Skip to main content

netbox-secrets-manager

Attach secrets to NetBox objects — BMC credentials on a device, a private certificate on a virtual machine — while keeping AWS Secrets Manager as the system of record. NetBox stores only metadata: the ARN, which object the secret belongs to, and which shape it has.

No field on any model in this plugin ever holds plaintext or ciphertext.

Why not netbox-secrets?

netbox-secrets encrypts secrets inside NetBox: a per-user RSA keypair wraps a per-install master key, which wraps a session key, which encrypts each value. Decryption is a cryptographic capability, held by whoever has the private key.

That makes one common arrangement impossible to express: an operator who may rotate a BMC password but may not read it. This plugin moves storage to AWS and makes decryption a permission instead, so view (list without revealing), decrypt (reveal), add/change (write) and delete are granted separately.

The trade-off is explicit and you should read docs/security.md before deploying: the application's IAM role holds GetSecretValue at all times, so decrypt is an application-layer control, not an IAM one.

What it does

  • Typed secrets. A SecretType carries a JSON Schema, so "BMC Credentials" (username, password) and "Private Cert" (one large certificate field) are data an admin edits, not code.
  • Four separable permissions, including a custom decrypt action with object-level constraints — scope reveal to one secret type, or one app.
  • Partial writes without reading. An operator with change but not decrypt can rotate one field; the server merges server-side and returns nothing.
  • REST and GraphQL, with plaintext reachable only through explicit, separately-permissioned endpoints.
  • Lifecycle management. The plugin names, creates and deletes the AWS secret, and nbsm_reconcile reports drift in both directions.

Requirements

  • NetBox 4.7.x
  • Python 3.12+
  • An AWS account, and credentials reachable by the default boto3 chain

Installation

pip install netbox-secrets-manager

Add to configuration.py:

PLUGINS = ['netbox_secrets_manager']

PLUGINS_CONFIG = {
    'netbox_secrets_manager': {
        'apps': ['dcim.device', 'virtualization.virtualmachine'],
        'aws_region': 'us-east-1',
        'instance_id': 'prod-netbox',
    },
}

Then run migrations and collect static files. Full options are documented in docs/configuration.md.

Development

Tasks run through just; just on its own lists everything.

just up             # NetBox + Postgres + Redis + LocalStack
just test           # the suite
just check          # lint, migration drift and tests, as CI runs them

NetBox comes up on http://localhost:8000 as admin / admin, with LocalStack standing in for AWS.

The suite runs inside the stack rather than a local virtualenv, because it is built on NetBox's own test utilities and needs NetBox's settings, database and app registry.

just test-integration additionally runs the backend contract against LocalStack. It is worth running before a release: moto is not faithful on two behaviours this plugin depends on, so those tests are the only coverage of the adopt and restore-previous paths against a real Secrets Manager implementation.

License

Apache-2.0

Metadata

Release files for netbox-secrets-manager 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for netbox-secrets-manager 0.2.0
File Size Uploaded
netbox_secrets_manager-0.2.0.tar.gz 80.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for netbox-secrets-manager 0.2.0
File Interpreter ABI Platform
netbox_secrets_manager-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 182.3 kB

Release files / netbox_secrets_manager-0.2.0.tar.gz

Download URL netbox_secrets_manager-0.2.0.tar.gz
Size 80.5 kB
Tags Source
SHA-256 checksum
How to use checksums
5b7fe9760f47fe6c3b347ddf3eaa70467136f2df49bffee66b3f7cc7a0f1d613
BLAKE2b-256 checksum
How to use checksums
fe726ae31e7a20d2450742c5f9a88f0d101187e0fc31a576f31841620c3f6ea5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.15 {"installer":{"name":"uv","version":"0.11.15","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / netbox_secrets_manager-0.2.0-py3-none-any.whl

Download URL netbox_secrets_manager-0.2.0-py3-none-any.whl
Size 101.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
569cdd85f4960b2aa1f0b66a361c43fae9307153632adfea421cfa5b2be4bca3
BLAKE2b-256 checksum
How to use checksums
cffa70d2502fb488dbd67f7f0cd382103c4ae5eb40f20b1f0c069c8b8812d584
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.15 {"installer":{"name":"uv","version":"0.11.15","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

0.2.4

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

This release

0.2.0 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page