netbox-secrets-manager
Attach secrets to NetBox objects — BMC credentials on a device, a private certificate on a virtual machine — while keeping AWS Secrets Manager as the system of record. NetBox stores only metadata: the ARN, which object the secret belongs to, and which shape it has.
No field on any model in this plugin ever holds plaintext or ciphertext.
Why not netbox-secrets?
netbox-secrets encrypts secrets inside NetBox: a per-user RSA keypair wraps a per-install master key, which wraps a session key, which encrypts each value. Decryption is a cryptographic capability, held by whoever has the private key.
That makes one common arrangement impossible to express: an operator who may
rotate a BMC password but may not read it. This plugin moves storage to AWS and
makes decryption a permission instead, so view (list without revealing),
decrypt (reveal), add/change (write) and delete are granted separately.
The trade-off is explicit and you should read
docs/security.md before deploying: the application's IAM
role holds GetSecretValue at all times, so decrypt is an application-layer
control, not an IAM one.
What it does
- Typed secrets. A
SecretTypecarries a JSON Schema, so "BMC Credentials" (username,password) and "Private Cert" (one largecertificatefield) are data an admin edits, not code. - Four separable permissions, including a custom
decryptaction with object-level constraints — scope reveal to one secret type, or one app. - Partial writes without reading. An operator with
changebut notdecryptcan rotate one field; the server merges server-side and returns nothing. - REST and GraphQL, with plaintext reachable only through explicit, separately-permissioned endpoints.
- Lifecycle management. The plugin names, creates and deletes the AWS
secret, and
nbsm_reconcilereports drift in both directions.
Requirements
- NetBox 4.7.x
- Python 3.12+
- An AWS account, and credentials reachable by the default boto3 chain
Installation
pip install netbox-secrets-manager
Add to configuration.py:
PLUGINS = ['netbox_secrets_manager']
PLUGINS_CONFIG = {
'netbox_secrets_manager': {
'apps': ['dcim.device', 'virtualization.virtualmachine'],
'aws_region': 'us-east-1',
'instance_id': 'prod-netbox',
},
}
Then run migrations and collect static files. Full options are documented in docs/configuration.md.
Development
Tasks run through just; just on its own lists
everything.
just up # NetBox + Postgres + Redis + LocalStack
just test # the suite
just check # lint, migration drift and tests, as CI runs them
NetBox comes up on http://localhost:8000 as admin / admin, with LocalStack
standing in for AWS.
The suite runs inside the stack rather than a local virtualenv, because it is built on NetBox's own test utilities and needs NetBox's settings, database and app registry.
just test-integration additionally runs the backend contract against
LocalStack. It is worth running before a release: moto is not faithful on two
behaviours this plugin depends on, so those tests are the only coverage of the
adopt and restore-previous paths against a real Secrets Manager implementation.
License
Apache-2.0
Metadata
Release files for netbox-secrets-manager 0.2.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| netbox_secrets_manager-0.2.1.tar.gz | 81.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| netbox_secrets_manager-0.2.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 183.3 kB
Release files / netbox_secrets_manager-0.2.1.tar.gz
| Download URL | netbox_secrets_manager-0.2.1.tar.gz |
|---|---|
| Size | 81.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
9be99533ffd83a0a7bd53950ee417e8c043d9e1bdc988e22f59a318fc8aa861f
|
|
BLAKE2b-256 checksum How to use checksums |
1acf49d14a63f17d8de63bd23bc5e0daa5a2bad450b02bc6b7fc5e5ddd06aa42
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.15 {"installer":{"name":"uv","version":"0.11.15","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / netbox_secrets_manager-0.2.1-py3-none-any.whl
| Download URL | netbox_secrets_manager-0.2.1-py3-none-any.whl |
|---|---|
| Size | 102.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8a12fc4af3ef962d477590fd8a5d05daff47e465dc8ee0356e832cc4f9b89b20
|
|
BLAKE2b-256 checksum How to use checksums |
9a3e1214aa466a30a97fa93b28df9f3e7d15de39e1ced86a7cdb626b29aa3cb2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.15 {"installer":{"name":"uv","version":"0.11.15","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|