Skip to main content

ops-py-monitoring

Description

Azure Key Vault reports

May be posted to a Slack App webhook, Slack Workflow webhook, or an MS Teams webhook.

The output is formatted as a Slack Code Block when posted Slack. The content is output as a two plaintext Markdown tables:
the Summary and the Report.

Long reports will be split into multiple parts. Part number will then be added to each part.

When posted to a MS Teams payload the Summary is formatted as Facts, followed by the Report as an HTML Table.

The az keyvault command outputs must be stored in separate files with a .json ending. The files must be placed in a folder named /tmp/az_json, e.g.:
/tmp/az_json/my-kv_secret.json

Azure Key Vault Slack alerts

Each alert message is formatted as Slack Markdown.

Azure Key Vault MS Teams alerts

Each alert message is formatted as AdaptiveCard with TextBlocks.

SSL certificate reports

Posted to a Slack App webhook.

Installation

pip install ops-py-monitoring

Usage

Environment variables

Export the webhook url(s) as environment variables:

  • WEBHOOK_REPORT This is where the reports(s) or alerts will be posted. It is automatically detected if the webook is of type:

    • Slack App
      When the webhook contains slack.com/services.

    • Slack Workflow
      When the webhook contains slack.com, but not the slack.com/services part.

    • MS Teams
      When the webhook does not contain slack.com.

    Example: export WEBHOOK_REPORT="https://hooks.slack.com/workflows/T02XYZ..."

  • WEBHOOK_NOTIFY
    If set, then when the result has been posted to the WEBHOOK_REPORTwebhook, an additional empty POST is performed to the value of this webhook.

NOTE: The actual post requests are handled by the ops-py-message-handler.


Arguments

-l, --ssl_certs STRING (space separated) The list of ssl certs to check Example: -l example.com equinor.com

-W, --ssl_warning_threshold INT - Default: 29 The SSL cert expire days warning threshold.

-C, --ssl_critical_threshold INT - Default: 14 The SSL cert expire days critical threshold.

-R --ssl_include_ok If provided all SSL certs will be included in the report.

-t --report_types Default: kv_report Kind of report to be posted. Example: -t kv_report kv_alert cert_report

-c, --alert_threshold INT - Default: not set If set, then only the records that are +/- this value in days till expire/expired will be alerted on, as individual messages.
Example: --alert_threshold 7 This will alert on records which will expire within the next 7 days OR the record that has expired, but only for less than 7 days ago.
If specified, the summary and other reports will not be posted. Only the alert messages about the records which are caught by this alert_thresholdfilter will be posted.

-e, --expire_threshold INT - Default: not set If this argument is provided, the days to the record's Expiration Date must be below this threshold in order to be included in the report.
Example: --expire_threshold 60 This will include the record in the report only if the record will expire within the next 60 days.

-i, --include_no_expiration Default: not set If this argument is provided, the report will also include the records which has no Expiration Date set.
The default behavior is simply to ignore records which do not have a Expiration Date set.

-a, --include_all Default: not set If this argument is provided, the report will include all the records (verbose) for the specified Record Types.
Records which have been disabled will also be included.

-T, --title Default: Azure Key Vault report The title of the message posted in Slack or MS Teams.

-L, --slack_split_chars INT - Default: 3500 If the Slack message is above this value it will be split into multiple posts.
Each post will then include a maximum characters specified by this value.

-M, --teams_max_chars INT - Default: 17367 The max characters the report can have due to the MS Teams payload size limits.
NOTE: If the message is above this threshold then only the facts (summary) will be posted to MS Teams.
The HTML table will in this case not be included.

-w, --workflow_output_file STRING - Default: output.json The file where a full json report will be written.

-s, --silence Default: not set If provided the workflow will run, log and write to the workflow_output_file and stdout, but no messages to Slack or MS Teams will be posted.

-m, --write_md_report Default: not set If provided, plain text markdown files will be written.

-V, --write_csv_report Default: not set If provided, plain text comma separated csv files will be written.

Examples

Generate a Key Vault report and summary of all records for specified Key Vaults
Example: python3 -m monitoring.monitoring --ssl_certs example.com google.com --report_types kv_report cert_report --write_md_report --write_csv_report --include_all

This will include all the Key Vault records found in the output files in the /tmp/az_json directory, even the records which are disabled and the records which has no Expiration Date set.
The result will be a summary report and a full report, which are posted to the webhook exported in WEBHOOK_REPORT
The status of the two provided ssl certificates will be generated. CSV and Markdown report text files will also be written.

To only print the result to stdout and not post to the webhook, append the -Sargument

To only include the records which will expire within the next 60 days
Example: python3 -m monitoring.monitoring --ssl_certs example.com google.com --report_types kv_report cert_report --write_md_report --write_csv_report --expire_threshold 60

The reports will then only include records will expire within the next 60 days and records which have already expired.

The summary will contain info about every record parsed, even if the record is not included to be output in the report.
NOTE: If no records are included in the report (none expired and none expiring within the threshold), the summary will still be posted.

For specified Key Vaults, alert only (no report) if any records is about to expire within the next 14 days or if any record has expired within the last 14 days
python3 -m monitoring.monitoring --report_types kv_alert --alert_threshold 14

NOTE: Each record will be alerted on in separate messages.
NOTE: E.g. if a record then has expired for 15 days or more, it will not be alerted on.

Log all output A summary and a full report is always written to file. This may then be used to post to an Monitoring service API etc., e.g.:

curl --request POST \    
  --header 'Content-Type: application/json' \    
  --header 'X-Api-Key: MY-SUPER-SECRET-KEY' \    
  --data @output.json \    
  https://my-superb-api.com  

Metadata

Release files for ops-py-monitoring 6.0.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ops-py-monitoring 6.0.3
File Size Uploaded
ops_py_monitoring-6.0.3.tar.gz 16.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ops-py-monitoring 6.0.3
File Interpreter ABI Platform
ops_py_monitoring-6.0.3-py3-none-any.whl Python 3 none any Details

Total release size: 30.1 kB

Release files / ops_py_monitoring-6.0.3.tar.gz

Download URL ops_py_monitoring-6.0.3.tar.gz
Size 16.0 kB
Tags Source
SHA-256 checksum
How to use checksums
45e33dc24b6dd420bb4100793e0f6d09a21d935c66683efe25e49dd1eb8d6fd7
BLAKE2b-256 checksum
How to use checksums
0e9be0912e110464f465ea112a7fb049c843ca27dbf53a07ed0d828fcadc2e70
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 18, 2025.

Transparency log

Release files / ops_py_monitoring-6.0.3-py3-none-any.whl

Download URL ops_py_monitoring-6.0.3-py3-none-any.whl
Size 14.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
18095a1ce71d5ad4e350689551a4bca66d02813a672575c03fb9529ff333f389
BLAKE2b-256 checksum
How to use checksums
25518eb9aa3d95178a768562b653938a59b9d0381b05209179aea91e620b408c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 18, 2025.

Transparency log

Release history Release notifications | RSS feed

This release

6.0.3 This release

2 release files

6.0.2

2 release files

6.0.1

2 release files

6.0.0

2 release files

5.0.1

2 release files

5.0.0

2 release files

4.0.0

2 release files

3.3.13

2 release files

3.3.12

2 release files

3.3.11

2 release files

3.3.10

2 release files

3.3.9

2 release files

3.3.8

2 release files

3.3.7

2 release files

3.3.6

2 release files

3.3.5

2 release files

3.3.4

2 release files

3.3.3

2 release files

3.3.2

2 release files

3.3.1

2 release files

3.3.0

2 release files

3.2.0

2 release files

3.1.1

2 release files

3.1.0

2 release files

3.0.0

2 release files

2.1.0

2 release files

2.0.2

2 release files

2.0.1

2 release files

2.0.0

2 release files

1.5.1

2 release files

1.5.0

2 release files

1.4.0

2 release files

1.3.1

2 release files

1.3.0

2 release files

1.2.0

2 release files

1.1.0

2 release files

1.0.1

2 release files

1.0.0

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page