For our new network backbone the configuration of every switch is built from NetBox. Nobody logs in to a switch to change something by hand. This post describes how the pieces fit together.

The NetBox Model

We keep the model deliberately small:

  • Devices
  • Interfaces
  • VRFs
  • VLAN groups
  • VLANs

For the VXLANs we do not use L2VPN objects. A VLAN in NetBox is the L2 segment, and its VNI is derived from the object ID:

ObjectVNI formulaExample
VLAN10,000 + VLAN object IDVLAN with ID 42 → VNI 10042
VRF100,000 + VRF object IDVRF with ID 7 → VNI 100007

No extra field to maintain, no VNI spreadsheet, and the VNI can always be calculated from what is in NetBox. It’s a KISS approach, and the trade-off is that VNIs are tied to the object IDs, so objects should not be deleted and recreated casually.

Arista: Ansible and CloudVision

The Arista configuration is rendered by Ansible using plain Jinja2 templates, with no fancy framework in between. The rendered configuration is then pushed to CloudVision through its API.

SONiC: JSON and a Small Manager

For the Dell SONiC switches, the configuration is generated as JSON objects. These are handed to a small tool, the sonic-manager, which

  1. fetches the generated configuration,
  2. compares it with the current configuration on the SONiC switch,
  3. and applies it only if there are differences.

Because it only acts on a difference, running the pipeline again is harmless.

The Workflow

  1. A change is prepared in a branch using the NetBox Branching plugin.
  2. Once the change is merged, a GitLab CI/CD pipeline picks it up.
  3. The pipeline runs Ansible to generate the configurations.
  4. The results are deployed to the tools: CloudVision for Arista, the sonic-manager for SONiC.

Every change is reviewable in NetBox before it goes live, and every deployment is traceable in GitLab.

Why This Way

  • One source of truth: If it isn’t in NetBox, it isn’t on the switch.
  • Boring technology: Jinja2 and JSON are easy to read and debug.
  • Repeatable: Adding a leaf or a VLAN means changing the model, not editing configs.