance for secretless authentication, Foundry authentication, and Azure Storage Shared Key.
Documentation
See the documentation for setup, supported workflows, and recovery.
Contributing
See CONTRIBUTING.md.
License
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file azurator-0.1.0a3.tar.gz.
File metadata
- Download URL: azurator-0.1.0a3.tar.gz
- Upload date:
- Size: 185.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
13bfc364fbde6d43f7bfeec1a6d5a23704924efc9e31a1d328184cae04ce767b
|
|
| MD5 |
a420523e75094efb93c3045e90ab08e3
|
|
| BLAKE2b-256 |
db8ff782e0c8bec3e0a1ffbfba30a8f44b571a8bf4a4adc85f3f9c3b7e0c1d81
|
Provenance
The following attestation bundles were made for azurator-0.1.0a3.tar.gz:
Publisher:
release.yml on janthmueller/azurator
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
azurator-0.1.0a3.tar.gz -
Subject digest:
13bfc364fbde6d43f7bfeec1a6d5a23704924efc9e31a1d328184cae04ce767b - Sigstore transparency entry: 2689089012
- Sigstore integration time:
-
Permalink:
janthmueller/azurator@5c2fa0204522e1ebd6b98df492d162d82176459e -
Branch / Tag:
refs/heads/main - Owner: https://github.com/janthmueller
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@5c2fa0204522e1ebd6b98df492d162d82176459e -
Trigger Event:
workflow_run
-
Statement type:
File details
Details for the file azurator-0.1.0a3-py3-none-any.whl.
File metadata
- Download URL: azurator-0.1.0a3-py3-none-any.whl
- Upload date:
- Size: 119.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
ccb588313c8ecfb6b057204fe79608137df218b2cef24ec9439e2085fdf96579
|
|
| MD5 |
1c32152b12d87b73bab913adc425fc76
|
|
| BLAKE2b-256 |
d6f63cff9c1fcb669fa859790f0cea2a39c52f13a95732b833a72468b470e8e5
|
Provenance
The following attestation bundles were made for azurator-0.1.0a3-py3-none-any.whl:
Publisher:
release.yml on janthmueller/azurator
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
azurator-0.1.0a3-py3-none-any.whl -
Subject digest:
ccb588313c8ecfb6b057204fe79608137df218b2cef24ec9439e2085fdf96579 - Sigstore transparency entry: 2689089061
- Sigstore integration time:
-
Permalink:
janthmueller/azurator@5c2fa0204522e1ebd6b98df492d162d82176459e -
Branch / Tag:
refs/heads/main - Owner: https://github.com/janthmueller
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@5c2fa0204522e1ebd6b98df492d162d82176459e -
Trigger Event:
workflow_run
-
Statement type: