Skip to main content
Libre DevOps

Libre DevOps Helpers

ldo: importable Python helpers and a fast CLI for day-to-day DevOps and security work.

Lint and Test Coverage CodeQL Container

Release PyPI Container images Python Licence: MIT


ldo is a fast, read-only command line for day-to-day security and platform work across Microsoft (Entra ID, Defender XDR, Intune, Azure, Graph, PIM, Logic Apps) and ServiceNow. It signs in as you, through the Azure CLI by default, and can read only what you can. The Python sibling of the LibreDevOpsHelpers PowerShell module, and importable as a library too.


Commands

Command What it does Docs
ldo devices check a list of devices across Entra, Defender and Intune, watch until they are all there, show one, read Defender Antivirus versions devices
ldo entra devices and whether they are in a group, users, groups, roles, sign-ins, app credentials, Conditional Access; tokens entra
ldo intune managed devices: compliance, last sync, owner entra
ldo xdr Defender machines, alerts, vulnerabilities, indicators, Advanced Hunting defender
ldo xdr incidents the Defender XDR queue, Sentinel's included: top, latest, between days, summary defender
ldo graph any Graph GET, objects by name, whoami, a Graph token, hunting graph
ldo azure subscriptions, Resource Graph, role assignments, Defender for Cloud azure
ldo azure automation Automation accounts: runbook jobs, and each job's logs and output azure
ldo keyvault secrets, certificates and keys close to expiry azure
ldo logs KQL against a Log Analytics or Sentinel workspace azure
ldo pim eligible, active and standing access, requests, approvals, activation settings pim
ldo logicapp offline checks, export and validation for Consumption Logic Apps and Sentinel playbooks logic apps
ldo snow ServiceNow: sign in, whoami, the instance, applications, a token servicenow
ldo az switch the Azure CLI between profiles signing in
ldo network test test the way out through a corporate proxy: the proxy, the certificates, each service network
ldo json pretty-print any JSON (az rest ... | ldo json) in colour, or as YAML configuration
ldo profiles, ldo config your profiles, and the config file configuration

Every command takes -p for a profile and -o table|json|csv, and lists of names from arguments, stdin, a text file, or a column of a CSV or Excel workbook.


Install

From PyPI:

uv tool install libre-devops-helpers     # the ldo command, in an environment of its own
pipx install libre-devops-helpers        # the same, with pipx
uv pip install libre-devops-helpers      # into the current environment, to use it as a library
pip install libre-devops-helpers         # the same, with pip
uv tool upgrade libre-devops-helpers     # later, to the newest release

Add the keychain extra ("libre-devops-helpers[keychain]") to keep sign-ins in the macOS Keychain or the Linux Secret Service. A tagged release installs straight from GitHub too: uv tool install git+https://github.com/libre-devops/python-helpers@v0.5.0.

Or run the container image, which has the Azure CLI inside: podman run --rm -it ghcr.io/libre-devops/python-helpers:latest --help (see Container images).


Quickstart

az login                        # the default sign-in is the Azure CLI's
ldo config init                 # write ~/.config/ldo/config.toml
$EDITOR "$(ldo config path)"    # put your tenant id in a profile
ldo profiles                    # your profiles, and whether each can sign in

Then:

ldo devices check web01,web02                        # in Entra and onboarded to Defender?
ldo devices check -f plan.xlsx --column FQDN --tag linux-servers
ldo devices av-signature web01                       # Defender Antivirus versions
ldo entra devices -f plan.xlsx --column FQDN --group "MDE Pilot Devices"
ldo azure automation logs aa-ops --runbook Rotate-Keys    # the newest run's logs
ldo graph get-device web01
ldo xdr alerts --since 24h --severity high
ldo azure resource-graph "resources | summarize count() by type"
ldo keyvault expiry --all-vaults --within 30d

Incidents, Graph hunting and PIM for Entra roles need scopes the Azure CLI's token never has: sign in through your own app registration for those. Permissions lists what each command needs.


Documentation

Contributions are welcome: see CONTRIBUTING.md, and SECURITY.md to report a vulnerability. Licensed under MIT.


Part of Libre DevOps. Everything we publish is open and provided as-is; review and test it against your own requirements before production use.

Release files for libre-devops-helpers 0.5.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for libre-devops-helpers 0.5.0
File Size Uploaded
libre_devops_helpers-0.5.0.tar.gz 484.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for libre-devops-helpers 0.5.0
File Interpreter ABI Platform
libre_devops_helpers-0.5.0-py3-none-any.whl Python 3 none any Details

Total release size: 740.7 kB

Release files / libre_devops_helpers-0.5.0.tar.gz

Download URL libre_devops_helpers-0.5.0.tar.gz
Size 484.8 kB
Tags Source
SHA-256 checksum
How to use checksums
1ca572bd1e460e733f574f7f3b98993d5a7869af7612592a1fd8fcb649c10c15
BLAKE2b-256 checksum
How to use checksums
f61ce59494c21b8a77a6c7ed312338b5a6ff988e45193d557f2a26026e998101
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release files / libre_devops_helpers-0.5.0-py3-none-any.whl

Download URL libre_devops_helpers-0.5.0-py3-none-any.whl
Size 255.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
31e4c2b93da4e285798295fc0d808a4a05a189514e95073a0ca308cc4b67b643
BLAKE2b-256 checksum
How to use checksums
35cde1b3395edcae25ec90b3697d996de8320e6dba51ec3404570e75ab103b6e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.5.0 This release

2 release files

0.4.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page