Manage NetBox prefixes and Kea DHCP scopes together from a single subnet
definition under config/<region>/<dc>/subnets/<name>.yaml.
- modules/ipam: netbox_prefix + netbox_ip_range (dhcp role) + gateway/managed
netbox_ip_address + kea_subnet; tokens read from Vault KV via the vault provider
- environments/au/syd1 terragrunt env, Consul state backend
- config seed: five DHCP subnets (198.18.13-17) + local netbox-only 198.18.25.0/24
- .woodpecker pre-commit+plan on PR, apply on main; Makefile Vault auth pattern
Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT