df3e8b017c
Why: - The netbox engine modules stand ready but mount nothing and create no identity until backend and role data exist, so terraform-infra still reads a static NetBox token instead of minting ephemeral scoped tokens. How: - Add config/netbox_secret_backend/netbox.yaml to mount the engine at netbox and point it at the syd1 NetBox URL; the admin token is read from KV, not stored here. - Add config/netbox_secret_backend_role/netbox/terraform-infra.yaml as the single declarative source for the terraform-infra identity: filename-derived role name and NetBox username, write access, short TTLs, and an inline permissions block. Nothing in the file repeats the filename. - Scope terraform-infra to view/add/change/delete on the IPAM/DCIM objects it manages: prefixes, ip-addresses, ip-ranges, devices, interfaces, mac addresses. - Add policies/netbox/creds/terraform-infra.yaml letting the terraform-infra AppRole and its Woodpecker k8s role read netbox/creds/terraform-infra; it attaches to nothing until the separate terraform-infra Vault onboarding lands.