Skip to main content

netbox-secrets-manager

Attach secrets to NetBox objects — BMC credentials on a device, a private certificate on a virtual machine — while keeping AWS Secrets Manager as the system of record. NetBox stores only metadata: the ARN, which object the secret belongs to, and which shape it has.

No field on any model in this plugin ever holds plaintext or ciphertext.

Why not netbox-secrets?

netbox-secrets encrypts secrets inside NetBox: a per-user RSA keypair wraps a per-install master key, which wraps a session key, which encrypts each value. Decryption is a cryptographic capability, held by whoever has the private key.

That makes one common arrangement impossible to express: an operator who may rotate a BMC password but may not read it. This plugin moves storage to AWS and makes decryption a permission instead, so view (list without revealing), decrypt (reveal), add/change (write) and delete are granted separately.

The trade-off is explicit and you should read docs/security.md before deploying: the application's IAM role holds GetSecretValue at all times, so decrypt is an application-layer control, not an IAM one.

What it does

  • Typed secrets. A SecretType carries a JSON Schema, so "BMC Credentials" (username, password) and "Private Cert" (one large certificate field) are data an admin edits, not code.
  • Four separable permissions, including a custom decrypt action with object-level constraints — scope reveal to one secret type, or one app.
  • Partial writes without reading. An operator with change but not decrypt can rotate one field; the server merges server-side and returns nothing.
  • REST and GraphQL, with plaintext reachable only through explicit, separately-permissioned endpoints.
  • Lifecycle management. The plugin names, creates and deletes the AWS secret, and nbsm_reconcile reports drift in both directions.

Requirements

  • NetBox 4.7.x
  • Python 3.12+
  • An AWS account, and credentials reachable by the default boto3 chain

Installation

pip install netbox-secrets-manager

Add to configuration.py:

PLUGINS = ['netbox_secrets_manager']

PLUGINS_CONFIG = {
    'netbox_secrets_manager': {
        'apps': ['dcim.device', 'virtualization.virtualmachine'],
        'aws_region': 'us-east-1',
        'instance_id': 'prod-netbox',
    },
}

Then run migrations and collect static files. Full options are documented in docs/configuration.md.

Development

Tasks run through just; just on its own lists everything.

just up             # NetBox + Postgres + Redis + LocalStack
just test           # the suite
just check          # lint, migration drift and tests, as CI runs them

NetBox comes up on http://localhost:8000 as admin / admin, with LocalStack standing in for AWS.

The suite runs inside the stack rather than a local virtualenv, because it is built on NetBox's own test utilities and needs NetBox's settings, database and app registry.

just test-integration additionally runs the backend contract against LocalStack. It is worth running before a release: moto is not faithful on two behaviours this plugin depends on, so those tests are the only coverage of the adopt and restore-previous paths against a real Secrets Manager implementation.

License

Apache-2.0

Metadata

Release files for netbox-secrets-manager 0.2.4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for netbox-secrets-manager 0.2.4
File Size Uploaded
netbox_secrets_manager-0.2.4.tar.gz 83.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for netbox-secrets-manager 0.2.4
File Interpreter ABI Platform
netbox_secrets_manager-0.2.4-py3-none-any.whl Python 3 none any Details

Total release size: 187.9 kB

Release files / netbox_secrets_manager-0.2.4.tar.gz

Download URL netbox_secrets_manager-0.2.4.tar.gz
Size 83.0 kB
Tags Source
SHA-256 checksum
How to use checksums
c1964b3d201db5e21274dad15c1ba47dcaf80599591dc4a8ca41f5d33ed2d020
BLAKE2b-256 checksum
How to use checksums
954630cb476cfd0dccc5bed97878fa5e9cd94048d6eb77c90305a05830b05726
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.15 {"installer":{"name":"uv","version":"0.11.15","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / netbox_secrets_manager-0.2.4-py3-none-any.whl

Download URL netbox_secrets_manager-0.2.4-py3-none-any.whl
Size 104.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
efec0153377504a5b3f608cb10750dc8c9de50c4faae59ef6ecebda66388ea63
BLAKE2b-256 checksum
How to use checksums
7b7363634d618982fad54284c1e83c9dccfab665cf190ccbeca97136e0992cf5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.15 {"installer":{"name":"uv","version":"0.11.15","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

This release

0.2.4 This release

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page