Skip to main content
netbox change control

Policy-driven change control and mandatory review for NetBox branches

change requests • policies • checks • comments

License NetBox compatibility netbox-branching compatibility Python version

Documentation | Install | Compatibility | Policies | Checks | Changelog

This plugin builds on netbox-branching. A branch stages your changes; this plugin decides who must approve them and refuses the merge until they have.

The goal is change control that is policy driven: who must approve a change is decided by the objects it touches, not by whoever opened it. Around that sit two extension points, so the same gate can be driven by more than people. Pre-merge checks are pluggable, and an event fires on every status change, so a change request can call an external system, wait for a CI result, or ask a model to review the diff before anyone merges it. See writing your own checks, which includes an AI reviewer and a CI reporter.

It takes ideas from NetBox Labs change management, for policies and rules governing who must review a branch; from GitHub, for status checks that gate a merge independently of human approval and for review comments anchored to a specific change; and from Infrahub by OpsMill, for treating a proposed change as a first-class object that carries its own validation.

How it works | Documentation | Features | Requirements | Quick install

A change request, showing the approval status, the pre-merge checks and the conflict banner

How it works

  1. Someone creates a branch and makes their changes inside it, as normal for netbox-branching.
  2. They open a change request against that branch.
  3. The plugin reads which object types the branch touches and attaches every policy whose scope matches. A policy can narrow further on the values of the objects themselves. The author cannot remove them.
  4. Each policy contains rules. A rule says how many approvals it needs and who may give them.
  5. Reviewers approve, request changes, or comment. They can also comment on one specific changed object.
  6. Independently, the pre-merge checks named by those policies run. A required check that is not passing blocks the merge on its own.
  7. Once every rule is satisfied and every required check passes, the merge button appears.
  8. After the merge, the request is marked completed.

Two gates guard the merge and they are independent: the people gate (policies and reviews) and the machine gate (checks). A change can be approved by every reviewer and still be refused by a check.

Documentation

The documentation is a website: antoinekh.github.io/netbox-change-control. Its sources are the Markdown files in docs/, built with Zensical and published by GitHub Actions on every push to master.

Page Covers
Installation and configuration Requirements, installing, and every setting.
Compatibility matrix Which release runs on which NetBox and which netbox-branching.
Policies and rules Scoping a policy and writing rules.
Policy conditions Narrowing a policy on object values.
Conflicts with main What counts as a real conflict, and how to resolve one.
Change requests The lifecycle, and what survives a branch deletion.
Reviews Submitting reviews and commenting on individual changes.
Pre-merge checks What checks are and which ship built in.
Writing your own checks The registry, an AI reviewer, and reporting from CI.
Event rules Firing a webhook or a script on a change request.
Merging, windows and auto-merge Change windows and automatic merging.
Protecting main Requiring a branch, optionally for part of NetBox only.
Automatic behaviours Stale reviews, reevaluation, notifications.
Administration guide Roles, the permission matrix, building policies, troubleshooting.
Permissions The short reference for every permission name.
REST API Every endpoint.
Extending this plugin How another plugin adds content and checks.
Design Why it is built this way.

To read the site on your own machine, install Zensical and run zensical serve at the root of a checkout.

Features

Feature Status
Policies containing rules with a minimum approval count Done
Rules naming reviewer groups and individual reviewers Done
Policies attached automatically, scope-matched from the branch contents, following it as it changes, and not selectable by the author Done
Policy conditions, narrowing a policy on the values of the changed objects Done
Change requests with status and priority Done
Reviews with approve, request changes, and comment Done
Per-change comments on the branch diff, with threaded replies, in Markdown Done
Merge button appears once approved Done, on the change request and on the branch
Status set to completed after a successful merge Done
Pre-merge gate, enforced regardless of protect_main Done
protect_main blocks direct edits outside a branch, optionally scoped Done, with a bypass permission
Stale review detection when the branch changes Done
Approval invalidation when the branch changes after approval Done
Policy reevaluation on rule, reviewer or group membership change Done
Notifications to reviewers Done, through NetBox's notification inbox
Pluggable pre-merge checks, in-process or reported over the REST API Done
Change windows, with an override permission Done
Automatic merge once every gate is satisfied Done
Change request survives deletion of its branch Done
REST API for every model Done

Requirements

Component Version
NetBox >= 4.7.0, < 4.8
netbox-branching >= 1.2.2, < 1.3
Python >= 3.12

This is the NetBox 4.7 line. For NetBox 4.6, stay on the 0.4.x line; the two do not overlap, because netbox-branching 1.1.x and 1.2 do not either. The compatibility matrix has every release, and Installation covers moving between the two lines.

Quick install

# configuration/plugins.py
PLUGINS = [
    'netbox_change_control',
    'netbox_branching',          # must stay last
]

PLUGINS_CONFIG = {
    'netbox_branching': {
        'exempt_models': ['netbox_change_control.*'],   # required
    },
}
./manage.py migrate netbox_change_control

See Installation and configuration for the detail, including why exempt_models is not optional.

Metadata

Release files for netbox-change-control 0.6.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for netbox-change-control 0.6.0
File Size Uploaded
netbox_change_control-0.6.0.tar.gz 159.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for netbox-change-control 0.6.0
File Interpreter ABI Platform
netbox_change_control-0.6.0-py3-none-any.whl Python 3 none any Details

Total release size: 371.2 kB

Release files / netbox_change_control-0.6.0.tar.gz

Download URL netbox_change_control-0.6.0.tar.gz
Size 159.3 kB
Tags Source
SHA-256 checksum
How to use checksums
7e7171031a0ac9dce1006ccb5ad773c788a596d2b871322e3c107c07378834d0
BLAKE2b-256 checksum
How to use checksums
73b5bf1f738d862e5f4672c2bdbf749f80cf70a1f3d7bd51447bbe3f88ba60ef
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.

Transparency log

Release files / netbox_change_control-0.6.0-py3-none-any.whl

Download URL netbox_change_control-0.6.0-py3-none-any.whl
Size 211.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6e2f784a48c7a73e1fceed0fca867fd520f0957c505bd69fc7e6cb4a500f3b7d
BLAKE2b-256 checksum
How to use checksums
76b5f13efee8955aa5005e588e6732805d72e9b27bd03f6c6b6346e376774fc2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.6.0 This release

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page