# netbox-openbao v0.2.0 v0.2.0 | Field |Value | | --- | --- | | Canonical URL | https://emersonfelipesp.com/netbox-openbao/releases/v0.2.0 | | GitHub URL | https://github.com/emersonfelipesp/netbox-openbao/releases/tag/v0.2.0 | | Tag | v0.2.0 | | State | latest | | Author | emersonfelipesp | | Created | 2026-10-02 20:49 UTC | | Published | 2026-10-02 20:51 UTC | | Target | main | | Synced | 2026-10-02 21:49 UTC | | Assets | 0 | ## Release notes - **Upgrade action required.** OpenBao login material (AppRole role and secret IDs, token, Kubernetes role, broker client certificate) and every plugin setting now live in encrypted NetBox models instead of `PLUGINS_CONFIG` and `NETBOX_BAO_*` environment variables. Runtime code no longer reads those sources; only the one-time `openbao_configure import-legacy-settings` and `import-env` commands do. Follow `docs/upgrading.md` in a maintenance window before relying on the upgraded plugin; until authentication material is stored, OpenBao access fails. Also added: a Settings page and API, and the `openbao_configure` management command for headless setup, connection tests and re-encryption after a `SECRET_KEY` rotation. - One consolidated migration, `0024_engine_auth_material`, covers everything added since 0.1.0.post2: the service endpoint and credential schema models with their seed, the unique credential import source constraint, the idempotent `SSH` service template seed, each policy's former environment prefix retained as non-executable metadata, and the encrypted authentication material model. Databases that already recorded that name skip it. - Service endpoints and an SSH public-key inventory, a permission-constrained metadata-only credential resolver, an atomic endpoint-with-credential write and a revision-bound endpoint reveal. Provider-specific imports remain the responsibility of consuming plugins. - SSH credentials (`ssh-keypair`, `ssh-password`) must now be tied to an SSH Application Service: the chain is OpenBao Credential > Application Service (`ipam.Service`) > Device or Virtual Machine. Assigning an SSH credential directly to a Device or VM is rejected (other targets such as hypervisor endpoints are unaffected). - Added a seeded `SSH` service template (`tcp/22`). Quick-add now builds the Application Service from a chosen service template and creates the credential on the same form; the optional "create service" checkbox is gone and the REST quick-add accepts `service_template` and `service_name` instead of `create_service`. - NetBox 4.7 is now required; the 4.6 `protocol` + `ports` service path was removed. Existing direct Device/VM assignments of SSH credentials are not rewritten and stay editable; the Application Service rule applies to new assignments. ## Assets No binary assets attached. Source archives: | Format |URL | | --- | --- | | zip | https://api.github.com/repos/emersonfelipesp/netbox-openbao/zipball/v0.2.0 | | tar.gz | https://api.github.com/repos/emersonfelipesp/netbox-openbao/tarball/v0.2.0 |