Libre DevOps Helpers
ldo: importable Python helpers and a fast CLI for day-to-day DevOps and security work.
ldo is a fast, read-only command line for day-to-day security and platform work across
Microsoft (Entra ID, Defender XDR, Intune, Azure, Graph, PIM, Logic Apps) and ServiceNow. It
signs in as you, through the Azure CLI by default, and can read only what you can. The Python
sibling of the LibreDevOpsHelpers
PowerShell module, and importable as a library too.
Commands
| Command | What it does | Docs |
|---|---|---|
ldo devices |
check a list of devices across Entra, Defender and Intune, watch until they are all there, show one, read Defender Antivirus versions | devices |
ldo entra |
devices and whether they are in a group, users, groups, roles, sign-ins, app credentials, Conditional Access; tokens | entra |
ldo intune |
managed devices: compliance, last sync, owner | entra |
ldo xdr |
Defender machines, alerts, vulnerabilities, indicators, Advanced Hunting | defender |
ldo xdr incidents |
the Defender XDR queue, Sentinel's included: top, latest, between days, summary | defender |
ldo graph |
any Graph GET, objects by name, whoami, a Graph token, hunting |
graph |
ldo azure |
subscriptions, Resource Graph, role assignments, Defender for Cloud | azure |
ldo azure automation |
Automation accounts: runbook jobs, and each job's logs and output | azure |
ldo keyvault |
secrets, certificates and keys close to expiry | azure |
ldo logs |
KQL against a Log Analytics or Sentinel workspace | azure |
ldo pim |
eligible, active and standing access, requests, approvals, activation settings | pim |
ldo logicapp |
offline checks, export and validation for Consumption Logic Apps and Sentinel playbooks | logic apps |
ldo snow |
ServiceNow: sign in, whoami, the instance, applications, a token | servicenow |
ldo az |
switch the Azure CLI between profiles | signing in |
ldo json |
pretty-print any JSON (az rest ... | ldo json) in colour, or as YAML |
configuration |
ldo profiles, ldo config |
your profiles, and the config file | configuration |
Every command takes -p for a profile and -o table|json|csv, and lists of names from
arguments, stdin, a text file, or a column of a CSV or Excel workbook.
Install
uv tool install git+https://github.com/libre-devops/python-helpers@v0.4.1
Or run the container image, which has the Azure CLI inside:
podman run --rm -it ghcr.io/libre-devops/python-helpers:latest --help
(see Container images).
Quickstart
az login # the default sign-in is the Azure CLI's
ldo config init # write ~/.config/ldo/config.toml
$EDITOR "$(ldo config path)" # put your tenant id in a profile
ldo profiles # your profiles, and whether each can sign in
Then:
ldo devices check web01,web02 # in Entra and onboarded to Defender?
ldo devices check -f plan.xlsx --column FQDN --tag linux-servers
ldo devices av-signature web01 # Defender Antivirus versions
ldo entra devices -f plan.xlsx --column FQDN --group "MDE Pilot Devices"
ldo azure automation logs aa-ops --runbook Rotate-Keys # the newest run's logs
ldo graph get-device web01
ldo xdr alerts --since 24h --severity high
ldo azure resource-graph "resources | summarize count() by type"
ldo keyvault expiry --all-vaults --within 30d
Incidents, Graph hunting and PIM for Entra roles need scopes the Azure CLI's token never has: sign in through your own app registration for those. Permissions lists what each command needs.
Documentation
- Configuration: profiles, common options, environment variables, exit codes
- Signing in and Permissions
- Container images
- Using it as a library and Rebranding for your organisation
- Development:
justrecipes, tests, CI and releasing
Contributions are welcome: see CONTRIBUTING.md, and SECURITY.md to report a vulnerability. Licensed under MIT.
Release files for libre-devops-helpers 0.4.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| libre_devops_helpers-0.4.1.tar.gz | 457.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| libre_devops_helpers-0.4.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 699.0 kB
Release files / libre_devops_helpers-0.4.1.tar.gz
| Download URL | libre_devops_helpers-0.4.1.tar.gz |
|---|---|
| Size | 457.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
35b868f42b64ca84dd57468829093db60de1291d255fc88966d1249f2dab4826
|
|
BLAKE2b-256 checksum How to use checksums |
822860f9b676467b2cde7dfacc74245c2f8300fe4cf2e94daf9c7115b5e63a90
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.
Transparency logRelease files / libre_devops_helpers-0.4.1-py3-none-any.whl
| Download URL | libre_devops_helpers-0.4.1-py3-none-any.whl |
|---|---|
| Size | 241.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
ea0507128b02aec84a738e5117d41c4d970f1d85f6c00ca2a740c5a52e675c09
|
|
BLAKE2b-256 checksum How to use checksums |
d72f6571ea3ba7906f3ca8f15f8b6c233144eee79c04dd448017ee3ca286b524
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.
Transparency log