Infer NetBox user from the engine role config
Why: - The NetBox service identity was split across two files (config/netbox_user and config/netbox_secret_backend_role) that repeated the username three times: the filename, a netbox_username field, and the permission name. - Creating the engine role and creating its NetBox user are one act, so one file should describe the whole identity. How: - Make config/netbox_secret_backend_role/netbox/<name>.yaml the single source per identity: filename = engine role name = NetBox username, body = write access, TTLs, and an inline permissions block. - Derive netbox_username from the filename in config.hcl (keep netbox_user_id as an optional override), and drop the netbox_username field from the role yaml. - Iterate that same role map in the netbox_user_management module, keyed by config path, to synthesize the NetBox user and object permissions; default a single permission's name to the role name so nothing repeats the filename. - Delete the config/netbox_user tree and its netbox_user variable/wiring. - Scope terraform-infra to view/add/change/delete on the IPAM/DCIM objects it manages: prefixes, ip-addresses, ip-ranges, devices, interfaces, mac addresses.
This commit is contained in:
+3
-7
@@ -260,15 +260,11 @@ locals {
|
|||||||
netbox_secret_backend_role = {
|
netbox_secret_backend_role = {
|
||||||
for file_path, content in local.all_configs :
|
for file_path, content in local.all_configs :
|
||||||
trimsuffix(replace(file_path, "netbox_secret_backend_role/", ""), ".yaml") => merge(content, {
|
trimsuffix(replace(file_path, "netbox_secret_backend_role/", ""), ".yaml") => merge(content, {
|
||||||
name = trimsuffix(basename(file_path), ".yaml")
|
name = trimsuffix(basename(file_path), ".yaml")
|
||||||
backend = dirname(replace(file_path, "netbox_secret_backend_role/", ""))
|
netbox_username = trimsuffix(basename(file_path), ".yaml")
|
||||||
|
backend = dirname(replace(file_path, "netbox_secret_backend_role/", ""))
|
||||||
})
|
})
|
||||||
if startswith(file_path, "netbox_secret_backend_role/")
|
if startswith(file_path, "netbox_secret_backend_role/")
|
||||||
}
|
}
|
||||||
netbox_user = {
|
|
||||||
for file_path, content in local.all_configs :
|
|
||||||
trimsuffix(basename(file_path), ".yaml") => content
|
|
||||||
if startswith(file_path, "netbox_user/")
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,10 +1,25 @@
|
|||||||
# Role minting ephemeral NetBox tokens for the terraform-infra CI runner.
|
# Single declarative source for the terraform-infra NetBox service identity. The
|
||||||
# terraform-infra manages NetBox IPAM/devices, so tokens carry write access
|
# filename stem is the engine role name AND the NetBox username (1:1); config.hcl
|
||||||
# (write_enabled true). Very short TTLs because a token is minted per plan/apply
|
# derives both from it, so neither is repeated below. Creating this file creates
|
||||||
# and revoked when the run's lease ends. Reading netbox/creds/terraform-infra
|
# the user: the netbox_user_management module synthesizes the NetBox user + object
|
||||||
# mints a lease-bound token deleted from NetBox on revoke/expiry.
|
# permissions from the permissions block, and the engine role mints ephemeral
|
||||||
|
# tokens for that same user. write_enabled true because terraform-infra manages
|
||||||
|
# NetBox IPAM/DCIM; very short TTLs because a token is minted per plan/apply and
|
||||||
|
# revoked when the run's lease ends.
|
||||||
---
|
---
|
||||||
netbox_username: terraform-infra
|
|
||||||
write_enabled: true
|
write_enabled: true
|
||||||
ttl: 120 # 2m
|
ttl: 120 # 2m
|
||||||
max_ttl: 300 # 5m
|
max_ttl: 300 # 5m
|
||||||
|
permissions:
|
||||||
|
- object_types:
|
||||||
|
- ipam.prefix
|
||||||
|
- ipam.ipaddress
|
||||||
|
- ipam.iprange
|
||||||
|
- dcim.device
|
||||||
|
- dcim.interface
|
||||||
|
- dcim.macaddress
|
||||||
|
actions:
|
||||||
|
- view
|
||||||
|
- add
|
||||||
|
- change
|
||||||
|
- delete
|
||||||
|
|||||||
@@ -1,31 +0,0 @@
|
|||||||
# Declarative NetBox service identity for the terraform-infra CI runner. The
|
|
||||||
# filename stem is the NetBox username and matches the netbox engine role name
|
|
||||||
# 1:1 (netbox/roles/terraform-infra mints tokens for this user). Ben seeds only
|
|
||||||
# the engine admin token; this user and its permissions are created from here,
|
|
||||||
# never by hand. Write access covers the IPAM/DCIM objects terraform-infra
|
|
||||||
# manages (prefixes, ip-addresses, ip-ranges, devices, interfaces, mac
|
|
||||||
# addresses, plus the supporting role/tag/type objects it also touches).
|
|
||||||
---
|
|
||||||
backend: netbox
|
|
||||||
active: true
|
|
||||||
staff: false
|
|
||||||
permissions:
|
|
||||||
- name: terraform-infra
|
|
||||||
description: terraform-infra IPAM/DCIM write access (tokens minted by Vault)
|
|
||||||
object_types:
|
|
||||||
- ipam.prefix
|
|
||||||
- ipam.ipaddress
|
|
||||||
- ipam.iprange
|
|
||||||
- ipam.role
|
|
||||||
- dcim.device
|
|
||||||
- dcim.interface
|
|
||||||
- dcim.macaddress
|
|
||||||
- dcim.manufacturer
|
|
||||||
- dcim.devicetype
|
|
||||||
- dcim.devicerole
|
|
||||||
- extras.tag
|
|
||||||
actions:
|
|
||||||
- view
|
|
||||||
- add
|
|
||||||
- change
|
|
||||||
- delete
|
|
||||||
@@ -89,7 +89,6 @@ inputs = {
|
|||||||
|
|
||||||
netbox_secret_backend = local.config.netbox_secret_backend
|
netbox_secret_backend = local.config.netbox_secret_backend
|
||||||
netbox_secret_backend_role = local.config.netbox_secret_backend_role
|
netbox_secret_backend_role = local.config.netbox_secret_backend_role
|
||||||
netbox_user = local.config.netbox_user
|
|
||||||
|
|
||||||
# Pass policy maps to vault_cluster module
|
# Pass policy maps to vault_cluster module
|
||||||
policy_auth_map = local.policies.policy_auth_map
|
policy_auth_map = local.policies.policy_auth_map
|
||||||
|
|||||||
@@ -477,13 +477,15 @@ module "netbox_secret_backend" {
|
|||||||
|
|
||||||
# Declaratively manage the NetBox service users + object permissions the engine
|
# Declaratively manage the NetBox service users + object permissions the engine
|
||||||
# roles mint tokens for, using the seeded admin token (mirrors consul_acl_management).
|
# roles mint tokens for, using the seeded admin token (mirrors consul_acl_management).
|
||||||
|
# Consumes the SAME role config as netbox_secret_backend_role: one file per identity,
|
||||||
|
# filename-derived username, inline permissions.
|
||||||
module "netbox_user_management" {
|
module "netbox_user_management" {
|
||||||
source = "./modules/netbox_user_management"
|
source = "./modules/netbox_user_management"
|
||||||
|
|
||||||
country = var.country
|
country = var.country
|
||||||
region = var.region
|
region = var.region
|
||||||
netbox_backends = var.netbox_secret_backend
|
netbox_backends = var.netbox_secret_backend
|
||||||
netbox_users = var.netbox_user
|
netbox_roles = var.netbox_secret_backend_role
|
||||||
netbox_backend_aliases = var.netbox_backend_aliases
|
netbox_backend_aliases = var.netbox_backend_aliases
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -24,19 +24,20 @@ provider "netbox" {
|
|||||||
# NetBox users authenticate only via Vault-minted API tokens, never the web UI,
|
# NetBox users authenticate only via Vault-minted API tokens, never the web UI,
|
||||||
# so give each a random unknown password (required by the API) that no one holds.
|
# so give each a random unknown password (required by the API) that no one holds.
|
||||||
resource "random_password" "user" {
|
resource "random_password" "user" {
|
||||||
for_each = var.netbox_users
|
for_each = var.netbox_roles
|
||||||
|
|
||||||
length = 32
|
length = 32
|
||||||
special = true
|
special = true
|
||||||
}
|
}
|
||||||
|
|
||||||
# Declarative NetBox service users, one per engine role (username == role name).
|
# Declarative NetBox service users, one per engine role. The role's filename-
|
||||||
|
# derived name is the username, so the engine role and its user match 1:1.
|
||||||
resource "netbox_user" "users" {
|
resource "netbox_user" "users" {
|
||||||
for_each = var.netbox_users
|
for_each = var.netbox_roles
|
||||||
|
|
||||||
provider = netbox.by_backend[each.value.backend]
|
provider = netbox.by_backend[each.value.backend]
|
||||||
|
|
||||||
username = each.key
|
username = each.value.name
|
||||||
password = random_password.user[each.key].result
|
password = random_password.user[each.key].result
|
||||||
active = each.value.active
|
active = each.value.active
|
||||||
staff = each.value.staff
|
staff = each.value.staff
|
||||||
@@ -44,14 +45,16 @@ resource "netbox_user" "users" {
|
|||||||
}
|
}
|
||||||
|
|
||||||
locals {
|
locals {
|
||||||
# Flatten users x permissions into one map keyed by "<user>:<permission>".
|
# Flatten roles x permissions into one map keyed by "<role_path>:<index>". A
|
||||||
|
# permission's name defaults to the role name (the username) so a single-
|
||||||
|
# permission identity repeats nothing already encoded by the filename.
|
||||||
netbox_permissions = merge([
|
netbox_permissions = merge([
|
||||||
for username, user in var.netbox_users : {
|
for role_key, role in var.netbox_roles : {
|
||||||
for perm in user.permissions :
|
for idx, perm in role.permissions :
|
||||||
"${username}:${perm.name}" => {
|
"${role_key}:${idx}" => {
|
||||||
backend = user.backend
|
backend = role.backend
|
||||||
user = username
|
user = role_key
|
||||||
name = perm.name
|
name = coalesce(perm.name, length(role.permissions) == 1 ? role.name : "${role.name}-${idx}")
|
||||||
object_types = perm.object_types
|
object_types = perm.object_types
|
||||||
actions = perm.actions
|
actions = perm.actions
|
||||||
constraints = perm.constraints
|
constraints = perm.constraints
|
||||||
|
|||||||
@@ -6,15 +6,16 @@ variable "netbox_backends" {
|
|||||||
}))
|
}))
|
||||||
}
|
}
|
||||||
|
|
||||||
variable "netbox_users" {
|
variable "netbox_roles" {
|
||||||
description = "Map of NetBox service users to create declaratively, keyed by username (1:1 with the engine role name)"
|
description = "Map of netbox engine roles (the netbox_secret_backend_role config). Each role's filename-derived name is the NetBox username to create, and its permissions block is the user's object-permission set. Keyed by the role's config path."
|
||||||
type = map(object({
|
type = map(object({
|
||||||
|
name = string
|
||||||
backend = string
|
backend = string
|
||||||
active = optional(bool, true)
|
active = optional(bool, true)
|
||||||
staff = optional(bool, false)
|
staff = optional(bool, false)
|
||||||
email = optional(string)
|
email = optional(string)
|
||||||
permissions = optional(list(object({
|
permissions = optional(list(object({
|
||||||
name = string
|
name = optional(string)
|
||||||
object_types = list(string)
|
object_types = list(string)
|
||||||
actions = optional(list(string), ["view", "add", "change", "delete"])
|
actions = optional(list(string), ["view", "add", "change", "delete"])
|
||||||
constraints = optional(string)
|
constraints = optional(string)
|
||||||
|
|||||||
@@ -431,7 +431,7 @@ variable "netbox_secret_backend" {
|
|||||||
}
|
}
|
||||||
|
|
||||||
variable "netbox_secret_backend_role" {
|
variable "netbox_secret_backend_role" {
|
||||||
description = "Map of netbox token-minting roles to create"
|
description = "Map of netbox engine roles; each role's filename-derived name is both the engine role and the NetBox username it mints tokens for, and its permissions block is the user's object-permission set"
|
||||||
type = map(object({
|
type = map(object({
|
||||||
name = string
|
name = string
|
||||||
backend = string
|
backend = string
|
||||||
@@ -441,19 +441,11 @@ variable "netbox_secret_backend_role" {
|
|||||||
description = optional(string)
|
description = optional(string)
|
||||||
ttl = optional(number)
|
ttl = optional(number)
|
||||||
max_ttl = optional(number)
|
max_ttl = optional(number)
|
||||||
}))
|
active = optional(bool, true)
|
||||||
default = {}
|
staff = optional(bool, false)
|
||||||
}
|
email = optional(string)
|
||||||
|
|
||||||
variable "netbox_user" {
|
|
||||||
description = "Map of NetBox service users to create declaratively (keyed by username; 1:1 with the engine role name)"
|
|
||||||
type = map(object({
|
|
||||||
backend = string
|
|
||||||
active = optional(bool, true)
|
|
||||||
staff = optional(bool, false)
|
|
||||||
email = optional(string)
|
|
||||||
permissions = optional(list(object({
|
permissions = optional(list(object({
|
||||||
name = string
|
name = optional(string)
|
||||||
object_types = list(string)
|
object_types = list(string)
|
||||||
actions = optional(list(string), ["view", "add", "change", "delete"])
|
actions = optional(list(string), ["view", "add", "change", "delete"])
|
||||||
constraints = optional(string)
|
constraints = optional(string)
|
||||||
|
|||||||
Reference in New Issue
Block a user