Skip to main content

Snowflake Key Pair Rotation Tool

PyPI version Python 3.8+ License: MIT

Automates Snowflake key-pair authentication setup and rotation with Hevo Data destinations.

Installation

From PyPI (Recommended)

pip install sf-rotation

From GitHub

pip install git+https://github.com/Legolasan/sf_rotation.git

From Source

git clone https://github.com/Legolasan/sf_rotation.git
cd sf_rotation
pip install .

Development Mode

git clone https://github.com/Legolasan/sf_rotation.git
cd sf_rotation
pip install -e .

Configuration

  1. Create a config file based on the example:
mkdir -p config
curl -o config/config.yaml https://raw.githubusercontent.com/Legolasan/sf_rotation/main/config/config.yaml.example
  1. Edit config/config.yaml with your credentials:
  • Snowflake account URL, admin credentials, target user
  • Hevo API credentials and destination details
  • Key encryption preferences

Usage

Command Line Interface

After installation, the sf-rotation command is available:

# Initial setup (creates new Hevo destination, saves destination_id to config)
sf-rotation setup --config config/config.yaml

# Update keys for existing destination (requires destination_id in config)
sf-rotation update-keys --config config/config.yaml

# Key rotation (for ongoing key rotations)
sf-rotation rotate --config config/config.yaml

# Snowflake-only setup (no Hevo integration)
sf-rotation snowflake-only --config config/config.yaml

# With encrypted private key
sf-rotation setup --config config/config.yaml --encrypted

Commands Overview

Command Description Hevo Integration
setup Initial setup - creates new Hevo destination Creates new
update-keys Update keys for existing Hevo destination Updates existing
rotate Rotate keys with zero-downtime (repeatable) Updates existing
snowflake-only Set up Snowflake keys only (no Hevo) None

Tip: Run rotate as many times as needed - it automatically alternates between Snowflake key slots.

As Python Module

python -m sf_rotation setup --config config/config.yaml
python -m sf_rotation rotate --config config/config.yaml
python -m sf_rotation snowflake-only --config config/config.yaml

Programmatic Usage

from sf_rotation import KeyGenerator, SnowflakeClient, HevoClient

# Generate keys (returns: private_key_path, public_key_path, backup_path)
generator = KeyGenerator(output_directory="./keys")
private_key_path, public_key_path, backup_path = generator.generate_key_pair(
    key_name="rsa_key",
    encrypted=False
)

# Connect to Snowflake
sf_client = SnowflakeClient(
    account_url="your_account.snowflakecomputing.com",
    username="admin",
    password="password"
)

# Set public key for user
public_key = generator.read_public_key(public_key_path)
formatted_key = generator.format_public_key_for_snowflake(public_key)
sf_client.set_rsa_public_key("target_user", formatted_key)

# Create Hevo destination
hevo = HevoClient(
    base_url="https://us.hevodata.com",
    username="hevo_user",
    password="hevo_pass"
)
private_key = generator.read_private_key(private_key_path)
hevo.create_destination(
    name="my_snowflake",
    account_url="your_account.snowflakecomputing.com",
    warehouse="WAREHOUSE",
    database_name="DATABASE",
    database_user="target_user",
    private_key=private_key
)

Features

  • Generate RSA 2048-bit key pairs (encrypted or non-encrypted)
  • Configure Snowflake users with RSA public keys
  • Create/update Hevo Data destinations with key-pair authentication
  • Seamless key rotation with automatic backup
  • CLI and programmatic interfaces

Process Flow

Setup Mode (New Destination)

  1. Generate RSA key pair
  2. Connect to Snowflake (username/password)
  3. Set RSA_PUBLIC_KEY for target user
  4. Create Hevo destination with private key
  5. Auto-save destination_id to config file

Update-Keys Mode (Existing Destination)

  1. Verify destination_id exists in config
  2. Generate RSA key pair
  3. Connect to Snowflake and set public key
  4. Update existing Hevo destination with private key

Rotate Mode (Key Rotation - Repeatable)

  1. Backup existing keys
  2. Generate new key pair
  3. Detect current key slot (RSA_PUBLIC_KEY or RSA_PUBLIC_KEY_2)
  4. Set new key in the alternate slot (zero-downtime)
  5. Update Hevo destination with new private key
  6. Unset the old key slot

Note: Rotation alternates between slots, allowing unlimited rotations without conflicts.

Snowflake-Only Mode (No Hevo)

  1. Generate RSA key pair
  2. Connect to Snowflake (username/password)
  3. Set RSA_PUBLIC_KEY for target user
  4. Does NOT interact with Hevo APIs

Use Case: Configure Snowflake key-pair auth when you manage Hevo separately or don't use Hevo at all.

Project Structure

sf_rotation/
├── src/sf_rotation/
│   ├── __init__.py           # Package exports
│   ├── main.py               # CLI entry point
│   ├── key_generator.py      # OpenSSL key generation
│   ├── snowflake_client.py   # Snowflake connection/key management
│   ├── hevo_client.py        # Hevo API client
│   └── utils.py              # Helper functions
├── config/
│   └── config.yaml.example   # Configuration template
├── pyproject.toml            # Package configuration
├── README.md
└── WORKFLOW.md               # Detailed workflow documentation

Requirements

  • Python 3.8+
  • OpenSSL (for key generation)
  • Snowflake account with admin access
  • Hevo Data account with API access

Security Notes

  • Private keys are stored with 600 permissions
  • Keys directory is gitignored
  • Config files with credentials are gitignored
  • Passphrase prompted at runtime (not stored in config)

License

MIT License - see LICENSE file for details.

Metadata

Release files for sf-rotation 1.3.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for sf-rotation 1.3.3
File Size Uploaded
sf_rotation-1.3.3.tar.gz 23.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for sf-rotation 1.3.3
File Interpreter ABI Platform
sf_rotation-1.3.3-py3-none-any.whl Python 3 none any Details

Total release size: 46.5 kB

Release files / sf_rotation-1.3.3.tar.gz

Download URL sf_rotation-1.3.3.tar.gz
Size 23.3 kB
Tags Source
SHA-256 checksum
How to use checksums
e6da721ffc010513757e255b161da5627dcf243d2d95153aee11e73ed3529165
BLAKE2b-256 checksum
How to use checksums
f0c6ad6529f53abf1edaa10ee6e538ecafa0d0465842f509d8e8fda8dab1e8e9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.2

Release files / sf_rotation-1.3.3-py3-none-any.whl

Download URL sf_rotation-1.3.3-py3-none-any.whl
Size 23.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9a4c2b2a2e57b64756a97dafa318423c839f33caa59d5ce7dcf4f6c0a3532c97
BLAKE2b-256 checksum
How to use checksums
b29ed999d153eaf6c41276c70c6ca504e42481c5251ce0ccc2e42632e4e2c37a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.2

Release history Release notifications | RSS feed

This release

1.3.3 This release

2 release files

1.3.2

2 release files

1.3.1

2 release files

1.3.0

2 release files

1.2.8

2 release files

1.2.7

2 release files

1.2.6

2 release files

1.2.4

2 release files

1.2.3

2 release files

1.2.2

2 release files

1.2.1

2 release files

1.2.0

2 release files

1.1.0

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page