Repository navigation
Releases: Infoblox-PS/ibcli
Releases · Infoblox-PS/ibcli
Release list
v1.0.1
First public release.
ibcli is an async Python CLI for Infoblox NIOS. It speaks the WAPI through ibx-nios-sdk and covers DNS, IPAM,
DHCP, grid administration, DTC, certificates, bulk data and service control from one prompt. Python 3.11 or
newer; ibx-nios-sdk 1.0.0 or newer installs with it.
Interface
- REPL with an abbreviation engine: any unambiguous prefix of a keyword is accepted at every position, so
co n a 192.0.2.0/24isconfigure network add 192.0.2.0/24. Line continuation, persistent history in
~/.ibcli_history, and standard key bindings. - Dynamic tab completion that resolves live NIOS object names on first Tab - grid members, views, zones,
networks, NS groups, named ACLs, failover groups, DTC servers, pools, LBDNs and per-protocol monitors.
configure serverprimes the member cache at connect time so the first Tab is immediate. Roughly 350 waypoints
carry dropdown help so every level of the tree describes itself. - Batch mode for command files,
-efor a single command, and.ibcli.cfauto-loaded at startup. -i/--idempotentdemotes genuine "already exists" conflicts toSkipped:so batch scripts re-run
cleanly, while a real HTTP 409 still counts as a failure.- A uniform
OK:line confirms mutating commands that produce no output of their own; read-only commands stay
silent. -dtracing at three levels: dispatch, httpx request logging, and the SDK's own DEBUG records. At-d 3an
unexpected exception is re-raised with its traceback; lower levels trace only and never turn a handler bug into a
dead REPL.--timeout <seconds>(default 30) raises the per-request WAPI timeout, which grid-wide aggregations on a
populated grid can exceed.-k/--insecurefor the self-signed certificates most grids present, and--wapi-versionto pin the
negotiated version.
DNS
- CRUD for
zone_auth,zone_forward,zone_delegatedandzone_stub, and for A, AAAA, CNAME, MX, PTR, TXT and
HOST records. - DNSSEC operations:
configure zone <zone> dnssec sign|unsign|rollover_ksk|rollover_zsk. - Zone copy clones records between zones, with
view=andsource_view=support. - Host rename preserves addresses, aliases, extensible attributes and comment.
- Incremental host modify with
add-alias/remove-alias,add-ip/remove-ip,add-ipv6/
remove-ipv6,comment=anddisable=, read-only fields stripped on the way through. - AXFR import via
configure zone add <zone> import_from=<ip>, with optional host abstraction and PTR
creation. - Response policy zones and RPZ records.
IPAM and DHCP
- IPv4 and IPv6 networks and network containers, shared networks, templates, split, move, and IPAM
next_availableallocation. - Ranges including in-place
range modify, which makes afailover=swap a single command rather than a delete,
move and add sequence. - Fixed addresses, MAC filters, failover associations, option spaces, and lease inspection.
- Relay agent filters across the full WAPI field set - circuit ID and remote ID names, substring matching, offsets
and lengths. - Network extensible attributes with
extattrs set|delete, merging with what is already there and accepting
quoted names. show addressandshow address ipv6surface the aggregator'stypesandusagefields.
Grid
- Member provisioning and pre-provisioning, including HA pairs,
master_candidate=, dual-stack
(ipv6addr=setsconfig_addr_typeautomatically), MGMT and LAN2 interfaces, 802.1Q VLAN tagging, port
redundancy and default-route failover. Verified end to end against NIOS 9.x. - Adaptive pre-provisioning: the CLI reads the target grid's
memberschema and dropshardware_infofields
it does not accept, because an unknown field aborts the request and rolls the new member back. - Anycast loopbacks with
member <fqdn> anycast add|delete, defaulting to /32 and /128. Known NIOS
preconditions surface asDeferred:rather thanError:. - Per-protocol DHCP service control:
member <fqdn> dhcp enable|disable [ipv4|ipv6|both]. - Views, NS groups, shared record groups and scheduled tasks.
- Service restarts with mode, option, member selection and delay, plus absolute scheduling via
at=<iso8601|epoch>andrestart status. show upgrade_status groupreports member rollout progress and step counts.show db_objectsacceptsobject_types=andversion=.
DTC
- Pool, server, monitor and LBDN wiring:
dtc pool <name> server add|delete,
dtc pool <name> monitor add|delete <proto> <name>, anddtc lbdn <name> pool add|delete <pool>.
Administration and security
- Admin users, groups, roles and permissions; RADIUS users and devices.
- Certificates: download, upload, generate self-signed, and generate a CSR.
- Notification endpoints and rules, including
outbound_member_type=and endpoint name resolution.
Files and bulk data
- CSV export, and import with operation modes (
INSERT,OVERRIDE,MERGE,DELETE,CUSTOM), update
method, error policy, task polling and error-log download. - Grid backup and restore, log files, support bundles and lease history.
- Per-member
getmemberdatadownloads across every NIOS-supported type, fromdns_confand the DNS caches
throughdhcpv6_conf,radius_conf,ntp_keysandtraffic_capture. - A dedicated transfer layer for the
http_direct_file_ioprotocol the SDK does not model, including the
application/force-downloadcontent type NIOS requires on the GET.
Session handling
- Automatic WAPI version detection, cookie authentication, pagination through
get_paginated, streaming file I/O,
and strict TLS verification by default. - Set-chains of up to 16 key/value pairs per command.
Documentation and testing
- 3,284 mocked tests that need no grid, plus an env-gated real-grid suite that locks in NIOS-specific quirks.
- Grammar and documentation guards: every waypoint word must have a node behind it, every registered handler is
dispatched against a mock grid, and every command and abbreviation printed in the operator playbook is re-checked
against the live grammar, so a new sibling command cannot silently make a published abbreviation ambiguous. - Live-grid audit tooling that runs every no-arg
showcommand and classifies failures as friendly usage, grid
configuration or suspected bug. - Object-build smoke harness with parameterised build, verify and teardown of up to ~10,000 objects across 30+
types at three scales, with reverse-dependency-ordered teardown. - A full documentation site covering commands, an operator playbook, a cookbook, troubleshooting and development
guides. scripts/release.shcuts a release in one command from a cleanmain: it moves the version in
pyproject.toml,ibcli.__version__and the changelog heading together, relocks, runs everything CI runs, then
commits, tags and pushes.tests/test_packaging.pypins the invariants it relies on - the three versions
agreeing, the changelog heading existing, and no direct URL requirement in the published metadata.