The Go port of the Libre DevOps Helpers command line: one binary for day-to-day security and platform work.
ldo-go is a fast, read-only command line for Microsoft (Entra ID, Defender XDR, Intune,
Azure, Graph, PIM, Logic Apps), ServiceNow, Jira and Confluence, with helpers for Terraform
modules. It signs in as you, and can read only what you can.
It is the Go port of ldo, the Python
original, and an experiment in how far a port gets: the Python ldo is the reference. The
two share a config file and behave the same, command for command, and every way they differ
is written down in How it differs.
- One binary, with nothing to install first: no Python, no virtual environment.
- Pure Go sign-in, through Microsoft's own libraries (azidentity and MSAL): with
auth = "device-code"or"interactive", a person signs in without the Azure CLI at all. The Azure CLI is still used by the defaultauth = "azure-cli", since its sign-in lives in its own token cache.
| Command | What it does | Docs |
|---|---|---|
ldo-go devices |
check a list of devices across Entra, Defender and Intune, watch until they are all there, show one, read Defender Antivirus versions | devices |
ldo-go entra |
devices and whether they are in a group, users, groups, roles, sign-ins, app credentials, Conditional Access; tokens | entra |
ldo-go intune |
managed devices: compliance, last sync, owner | entra |
ldo-go xdr |
Defender machines, alerts, vulnerabilities, indicators, Advanced Hunting, a device's timeline, custom detection rules (and their export to YAML), MDE Client Analyzer results | defender |
ldo-go xdr incidents |
the Defender XDR queue, Sentinel's included: top, latest, between days, summary | defender |
ldo-go graph |
any Graph GET, objects by name, whoami, a Graph token, hunting |
graph |
ldo-go azure |
subscriptions, Resource Graph, role assignments, Defender for Cloud, splitting resource ids into their parts | azure |
ldo-go azure automation |
Automation accounts: runbook jobs, and each job's logs and output | azure |
ldo-go keyvault |
secrets, certificates and keys close to expiry | azure |
ldo-go logs |
KQL against a Log Analytics or Sentinel workspace, and which tables are receiving data | azure |
ldo-go pim |
eligible, active and standing access, requests, approvals, activation settings | pim |
ldo-go logicapp |
offline checks, export and validation for Consumption Logic Apps and Sentinel playbooks | logic apps |
ldo-go snow |
ServiceNow: sign in, whoami, the instance, applications, a token | servicenow |
ldo-go news |
Microsoft 365 Message Center: posts by date, service and category, one post as Markdown | message center |
ldo-go planner |
Microsoft Planner: plans, buckets, tasks, and a task for each Message Center post, or one a month summing them up | message center |
ldo-go jira |
Jira Cloud: issues by JQL or project, one issue with its description as Markdown, projects | atlassian |
ldo-go confluence |
Confluence Cloud: spaces, pages, one page as Markdown, CQL search | atlassian |
ldo-go terraform |
a Terraform module's variables and outputs in name order, and its README from HEADER.md and terraform-docs | terraform |
ldo-go az |
switch the Azure CLI between profiles | signing in |
ldo-go network test |
test the way out through a corporate proxy: the proxy, the certificates, each service | network |
ldo-go json |
pretty-print any JSON (az rest ... | ldo-go json) in colour, or as YAML |
configuration |
ldo-go profiles, ldo-go config |
your profiles, and the config file | configuration |
Every data command takes -p for a profile and -o table|json|csv|tsv|html, lists take
--sort and --unique by column, and lists of names come from arguments, stdin, a text
file, or a column of a CSV or Excel workbook.
From a release: one binary for Linux,
macOS or Windows, on amd64 or arm64. Check it against SHA256SUMS, and its build provenance
with gh attestation verify:
gh release download --repo libre-devops/ldo-go-cli --pattern ldo-go-linux-amd64 --pattern SHA256SUMS
sha256sum --check --ignore-missing SHA256SUMS
gh attestation verify ldo-go-linux-amd64 --repo libre-devops/ldo-go-cli
install -m 0755 ldo-go-linux-amd64 ~/.local/bin/ldo-goWith Go:
go install github.com/libre-devops/ldo-go-cli/cmd/ldo-go@latestOr from the source, with just: just build writes
bin/ldo-go. The Azure CLI is needed only for azure-cli profiles, and terraform-docs only
for ldo-go terraform docs.
ldo-go config init # write a config file to fill in, if you have none yet
ldo-go profiles # your profiles, which is active, and which can sign in
ldo-go graph whoami # who you are, and what your token may do
ldo-go devices check web01,web02
ldo-go network test # behind a corporate proxy? test the way out firstThe Python ldo and ldo-go read the same config file, so a profile set up for one works
for the other. Each keeps its own sign-ins.
Everything is in docs: configuration, signing in, permissions, proxies and certificates, a page for each group of commands, and how it differs from the Python ldo.
just check runs gofmt, go vet and the tests with a coverage floor; just ci adds
staticcheck and govulncheck, as CI runs them. Nothing in a test touches the network, a real
az or a real clock. Development covers the layout, the tests and
their fakes, the self-test in a real tenant, CI and releasing; CONTRIBUTING.md
and AI.md the conventions. The changes are in the changelog.
MIT.