Skip to main content

Command Palette

Search for a command to run...

Secure Password Validation & Automated Credential Rotation using Python

Published
•3 min read•View as Markdown

Introduction

In modern DevOps and SRE environments, engineers are responsible not only for automation and reliability but also for security and compliance.
One common but often overlooked risk is weak or improperly managed credentials.

In this blog, I’ll walk through a real-world DevOps automation where I built a secure password validation and credential rotation system using Python, following industry best practices.

The Real-World Problem

In many organizations:

  • Internal tools rely on local admin users

  • Passwords are:

    • weak

    • reused

    • manually rotated (or never rotated)

  • Credentials are sometimes stored in plaintext or config files

This creates:

  • Security vulnerabilities

  • Audit failures (SOC2, ISO, PCI)

  • High operational risk

Goal of the Project

Build a system that:

✅ Enforces strong password policies
✅ Prevents weak credentials from entering the system
✅ Securely hashes passwords (never stores plaintext)
✅ Supports automated credential rotation
✅ Integrates naturally into DevOps workflows

Password Validation Rules Implemented

The script enforces the following policies:

  • Minimum 10 characters

  • At least:

    • one uppercase letter

    • one lowercase letter

    • one digit

    • one special character (@ # $ %)

  • No consecutive repeating characters (aa, 11, ##)

  • Clear validation errors for easier debugging

Core Validation Logic

MIN_LENGTH = 10
SPECIAL_CHARS = set("@#$%")

def validate_password(password: str) -> None:
    if len(password) < MIN_LENGTH:
        raise ValueError("Password too short")

    if not any(c.isupper() for c in password):
        raise ValueError("Missing uppercase letter")

    if not any(c.islower() for c in password):
        raise ValueError("Missing lowercase letter")

    if not any(c.isdigit() for c in password):
        raise ValueError("Missing digit")

    if not any(c in SPECIAL_CHARS for c in password):
        raise ValueError("Missing special character")

    for i in range(len(password) - 1):
        if password[i] == password[i + 1]:
            raise ValueError("Consecutive repeating characters not allowed")

Secure Password Hashing with bcrypt

Instead of storing passwords:

  • The password is hashed using bcrypt

  • bcrypt automatically:

    • generates a salt

    • protects against brute-force attacks

import bcrypt

def hash_password(password: str) -> bytes:
    return bcrypt.hashpw(password.encode(), bcrypt.gensalt())

Plaintext passwords are never stored or logged.

Automated Credential Rotation (DevOps Use Case)

This system is designed to rotate service credentials, not human passwords.

Examples:

  • Jenkins admin password

  • Internal API basic-auth credentials

  • Automation bot accounts

How rotation works:

  1. Generate a new password

  2. Validate it against policy

  3. Hash it securely

  4. Store it in a secrets manager

  5. Restart or reload the consuming service

Final Code


#take user input , password in string
import bcrypt

# ---------------- CONFIG ----------------
MIN_LENGTH = 10
SPECIAL_CHARS = set("@#$%")

def has_consecutive_chars(pwd):
    for i in range(len(pwd)-1):
        if pwd[i]==pwd[i+1]:
            return True
    return False

def one_upper(passwrd):
    return any(each_char.isupper() for each_char in passwrd)

def one_lower(passwrd):
    return any(each_char.islower() for each_char in passwrd)

def one_num(passwrd):
    return any(each_char.isdigit() for each_char in passwrd)

def one_special_char(passwrd):
    #return any(not each_char.isalnum() for each_char in passwrd)
    return any(c in SPECIAL_CHARS for c in passwrd)

def password_validation(pwd):
        if len(pwd) < MIN_LENGTH:
            raise ValueError(f"Password length should be atleast {MIN_LENGTH} characters in it")
        if not one_upper(pwd):
            raise ValueError("Password must have atleast 1 upper case character")
        if not one_lower(pwd):
            raise ValueError("Password must have atleast 1 lower case character")
        if not one_num(pwd):
            raise ValueError("Password must have atleast 1 digit")
        if not one_special_char(pwd):
            raise ValueError(f"Password must contain at least one special character {SPECIAL_CHARS}")
        if has_consecutive_chars(pwd):
            raise ValueError("Password must not have 2 consecutive same characters like (ss,##,11,AA)")
        return True

# ---------------- HASHING ----------------
def bcrypt_pass(pwd):

    #convert password to byte
    pass_in_bytes = pwd.encode('utf-8')

    #add salt and hass the byte password
    return bcrypt.hashpw(pass_in_bytes, bcrypt.gensalt())

user_pass = input("Please enter the password\nPassword should be of minimum 10 characters: ")

try:
    password_validation(user_pass)
    print("Passowrd Created Successfully")
    bcrypt_pass(user_pass)
except ValueError as e:
    print(f"Passowrd creation failed: {e}")

Conclusion

Password handling is not just an application concern — it’s a platform reliability and security problem.
By automating password validation and rotation, DevOps teams can significantly reduce risk while improving operational maturity.

This project showcases how Python scripting can be used to solve real-world DevOps security challenges.