For our new network backbone the configuration of every switch is built from NetBox. Nobody logs in to a switch to change something by hand. This post describes how the pieces fit together.
The NetBox Model
We keep the model deliberately small:
- Devices
- Interfaces
- VRFs
- VLAN groups
- VLANs
For the VXLANs we do not use L2VPN objects. A VLAN in NetBox is the L2 segment, and its VNI is derived from the object ID:
| Object | VNI formula | Example |
|---|---|---|
| VLAN | 10,000 + VLAN object ID | VLAN with ID 42 → VNI 10042 |
| VRF | 100,000 + VRF object ID | VRF with ID 7 → VNI 100007 |
No extra field to maintain, no VNI spreadsheet, and the VNI can always be calculated from what is in NetBox. It’s a KISS approach, and the trade-off is that VNIs are tied to the object IDs, so objects should not be deleted and recreated casually.
Arista: Ansible and CloudVision
The Arista configuration is rendered by Ansible using plain Jinja2 templates, with no fancy framework in between. The rendered configuration is then pushed to CloudVision through its API.
SONiC: JSON and a Small Manager
For the Dell SONiC switches, the configuration is generated as JSON objects. These are handed to a small tool, the sonic-manager, which
- fetches the generated configuration,
- compares it with the current configuration on the SONiC switch,
- and applies it only if there are differences.
Because it only acts on a difference, running the pipeline again is harmless.
The Workflow
- A change is prepared in a branch using the NetBox Branching plugin.
- Once the change is merged, a GitLab CI/CD pipeline picks it up.
- The pipeline runs Ansible to generate the configurations.
- The results are deployed to the tools: CloudVision for Arista, the sonic-manager for SONiC.
Every change is reviewable in NetBox before it goes live, and every deployment is traceable in GitLab.
Why This Way
- One source of truth: If it isn’t in NetBox, it isn’t on the switch.
- Boring technology: Jinja2 and JSON are easy to read and debug.
- Repeatable: Adding a leaf or a VLAN means changing the model, not editing configs.