Celeste by Aurelia
New From the AureliaK8s family

Azure, without fighting the portal.

Celeste brings together, in one desktop app, what your platform team does every day: testing APIs on a private API Management, checking which token each operation expects, copying secrets between Key Vaults and getting into private PostgreSQL databases without building tunnels by hand.

Screenshots show the app’s Spanish UI. Free macOS · Windows Uses your az CLI session
Celeste — API Management · Operations and policies
Celeste showing an API Management API: client → gateway → policies → backend flow and the policies per scope
7 operations will reject every tokenvalidate-jwt with an undefined audience
Private gateway, tested from your machineThrough Azure Bastion, no VPN
Speaks your Azure
Azure API ManagementSelf-hosted GatewayAzure Key VaultPostgreSQL Flexible ServerAzure BastionVNet integrationPrivate DNSpgwebvalidate-jwtAuth0Log AnalyticsEntra IDaz CLITerraform
Let’s be honest

Azure isn’t hard. The 40 portal tabs are.

A secret that has to move from one vault to another, an API that only answers inside the VNet and a private database you, once again, can’t reach today.

The API that only lives in the VNet

The gateway is internal, the portal can’t reach it and neither can Postman. To test one operation you end up borrowing a VM.

Celeste tests it from your machine, through Bastion, trace included.

Which token does this operation want?

The audience lives in a fragment, the scope in a variable and the issuer in a named value. Nobody knows until something returns 401.

It scans every policy and tells you, per audience and per operation.

Copy-pasting secrets

Open a vault, reveal the value, copy it, open another vault, create the secret, pray you didn’t drop a character.

One click: “Copy to another Key Vault”. And .env both ways.
30-second tour

Your whole platform Azure, in tabs.

Celeste
Celeste screenshot

API Management · Test

Test internal APIs without a VPN or borrowed VMs.

Pick an operation and hit “Test”. If the gateway lives inside a VNet, Celeste notices, finds its private IP and opens the way through Azure Bastion, direct or through a jump VM.

  • Public and private gateways: through Bastion or straight from your machine, depending on what resolves.
  • Step-by-step trace: which policy ran, which headers changed and what the backend answered.
  • Import cURL and pick the subscription key without hunting for it.
  • Readable policies: per scope, effective or as XML, with the fragments each operation uses.
Test console for an API Management operation
Connecting to a private gateway through Bastion
API Management · Audiences

Which token each operation expects. All of them. At once.

Celeste reads every API Management policy (global, products, APIs, operations and fragments), resolves the variables and returns every validate-jwt grouped by audience.

  • Audiences, scopes and issuers for each operation, and where they’re defined.
  • IAM findings: operations without a token, shared audiences and variables nobody sets.
  • Ready-made M2M code: tick operations and get the audience and scopes as a list, JSON or Terraform.
Audience detail with its APIs and operations
Audience indicators for an API Management instance
Key Vault

Hundreds of vaults. The ones that matter, in your menu.

Celeste finds the Key Vaults in all your subscriptions and lets you pin the ones you use to the menu. Inside, everything you do in the portal, with fewer clicks.

  • Copy to another Key Vault: move a secret to another vault without revealing or pasting its value.
  • Import and export .env: load variables in one go or take a vault to your local environment.
  • Expiring secrets, versions, deleted items with scheduled purge and who has access.
Key Vaults across every subscription
Key Vault toolbar with .env import and new secret
Private databases

Your private PostgreSQL, one click away. Literally.

The server is only reachable from its VNet. Celeste builds the tunnel through Azure Bastion to the jump VM, connects in a few seconds and opens pgweb so you can run queries without leaving the app.

  • Direct connection to private databases: Bastion → jump VM → PostgreSQL, no commands.
  • All your Flexible Servers: public and private, metrics, parameters and databases.
  • Saved Bastion tunnels: set them up once and get back in whenever you want, with their connection log.
Private PostgreSQL detail with its connection through Bastion
Connecting to a private server through Bastion and a jump VM
Features

What you do in the portal. And what the portal doesn’t.

Built for the day-to-day of platform, integration and security teams on Azure.

Full API Management

APIs, operations and policies per scope, real traffic from Log Analytics, versions and revisions, definition, consumers, products, subscriptions, named values, backends and self-hosted gateways.

Bastion without the pain

Saved tunnels with direct or jump-VM profiles, discovered from your subscriptions. No typing az network bastion tunnel.

Auth0 M2M vs API Management

Import your M2M apps report and see which ones have every scope API Management requires, which fall short and which don’t match at all.

Secrets, vault to vault

Copy a secret to another Key Vault without revealing it, create new versions and select several to export them to .env at once.

Tabs and search

VS Code-style tabs, favorites in the sidebar and a search that finds any resource.

Your credentials stay on your machine

No Azure passwords: it uses your az session. Anything sensitive it stores is encrypted on your machine.

And also…

  • Policy index: which API uses each fragment, named value and backend
  • Cached lists that paint instantly
  • Built-in terminal
  • Automatic updates
From the AureliaK8s family

Same jellyfish. Another ocean.

AureliaK8s takes care of your Kubernetes clusters. Celeste, of everything around them in Azure: gateways, secrets and databases. Same account to sign in, and both are free.

FAQ

Frequently asked questions

How much does it cost?

Nothing. Celeste is free, like AureliaK8s. If it saves you time, you can support the project with a donation.

What do I need installed?

The az CLI, signed in. Celeste uses that session to see your subscriptions; the Bastion hop is built in.

How does it reach private resources?

Through Azure Bastion. For API Management gateways and VNet-integrated PostgreSQL, it opens a tunnel to a jump VM inside the network and connects from there. You just pick the profile.

Can it change things in my Azure?

Only what you ask for: creating or copying a secret, a new version or deleting one, always with confirmation. The API Management, audiences and database views are read-only.

Where does my data go?

Nowhere. Celeste talks to Azure straight from your machine and keeps its cache and settings locally. You sign in with your AureliaK8s account, using a code sent to your email.

Which systems does it run on?

macOS (Apple Silicon) and Windows 10 and 11, with automatic updates.

Your Azure is waiting. Keep it at hand.

Download Celeste, sign in with your AureliaK8s account and pick your subscriptions. In a couple of minutes your gateways, vaults and databases are one click away.

Liked it? Support the project ✨