702dc6c62f
Why: - The NetBox service identity was split across two files (config/netbox_user and config/netbox_secret_backend_role) that repeated the username three times: the filename, a netbox_username field, and the permission name. - Creating the engine role and creating its NetBox user are one act, so one file should describe the whole identity. How: - Make config/netbox_secret_backend_role/netbox/<name>.yaml the single source per identity: filename = engine role name = NetBox username, body = write access, TTLs, and an inline permissions block. - Derive netbox_username from the filename in config.hcl (keep netbox_user_id as an optional override), and drop the netbox_username field from the role yaml. - Iterate that same role map in the netbox_user_management module, keyed by config path, to synthesize the NetBox user and object permissions; default a single permission's name to the role name so nothing repeats the filename. - Delete the config/netbox_user tree and its netbox_user variable/wiring. - Scope terraform-infra to view/add/change/delete on the IPAM/DCIM objects it manages: prefixes, ip-addresses, ip-ranges, devices, interfaces, mac addresses.