Sigantry
Sigantry is an enterprise-grade governance, drift detection, and rollback engine for Microsoft Fabric CI/CD pipelines.
Built by JToye Digital, Sigantry wraps Microsoft's official deployment tooling (fabric-cicd, fab CLI, and Fabric REST APIs) rather than replacing them. While Microsoft owns the automation lane, Sigantry provides the mission-critical governance layer enterprise platform teams require: integrity-checked deploy ledgers, release rollback, scheduled drift detection, destructive-operation gating, and headless PR-review bots.
Key Capabilities
- 🚀 Pre-Deployment Safety Probes:
sigantry preflightruns four-phase non-destructive simulations (Schema Syntax, Dependency DAG, Entra ID Scope, Capacity State) before deploying. - 🔄 Brownfield Adoption:
sigantry sync pullintrospects a hand-built Fabric workspace and generates async.ymlmanifest and code tree from it. - 🏗️ Declarative Greenfield Scaffolding:
sigantry workspace bootstrapprovisions brand-new workspaces, capacity bindings, and medallion folder blueprints from a singleworkspace.ymlmanifest with idempotent probe-before-act convergence. - ⚡ Concurrent Bulk Publishing:
--bulkpublishes items through a parallel worker pool instead of one at a time, cutting wall-clock deploy time on multi-item repositories. - 🛡️ Release Rollback:
sigantry deploy run --rollback --to-release <id> --rollback-forcepublishes again the items a recorded release names whose type is in--item-types(by defaultLakehouse,Environment,NotebookandDataPipeline), taking their content from the--sourcecheckout you pass. The ledger records item names, not item content or a commit, so check out the source you want to restore before you run it. - 🔍 Interactive Drift Detection:
sigantry diffcompares a live Fabric workspace with a Git manifest at the moment it runs, by item name, type and folder (not item content), and outputs rich CLI tables, SemVer JSON, or standalone interactive HTML reports (--output html). To check on a schedule, call the reusable drift workflow from a scheduled workflow of your own. - 🛑 TMDL Breaking Change Impact Guard:
sigantry pr-bot run --fail-on-breakingintercepts Power BI semantic model edits in CI/CD, highlighting dropped measures, columns, and tables before downstream reports break. - 📜 Integrity-Checked Audit Ledger: SHA-256 hash-chained JSONL records (
DeployRecord,BootstrapRecord).sigantry release verifychecks the deploy ledger's chain; nosigantrycommand checks the bootstrap ledger's chain. The chain is unkeyed and unanchored: it detects accidental corruption, unsealed edits and middle-record deletion, but anyone who can write the ledger file can re-seal it, and tail truncation is undetectable without an external anchor. Read the audit ledger threat model before treating the ledger as evidence against an insider. - 🔌 11 Protocol Seams: Pluggable architecture supporting custom notification sinks (Teams, Slack, Email), secret stores (Key Vault, GitHub, ADO), approval gates (OPA, ADO, GHA), and data quality gates.
60-Second Quickstart
1. Installation
pip install sigantry
Verify the installation:
sigantry --help
sigantry doctor
2. Adopt an Existing Workspace (Brownfield)
Bring an existing, hand-built Fabric workspace under version-controlled manifest management:
sigantry sync pull --workspace-id "<YOUR-WORKSPACE-GUID>" --into ./adopted
Inspect what was generated:
head -25 ./adopted/sync.yml
Check that re-applying the pulled manifest changes nothing (the dry run should report 0 folders created and 0 items moved):
sigantry sync apply --manifest ./adopted/sync.yml --workspace-id "<YOUR-WORKSPACE-GUID>" --dry-run
3. Detect Drift
Check if anyone has modified, added, or deleted items out-of-band in the Fabric portal:
sigantry diff --manifest ./adopted/sync.yml --workspace-id "<YOUR-WORKSPACE-GUID>" --fail-on-drift
4. Bootstrap a Fresh Workspace (Greenfield)
Author a workspace.yml blueprint:
schema_version: "1.0"
workspace:
name: "analytics-prod"
description: "Production Fabric Workspace"
capacity_id: "<YOUR-CAPACITY-GUID>"
folders:
blueprint: medallion
git:
enabled: false
Bootstrap with probe-before-act convergence:
sigantry workspace bootstrap workspace.yml --dry-run
sigantry workspace bootstrap workspace.yml
Documentation
Full documentation, architecture guides, and step-by-step tutorials are available at: 👉 https://github.com/Bralabee/sigantry/tree/main/docs
License
Sigantry is licensed under the Apache License, Version 2.0.
Metadata
Release files for sigantry 1.0.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| sigantry-1.0.1.tar.gz | 363.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| sigantry-1.0.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 790.6 kB
Release files / sigantry-1.0.1.tar.gz
| Download URL | sigantry-1.0.1.tar.gz |
|---|---|
| Size | 363.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d9779ef989353717d1b361802a04b2a6ae846f07f85974f771aa34528bb75e93
|
|
BLAKE2b-256 checksum How to use checksums |
aadbb73cd2b994227a5cfa42513270dcad88f7383ac5e4c937696968b10de216
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.
Transparency logRelease files / sigantry-1.0.1-py3-none-any.whl
| Download URL | sigantry-1.0.1-py3-none-any.whl |
|---|---|
| Size | 426.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a0aa3093acdb55363fd11eeb6adff64cf4a986bbab8c13fd60b42a07e231e1ad
|
|
BLAKE2b-256 checksum How to use checksums |
a8eaa06cccb26c43cda2e8013dd8346ab662b5a259f7e5a296e6549d25f71625
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.
Transparency log