0
[ ~/netbox-openbao/releases/v0.2.0 ]tty0

emerson@netdevops:~/netbox-openbao$ gh release view v0.2.0 --repo emersonfelipesp/netbox-openbao

back to releases / back to project

v0.2.0

[open on GitHub]
tag=v0.2.0state=latestpublished=2026-10-02synced=2026-10-02 21:49 UTC
author
emersonfelipesp
created
2026-10-02 20:49 UTC
target
main
downloads
0

emerson@netdevops:~/netbox-openbao$ cat RELEASE_NOTES.md

  • Upgrade action required. OpenBao login material (AppRole role and secret
    IDs, token, Kubernetes role, broker client certificate) and every plugin
    setting now live in encrypted NetBox models instead of PLUGINS_CONFIG and
    NETBOX_BAO_* environment variables. Runtime code no longer reads those
    sources; only the one-time openbao_configure import-legacy-settings and
    import-env commands do. Follow docs/upgrading.md in a maintenance window
    before relying on the upgraded plugin; until authentication material is
    stored, OpenBao access fails. Also added: a Settings page and API, and the
    openbao_configure management command for headless setup, connection tests
    and re-encryption after a SECRET_KEY rotation.
  • One consolidated migration, 0024_engine_auth_material, covers everything
    added since 0.1.0.post2: the service endpoint and credential schema models
    with their seed, the unique credential import source constraint, the
    idempotent SSH service template seed, each policy's former environment
    prefix retained as non-executable metadata, and the encrypted authentication
    material model. Databases that already recorded that name skip it.
  • Service endpoints and an SSH public-key inventory, a permission-constrained
    metadata-only credential resolver, an atomic endpoint-with-credential write
    and a revision-bound endpoint reveal. Provider-specific imports remain the
    responsibility of consuming plugins.
  • SSH credentials (ssh-keypair, ssh-password) must now be tied to an SSH
    Application Service: the chain is OpenBao Credential > Application Service
    (ipam.Service) > Device or Virtual Machine. Assigning an SSH credential
    directly to a Device or VM is rejected (other targets such as hypervisor
    endpoints are unaffected).
  • Added a seeded SSH service template (tcp/22). Quick-add now builds the
    Application Service from a chosen service template and creates the
    credential on the same form; the optional "create service" checkbox is gone
    and the REST quick-add accepts service_template and service_name instead
    of create_service.
  • NetBox 4.7 is now required; the 4.6 protocol + ports service path was
    removed. Existing direct Device/VM assignments of SSH credentials are not
    rewritten and stay editable; the Application Service rule applies to new
    assignments.

emerson@netdevops:~/netbox-openbao$ gh release download --pattern '*'

assets

no binary assets attached

source code