Skip to main content

netbox-secrets-manager

Attach secrets to NetBox objects — BMC credentials on a device, a private certificate on a virtual machine — while keeping AWS Secrets Manager as the system of record. NetBox stores only metadata: the ARN, which object the secret belongs to, and which shape it has.

No field on any model in this plugin ever holds plaintext or ciphertext.

Why not netbox-secrets?

netbox-secrets encrypts secrets inside NetBox: a per-user RSA keypair wraps a per-install master key, which wraps a session key, which encrypts each value. Decryption is a cryptographic capability, held by whoever has the private key.

That makes one common arrangement impossible to express: an operator who may rotate a BMC password but may not read it. This plugin moves storage to AWS and makes decryption a permission instead, so view (list without revealing), decrypt (reveal), add/change (write) and delete are granted separately.

The trade-off is explicit and you should read docs/security.md before deploying: the application's IAM role holds GetSecretValue at all times, so decrypt is an application-layer control, not an IAM one.

What it does

  • Typed secrets. A SecretType carries a JSON Schema, so "BMC Credentials" (username, password) and "Private Cert" (one large certificate field) are data an admin edits, not code.
  • Four separable permissions, including a custom decrypt action with object-level constraints — scope reveal to one secret type, or one app.
  • Partial writes without reading. An operator with change but not decrypt can rotate one field; the server merges server-side and returns nothing.
  • REST and GraphQL, with plaintext reachable only through explicit, separately-permissioned endpoints.
  • Lifecycle management. The plugin names, creates and deletes the AWS secret, and nbsm_reconcile reports drift in both directions.

Requirements

  • NetBox 4.7.x
  • Python 3.12+
  • An AWS account, and credentials reachable by the default boto3 chain

Installation

pip install netbox-secrets-manager

Add to configuration.py:

PLUGINS = ['netbox_secrets_manager']

PLUGINS_CONFIG = {
    'netbox_secrets_manager': {
        'apps': ['dcim.device', 'virtualization.virtualmachine'],
        'aws_region': 'us-east-1',
        'instance_id': 'prod-netbox',
    },
}

Then run migrations and collect static files. Full options are documented in docs/configuration.md.

Development

Tasks run through just; just on its own lists everything.

just up             # NetBox + Postgres + Redis + LocalStack
just test           # the suite
just check          # lint, migration drift and tests, as CI runs them

NetBox comes up on http://localhost:8000 as admin / admin, with LocalStack standing in for AWS.

The suite runs inside the stack rather than a local virtualenv, because it is built on NetBox's own test utilities and needs NetBox's settings, database and app registry.

just test-integration additionally runs the backend contract against LocalStack. It is worth running before a release: moto is not faithful on two behaviours this plugin depends on, so those tests are the only coverage of the adopt and restore-previous paths against a real Secrets Manager implementation.

License

Apache-2.0

Metadata

Release files for netbox-secrets-manager 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for netbox-secrets-manager 0.2.1
File Size Uploaded
netbox_secrets_manager-0.2.1.tar.gz 81.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for netbox-secrets-manager 0.2.1
File Interpreter ABI Platform
netbox_secrets_manager-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 183.3 kB

Release files / netbox_secrets_manager-0.2.1.tar.gz

Download URL netbox_secrets_manager-0.2.1.tar.gz
Size 81.0 kB
Tags Source
SHA-256 checksum
How to use checksums
9be99533ffd83a0a7bd53950ee417e8c043d9e1bdc988e22f59a318fc8aa861f
BLAKE2b-256 checksum
How to use checksums
1acf49d14a63f17d8de63bd23bc5e0daa5a2bad450b02bc6b7fc5e5ddd06aa42
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.15 {"installer":{"name":"uv","version":"0.11.15","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / netbox_secrets_manager-0.2.1-py3-none-any.whl

Download URL netbox_secrets_manager-0.2.1-py3-none-any.whl
Size 102.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8a12fc4af3ef962d477590fd8a5d05daff47e465dc8ee0356e832cc4f9b89b20
BLAKE2b-256 checksum
How to use checksums
9a3e1214aa466a30a97fa93b28df9f3e7d15de39e1ced86a7cdb626b29aa3cb2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.15 {"installer":{"name":"uv","version":"0.11.15","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

0.2.4

2 release files

0.2.3

2 release files

0.2.2

2 release files

This release

0.2.1 This release

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page