0
[ ~/netbox-openbao/releases/v0.2.1 ]tty0

emerson@netdevops:~/netbox-openbao$ gh release view v0.2.1 --repo emersonfelipesp/netbox-openbao

back to releases / back to project

v0.2.1

[open on GitHub]
tag=v0.2.1state=latestpublished=2026-10-03synced=2026-10-03 15:43 UTC
author
emersonfelipesp
created
2026-10-03 14:44 UTC
target
main
downloads
0

emerson@netdevops:~/netbox-openbao$ cat RELEASE_NOTES.md

netbox-openbao 0.2.1

Connections now use NetBox's built-in Application Service instead of a plugin-specific endpoint model.

Changes

  • ServiceEndpoint is removed, with its REST routes, UI pages, menu entry and the with-credential action.
  • A credential connects through the Application Service it is assigned to. The service must list exactly one IP address and exactly one TCP port; otherwise resolution fails closed with a clear error.
  • The SSH host-key pin (ssh_known_hosts_entry, ssh_strict_host_key_checking) now lives on the credential assignment. SSH public keys reference the Application Service.
  • New POST assignments/{id}/reveal-credential/ reveals a credential only while the assignment still matches the approved revision, host and port, and re-checks authorization before and after the backend read.
  • GET resolve/ returns services with their host, port and error, plus assignments.
  • Quick-add accepts an IP address for the new SSH service; only addresses the caller can view are accepted.
  • The NMS credential importer commands are removed.

Upgrade notes

Migration 0025_application_service_connection carries host-key pins and SSH keys over to services, creates the login assignment for an endpoint that bound a credential without one, skips endpoints of deleted services, and stops with row-level diagnostics if keys or host-key settings conflict. Reversing it clears the SSH key inventory.

Clients of the removed endpoint routes must move to the Application Service resolver and the assignment reveal action. Fill in the IP address on every SSH Application Service.

emerson@netdevops:~/netbox-openbao$ gh release download --pattern '*'

assets

no binary assets attached

source code