Developer control plane for local Azure emulation, events, and storage workflows
2.5K
A developer control plane for local cloud emulators — Azurite, Azure Service Bus, Azure Event Hubs, Google Cloud Pub/Sub, S3-compatible stores. One image serving an HTTP API and a web UI.
docker run -p 8080:8080 sadhasivam/azura
Then open http://localhost:8080. It runs with no configuration, so you can look before you set anything up.
| Tag | |
|---|---|
latest | most recent stable release |
0.1.0 · v0.1.0 | a specific release, both spellings |
0.1.0-rc.N | prereleases — never tagged latest |
Pin a version. Under semver a 0.x minor may break anything, so latest
moves across breaking changes.
Platforms: linux/amd64, linux/arm64
Size: ~14 MB compressed, 13 layers
Base: gcr.io/distroless/static-debian12:nonroot — static binary, no
shell, no package manager
| Entrypoint | /usr/local/bin/azura |
| Default command | serve |
| Exposed port | 8080/tcp |
| User | nonroot:nonroot (uid 65532) |
| Working directory | /home/nonroot |
| Config path (convention) | /etc/azura/azura.yaml |
AZURA_SERVER__HTTP__ADDR is preset to 0.0.0.0:8080. Do not set it to
127.0.0.1 — a loopback bind inside a container is unreachable through a
published port.
Append to the image name; the entrypoint is the binary.
docker run --rm sadhasivam/azura version
docker run -p 8080:8080 sadhasivam/azura serve --config /etc/azura/azura.yaml
serve · status · stop · version
Any setting can be overridden with an AZURA_ variable. Path segments are
separated by a double underscore; a single underscore belongs to the key.
-e AZURA_LOG__LEVEL=debug # debug | info | warn | error
-e AZURA_LOG__FORMAT=json # text | json
-e AZURA_SERVER__HTTP__ADDR=0.0.0.0:8080
-e AZURA_SERVER__GRPC__ENABLED=true # second listener on 9090, off by default
-e AZURA_OBSERVABILITY__WEB_VITALS__ENABLED=false
-e AZURA_OBSERVABILITY__SENTRY__ENABLED=false
Lists cannot be expressed this way — there is no spelling for
workspaces[0].storage.accounts[0].id — so the emulators themselves have to
come from a mounted file.
One optional mount. Azura never writes it, so mount it read-only.
/etc/azura/azura.yaml your configuration
There is no state to persist: Azura has no database, and everything it shows lives in the emulators it connects to.
8080 HTTP — API and UI
9090 gRPC — only when AZURA_SERVER__GRPC__ENABLED=true
No HEALTHCHECK is baked in, because the binary is the only thing in the
image and there is no shell or curl to probe with. From outside:
healthcheck:
test: ["CMD", "/usr/local/bin/azura", "status"]
interval: 15s
timeout: 5s
retries: 3
Resolution order, each overriding the last: built-in defaults → azura.yaml
→ AZURA_* variables → command-line flags.
Everything is declared under a workspace, which is a container and nothing more — Azura makes no claim about what belongs in one. Most setups need exactly one.
workspaces:
- id: default
storage:
accounts:
- id: azurite
provider: azure.blob
endpoint: "http://azurite:10000"
account_name: devstoreaccount1
account_key: "${AZURITE_KEY}" # ${VAR} is expanded
messaging:
namespaces:
- id: pubsub
provider: gcp.pubsub
project_id: local
emulator_host: "pubsub-emulator:8085"
Endpoints are service names, not 127.0.0.1. Inside a container,
localhost is that container.
Providers: azure.blob, azure.servicebus, azure.eventhubs, gcp.pubsub,
aws.s3 (objects only, untested). Each advertises what it supports and the
API returns 501 for the rest, so the UI never offers an action that must
fail.
services:
azurite:
image: mcr.microsoft.com/azure-storage/azurite:latest
command: azurite --blobHost 0.0.0.0 --loose --skipApiVersionCheck
networks: [azura]
azura:
image: sadhasivam/azura:0.1.0
ports: ["8080:8080"]
volumes:
- ./azura.yaml:/etc/azura/azura.yaml:ro
command: ["serve", "--config", "/etc/azura/azura.yaml"]
networks: [azura]
depends_on: [azurite]
networks:
azura:
No authentication. This is a local development tool — do not publish the port beyond your machine.
Nothing leaves the host by default: error reporting is off and ships no DSN, and browser timings stay in a bounded in-memory buffer cleared on restart. Credentials are never returned by any endpoint, never appear in a URL, and are redacted before they reach the log buffer.
Source and documentation: https://github.com/sadhasivam/azura
Content type
Image
Digest
sha256:fbded9f46…
Size
17.9 MB
Last updated
1 day ago
docker pull sadhasivam/azura