Sigantry
Sigantry is an enterprise-grade governance, drift detection, and rollback engine for Microsoft Fabric CI/CD pipelines.
Built by JToye Digital, Sigantry wraps Microsoft's official deployment tooling (fabric-cicd, fab CLI, and Fabric REST APIs) rather than replacing them. While Microsoft owns the automation lane, Sigantry provides the mission-critical governance layer enterprise platform teams require: tamper-evident deploy ledgers, automated rollback, scheduled drift detection, destructive-operation gating, and headless PR-review bots.
Key Capabilities
- 🚀 Pre-Deployment Safety Probes:
sigantry preflightruns four-phase non-destructive simulations (Schema Syntax, Dependency DAG, Entra ID Scope, Capacity State) before deploying. - 🔄 Lossless Brownfield Adoption:
sigantry sync pullintrospects any hand-built Fabric workspace and generates an exact, round-trip losslesssync.ymlmanifest and code tree. - 🏗️ Declarative Greenfield Scaffolding:
sigantry workspace bootstrapprovisions brand-new workspaces, capacity bindings, and medallion folder blueprints from a singleworkspace.ymlmanifest with idempotent probe-before-act convergence. - ⚡ Concurrent Bulk Publishing:
--bulkoption accelerates workspace deployments via parallel item publishing pools, reducing deploy times by up to 3.8x on multi-item repositories. - 🛡️ Automated Release Rollback:
sigantry deploy run --rollback --to-release <id>re-publishes the exact historical version of items from immutable ledger snapshots. - 🔍 Interactive Drift Detection:
sigantry diffcontinuously compares live Fabric workspaces against Git manifests, outputting rich CLI tables, SemVer JSON, or standalone interactive HTML reports (--output html). - 🛑 TMDL Breaking Change Impact Guard:
sigantry pr-bot run --fail-on-breakingintercepts Power BI semantic model edits in CI/CD, highlighting dropped measures, columns, and tables before downstream reports break. - 📜 Tamper-Evident Audit Ledger: Cryptographic SHA-256 hash-chained JSONL records (
DeployRecord,BootstrapRecord) independently verifiable viasigantry release verify. - 🔌 11 Protocol Seams: Pluggable architecture supporting custom notification sinks (Teams, Slack, Email), secret stores (Key Vault, GitHub, ADO), approval gates (OPA, ADO, GHA), and data quality gates.
60-Second Quickstart
1. Installation
pip install sigantry
Verify the installation:
sigantry --help
sigantry doctor
2. Adopt an Existing Workspace (Brownfield)
Bring an existing, hand-built Fabric workspace under version-controlled manifest management:
sigantry sync pull --workspace-id "<YOUR-WORKSPACE-GUID>" --into ./adopted
Inspect what was generated:
head -25 ./adopted/sync.yml
Prove the round-trip is lossless (should report 0 folders created and 0 items moved):
sigantry sync apply --manifest ./adopted/sync.yml --workspace-id "<YOUR-WORKSPACE-GUID>" --dry-run
3. Detect Drift
Check if anyone has modified, added, or deleted items out-of-band in the Fabric portal:
sigantry diff --manifest ./adopted/sync.yml --workspace-id "<YOUR-WORKSPACE-GUID>" --fail-on-drift
4. Bootstrap a Fresh Workspace (Greenfield)
Author a workspace.yml blueprint:
schema_version: "1.0"
workspace:
name: "analytics-prod"
description: "Production Fabric Workspace"
capacity_id: "<YOUR-CAPACITY-GUID>"
folders:
blueprint: medallion
git:
enabled: false
Bootstrap with probe-before-act convergence:
sigantry workspace bootstrap workspace.yml --dry-run
sigantry workspace bootstrap workspace.yml
Documentation
Full documentation, architecture guides, and step-by-step tutorials are available at: 👉 https://bralabee.github.io/sigantry
License
Sigantry is licensed under the Apache License, Version 2.0.
Metadata
Release files for sigantry 1.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| sigantry-1.0.0.tar.gz | 303.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| sigantry-1.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 695.2 kB
Release files / sigantry-1.0.0.tar.gz
| Download URL | sigantry-1.0.0.tar.gz |
|---|---|
| Size | 303.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
9f26f7658842b0c8b4699ba7c37a9db234e98c4bd2a57f440258da83d6b2a459
|
|
BLAKE2b-256 checksum How to use checksums |
a7d1a8834e532c1f4a06f7137b2b031d157497cf035297ef8c03e58643ba9e13
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 19, 2026.
Transparency logRelease files / sigantry-1.0.0-py3-none-any.whl
| Download URL | sigantry-1.0.0-py3-none-any.whl |
|---|---|
| Size | 391.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
30895b7e592d2661e64d9e290483f27ce42ab563ff2ef64d21a1e97700d96434
|
|
BLAKE2b-256 checksum How to use checksums |
d50ef5ca920e663efd0c117f7eae16d98ffb4d37d71b161612da41d581ef3d91
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 19, 2026.
Transparency log