Infer NetBox user from the engine role config
Why: - The NetBox service identity was split across two files (config/netbox_user and config/netbox_secret_backend_role) that repeated the username three times: the filename, a netbox_username field, and the permission name. - Creating the engine role and creating its NetBox user are one act, so one file should describe the whole identity. How: - Make config/netbox_secret_backend_role/netbox/<name>.yaml the single source per identity: filename = engine role name = NetBox username, body = write access, TTLs, and an inline permissions block. - Derive netbox_username from the filename in config.hcl (keep netbox_user_id as an optional override), and drop the netbox_username field from the role yaml. - Iterate that same role map in the netbox_user_management module, keyed by config path, to synthesize the NetBox user and object permissions; default a single permission's name to the role name so nothing repeats the filename. - Delete the config/netbox_user tree and its netbox_user variable/wiring. - Scope terraform-infra to view/add/change/delete on the IPAM/DCIM objects it manages: prefixes, ip-addresses, ip-ranges, devices, interfaces, mac addresses.
This commit is contained in:
@@ -431,7 +431,7 @@ variable "netbox_secret_backend" {
|
||||
}
|
||||
|
||||
variable "netbox_secret_backend_role" {
|
||||
description = "Map of netbox token-minting roles to create"
|
||||
description = "Map of netbox engine roles; each role's filename-derived name is both the engine role and the NetBox username it mints tokens for, and its permissions block is the user's object-permission set"
|
||||
type = map(object({
|
||||
name = string
|
||||
backend = string
|
||||
@@ -441,19 +441,11 @@ variable "netbox_secret_backend_role" {
|
||||
description = optional(string)
|
||||
ttl = optional(number)
|
||||
max_ttl = optional(number)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "netbox_user" {
|
||||
description = "Map of NetBox service users to create declaratively (keyed by username; 1:1 with the engine role name)"
|
||||
type = map(object({
|
||||
backend = string
|
||||
active = optional(bool, true)
|
||||
staff = optional(bool, false)
|
||||
email = optional(string)
|
||||
active = optional(bool, true)
|
||||
staff = optional(bool, false)
|
||||
email = optional(string)
|
||||
permissions = optional(list(object({
|
||||
name = string
|
||||
name = optional(string)
|
||||
object_types = list(string)
|
||||
actions = optional(list(string), ["view", "add", "change", "delete"])
|
||||
constraints = optional(string)
|
||||
|
||||
Reference in New Issue
Block a user