Secure Password Validation & Automated Credential Rotation using Python
Introduction
In modern DevOps and SRE environments, engineers are responsible not only for automation and reliability but also for security and compliance.
One common but often overlooked risk is weak or improperly managed credentials.
In this blog, I’ll walk through a real-world DevOps automation where I built a secure password validation and credential rotation system using Python, following industry best practices.
The Real-World Problem
In many organizations:
Internal tools rely on local admin users
Passwords are:
weak
reused
manually rotated (or never rotated)
Credentials are sometimes stored in plaintext or config files
This creates:
Security vulnerabilities
Audit failures (SOC2, ISO, PCI)
High operational risk
Goal of the Project
Build a system that:
✅ Enforces strong password policies
✅ Prevents weak credentials from entering the system
✅ Securely hashes passwords (never stores plaintext)
✅ Supports automated credential rotation
✅ Integrates naturally into DevOps workflows
Password Validation Rules Implemented
The script enforces the following policies:
Minimum 10 characters
At least:
one uppercase letter
one lowercase letter
one digit
one special character (
@ # $ %)
No consecutive repeating characters (
aa,11,##)Clear validation errors for easier debugging
Core Validation Logic
MIN_LENGTH = 10
SPECIAL_CHARS = set("@#$%")
def validate_password(password: str) -> None:
if len(password) < MIN_LENGTH:
raise ValueError("Password too short")
if not any(c.isupper() for c in password):
raise ValueError("Missing uppercase letter")
if not any(c.islower() for c in password):
raise ValueError("Missing lowercase letter")
if not any(c.isdigit() for c in password):
raise ValueError("Missing digit")
if not any(c in SPECIAL_CHARS for c in password):
raise ValueError("Missing special character")
for i in range(len(password) - 1):
if password[i] == password[i + 1]:
raise ValueError("Consecutive repeating characters not allowed")
Secure Password Hashing with bcrypt
Instead of storing passwords:
The password is hashed using bcrypt
bcrypt automatically:
generates a salt
protects against brute-force attacks
import bcrypt
def hash_password(password: str) -> bytes:
return bcrypt.hashpw(password.encode(), bcrypt.gensalt())
Plaintext passwords are never stored or logged.
Automated Credential Rotation (DevOps Use Case)
This system is designed to rotate service credentials, not human passwords.
Examples:
Jenkins admin password
Internal API basic-auth credentials
Automation bot accounts
How rotation works:
Generate a new password
Validate it against policy
Hash it securely
Store it in a secrets manager
Restart or reload the consuming service
Final Code
#take user input , password in string
import bcrypt
# ---------------- CONFIG ----------------
MIN_LENGTH = 10
SPECIAL_CHARS = set("@#$%")
def has_consecutive_chars(pwd):
for i in range(len(pwd)-1):
if pwd[i]==pwd[i+1]:
return True
return False
def one_upper(passwrd):
return any(each_char.isupper() for each_char in passwrd)
def one_lower(passwrd):
return any(each_char.islower() for each_char in passwrd)
def one_num(passwrd):
return any(each_char.isdigit() for each_char in passwrd)
def one_special_char(passwrd):
#return any(not each_char.isalnum() for each_char in passwrd)
return any(c in SPECIAL_CHARS for c in passwrd)
def password_validation(pwd):
if len(pwd) < MIN_LENGTH:
raise ValueError(f"Password length should be atleast {MIN_LENGTH} characters in it")
if not one_upper(pwd):
raise ValueError("Password must have atleast 1 upper case character")
if not one_lower(pwd):
raise ValueError("Password must have atleast 1 lower case character")
if not one_num(pwd):
raise ValueError("Password must have atleast 1 digit")
if not one_special_char(pwd):
raise ValueError(f"Password must contain at least one special character {SPECIAL_CHARS}")
if has_consecutive_chars(pwd):
raise ValueError("Password must not have 2 consecutive same characters like (ss,##,11,AA)")
return True
# ---------------- HASHING ----------------
def bcrypt_pass(pwd):
#convert password to byte
pass_in_bytes = pwd.encode('utf-8')
#add salt and hass the byte password
return bcrypt.hashpw(pass_in_bytes, bcrypt.gensalt())
user_pass = input("Please enter the password\nPassword should be of minimum 10 characters: ")
try:
password_validation(user_pass)
print("Passowrd Created Successfully")
bcrypt_pass(user_pass)
except ValueError as e:
print(f"Passowrd creation failed: {e}")
Conclusion
Password handling is not just an application concern — it’s a platform reliability and security problem.
By automating password validation and rotation, DevOps teams can significantly reduce risk while improving operational maturity.
This project showcases how Python scripting can be used to solve real-world DevOps security challenges.