Files
terraform-vault/config
unkinben df3e8b017c
ci/woodpecker/pr/plan Pipeline failed
ci/woodpecker/pr/pre-commit Pipeline was successful
Add the netbox backend and terraform-infra role
Why:
- The netbox engine modules stand ready but mount nothing and create no
  identity until backend and role data exist, so terraform-infra still reads a
  static NetBox token instead of minting ephemeral scoped tokens.

How:
- Add config/netbox_secret_backend/netbox.yaml to mount the engine at netbox and
  point it at the syd1 NetBox URL; the admin token is read from KV, not stored
  here.
- Add config/netbox_secret_backend_role/netbox/terraform-infra.yaml as the
  single declarative source for the terraform-infra identity: filename-derived
  role name and NetBox username, write access, short TTLs, and an inline
  permissions block. Nothing in the file repeats the filename.
- Scope terraform-infra to view/add/change/delete on the IPAM/DCIM objects it
  manages: prefixes, ip-addresses, ip-ranges, devices, interfaces, mac
  addresses.
- Add policies/netbox/creds/terraform-infra.yaml letting the terraform-infra
  AppRole and its Woodpecker k8s role read netbox/creds/terraform-infra; it
  attaches to nothing until the separate terraform-infra Vault onboarding lands.
2026-08-09 13:01:41 +10:00
..