Add the netbox secrets engine modules and wiring
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful

Why:
- Managing NetBox from Vault needs three capabilities the repo does not yet
  have: mounting the netbox engine, minting scoped tokens through roles, and
  creating the NetBox service users those roles mint tokens for. Landing the
  modules and config scaffolding before any backend or role data lets each
  concrete identity be added as pure data later.

How:
- Add three modules under modules/vault_cluster/modules: netbox_secret_backend
  (mount + engine config, admin token read from KV), netbox_secret_backend_role
  (mint ephemeral scoped tokens for a filename-derived NetBox username), and
  netbox_user_management (mirror consul_acl_management: read the seeded admin
  token, drive one e-breuninger/netbox provider per backend, and synthesize the
  NetBox user + object permissions from the role map's inline permissions).
- Derive the netbox_secret_backend and netbox_secret_backend_role maps in
  config.hcl, deriving each role's name and netbox_username from its filename so
  the engine role and NetBox username match by construction.
- Wire the three module blocks and their variables through vault_cluster and the
  syd1 terragrunt inputs, reusing the sanitized backend-alias pattern the Consul
  providers use.
- Leave the backend and role maps empty: the modules stand ready and create
  nothing until backend and role config data are added.
This commit is contained in:
2026-08-09 13:00:54 +10:00
parent f1b6751257
commit e2cd80e222
15 changed files with 456 additions and 0 deletions
+12
View File
@@ -39,6 +39,12 @@ locals {
for backend_name, _ in local.config.consul_secret_backend :
backend_name => replace(backend_name, "/", "_")
}
# Same sanitized alias mapping for the NetBox providers.
netbox_backend_aliases = {
for backend_name, _ in local.config.netbox_secret_backend :
backend_name => replace(backend_name, "/", "_")
}
}
terraform {
@@ -81,10 +87,16 @@ inputs = {
gitea_secret_backend = local.config.gitea_secret_backend
gitea_secret_backend_role = local.config.gitea_secret_backend_role
netbox_secret_backend = local.config.netbox_secret_backend
netbox_secret_backend_role = local.config.netbox_secret_backend_role
# Pass policy maps to vault_cluster module
policy_auth_map = local.policies.policy_auth_map
policy_rules_map = local.policies.policy_rules_map
# Pass sanitized consul backend aliases for provider configuration
consul_backend_aliases = local.consul_backend_aliases
# Pass sanitized netbox backend aliases for provider configuration
netbox_backend_aliases = local.netbox_backend_aliases
}