Infer NetBox user from the engine role config
ci/woodpecker/pr/plan Pipeline failed
ci/woodpecker/pr/pre-commit Pipeline was successful

Why:
- The NetBox service identity was split across two files (config/netbox_user
  and config/netbox_secret_backend_role) that repeated the username three
  times: the filename, a netbox_username field, and the permission name.
- Creating the engine role and creating its NetBox user are one act, so one
  file should describe the whole identity.

How:
- Make config/netbox_secret_backend_role/netbox/<name>.yaml the single source
  per identity: filename = engine role name = NetBox username, body = write
  access, TTLs, and an inline permissions block.
- Derive netbox_username from the filename in config.hcl (keep netbox_user_id
  as an optional override), and drop the netbox_username field from the role
  yaml.
- Iterate that same role map in the netbox_user_management module, keyed by
  config path, to synthesize the NetBox user and object permissions; default a
  single permission's name to the role name so nothing repeats the filename.
- Delete the config/netbox_user tree and its netbox_user variable/wiring.
- Scope terraform-infra to view/add/change/delete on the IPAM/DCIM objects it
  manages: prefixes, ip-addresses, ip-ranges, devices, interfaces, mac
  addresses.
This commit is contained in:
2026-08-09 12:37:45 +10:00
parent bd1bcc2db9
commit 702dc6c62f
8 changed files with 50 additions and 73 deletions
+5 -13
View File
@@ -431,7 +431,7 @@ variable "netbox_secret_backend" {
}
variable "netbox_secret_backend_role" {
description = "Map of netbox token-minting roles to create"
description = "Map of netbox engine roles; each role's filename-derived name is both the engine role and the NetBox username it mints tokens for, and its permissions block is the user's object-permission set"
type = map(object({
name = string
backend = string
@@ -441,19 +441,11 @@ variable "netbox_secret_backend_role" {
description = optional(string)
ttl = optional(number)
max_ttl = optional(number)
}))
default = {}
}
variable "netbox_user" {
description = "Map of NetBox service users to create declaratively (keyed by username; 1:1 with the engine role name)"
type = map(object({
backend = string
active = optional(bool, true)
staff = optional(bool, false)
email = optional(string)
active = optional(bool, true)
staff = optional(bool, false)
email = optional(string)
permissions = optional(list(object({
name = string
name = optional(string)
object_types = list(string)
actions = optional(list(string), ["view", "add", "change", "delete"])
constraints = optional(string)