Skip to main content

netbox-secrets-manager

Attach secrets to NetBox objects — BMC credentials on a device, a private certificate on a virtual machine — while keeping AWS Secrets Manager as the system of record. NetBox stores only metadata: the ARN, which object the secret belongs to, and which shape it has.

No field on any model in this plugin ever holds plaintext or ciphertext.

Why not netbox-secrets?

netbox-secrets encrypts secrets inside NetBox: a per-user RSA keypair wraps a per-install master key, which wraps a session key, which encrypts each value. Decryption is a cryptographic capability, held by whoever has the private key.

That makes one common arrangement impossible to express: an operator who may rotate a BMC password but may not read it. This plugin moves storage to AWS and makes decryption a permission instead, so view (list without revealing), decrypt (reveal), add/change (write) and delete are granted separately.

The trade-off is explicit and you should read docs/security.md before deploying: the application's IAM role holds GetSecretValue at all times, so decrypt is an application-layer control, not an IAM one.

What it does

  • Typed secrets. A SecretType carries a JSON Schema, so "BMC Credentials" (username, password) and "Private Cert" (one large certificate field) are data an admin edits, not code.
  • Four separable permissions, including a custom decrypt action with object-level constraints — scope reveal to one secret type, or one app.
  • Partial writes without reading. An operator with change but not decrypt can rotate one field; the server merges server-side and returns nothing.
  • REST and GraphQL, with plaintext reachable only through explicit, separately-permissioned endpoints.
  • Lifecycle management. The plugin names, creates and deletes the AWS secret, and nbsm_reconcile reports drift in both directions.

Requirements

  • NetBox 4.7.x
  • Python 3.12+
  • An AWS account, and credentials reachable by the default boto3 chain

Installation

pip install netbox-secrets-manager

Add to configuration.py:

PLUGINS = ['netbox_secrets_manager']

PLUGINS_CONFIG = {
    'netbox_secrets_manager': {
        'apps': ['dcim.device', 'virtualization.virtualmachine'],
        'aws_region': 'us-east-1',
        'instance_id': 'prod-netbox',
    },
}

Then run migrations and collect static files. Full options are documented in docs/configuration.md.

Development

Tasks run through just; just on its own lists everything.

just up             # NetBox + Postgres + Redis + LocalStack
just test           # the suite
just check          # lint, migration drift and tests, as CI runs them

NetBox comes up on http://localhost:8000 as admin / admin, with LocalStack standing in for AWS.

The suite runs inside the stack rather than a local virtualenv, because it is built on NetBox's own test utilities and needs NetBox's settings, database and app registry.

just test-integration additionally runs the backend contract against LocalStack. It is worth running before a release: moto is not faithful on two behaviours this plugin depends on, so those tests are the only coverage of the adopt and restore-previous paths against a real Secrets Manager implementation.

License

Apache-2.0

Metadata

Release files for netbox-secrets-manager 0.2.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for netbox-secrets-manager 0.2.2
File Size Uploaded
netbox_secrets_manager-0.2.2.tar.gz 82.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for netbox-secrets-manager 0.2.2
File Interpreter ABI Platform
netbox_secrets_manager-0.2.2-py3-none-any.whl Python 3 none any Details

Total release size: 186.8 kB

Release files / netbox_secrets_manager-0.2.2.tar.gz

Download URL netbox_secrets_manager-0.2.2.tar.gz
Size 82.5 kB
Tags Source
SHA-256 checksum
How to use checksums
eea4377f63924f4a8a9c3262794275bd269faa087a7e3c64174c1276ff0d980b
BLAKE2b-256 checksum
How to use checksums
8da8fdfe180edd28e8dddd754fbb32c0b38b7e39a9a3bdf050d94a2a52d24827
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.15 {"installer":{"name":"uv","version":"0.11.15","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / netbox_secrets_manager-0.2.2-py3-none-any.whl

Download URL netbox_secrets_manager-0.2.2-py3-none-any.whl
Size 104.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7a330702895f5e7fbf1a484d7d26bf47b51b69d91e86bb50278c4cb89c1d627e
BLAKE2b-256 checksum
How to use checksums
80a1429bdcecc93dd91d01f9747df5ad4bd62c9ebde9ca34f6fb682685aa3831
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.15 {"installer":{"name":"uv","version":"0.11.15","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

0.2.4

2 release files

0.2.3

2 release files

This release

0.2.2 This release

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page