ibcli¶
An async Python CLI for Infoblox NIOS¶
Tab-completion at every position, a live REPL, batch mode, and 1,063 commands over the WAPI.
A ground-up rewrite of the original Perl ibcli, with no Perl runtime and no unmaintained SDK.
admin@gm.corp.example > co z a example.com # tab-expands to: configure zone add
admin@gm.corp.example > configure zone add example.com view=Internal
OK: configure zone add example.com view Internal
admin@gm.corp.example > show zone example.com
fqdn=example.com view=Internal
Why this port exists¶
The original Perl ibcli is roughly 13,000 lines, predates the modern NIOS WAPI, and depends on the Infoblox::* Perl
SDK, which is no longer maintained.
-
Speaks WAPI directly
REST over
ibx-nios-sdk. No Perl runtime, no legacy SDK, and async end-to-end so a slow grid-wide call never blocks the prompt. -
The UX network engineers expect
Cisco-IOS-style prefix abbreviation at every position, with inline descriptions in the completion dropdown.
co z aexpands toconfigure zone add. -
Scriptable three ways
-efor one-shot, a batch file for bulk change, and.ibcli.cffor silent auto-connect.-imakes a re-run after a partial failure safe. -
Runs anywhere Python does
Python 3.11 or newer, Windows included. Persistent history in
~/.ibcli_history, up-arrow recall andCtrl-Rreverse search.
Quick start¶
Install the CLI:
Connect to a grid. Most NIOS deployments use a self-signed certificate, so -k is usually needed:
Press Tab to explore. Every keyword abbreviates to its shortest unambiguous prefix.
What it covers¶
-
DNS
Authoritative, forward, stub and delegated zones, forward and reverse. A, AAAA, CNAME, MX, TXT, PTR, SRV, CAA, NAPTR, TLSA, HTTPS, SVCB, DNAME and ALIAS records. Host records, shared record groups, RPZ, DNS64, GSS-TSIG.
-
IPAM
Network views, VLAN views, ranges and VLANs. Superhosts, bulkhosts, RIR organisations, hostname policies, and IPv4 and IPv6 address inventory.
-
DHCP
Networks and containers (v4 and v6), shared networks, ranges, fixed addresses and failover pairs. All five filter types, option spaces and definitions, templates, and leases.
-
Grid
Members both pre-provisioned and online, HA pairs with VRRP, MGMT and LAN2 ports, VLAN tagging, port redundancy, NS groups, upgrade groups and restart status.
-
Security
Admin users, groups and roles. Auth services for LDAP, AD, RADIUS, TACACS+, SAML and certificates. Approval workflows, HSM groups, parental controls and CA certificates.
-
DTC and Ops
DTC servers, pools, LBDNs, monitors and topology rules. CSV import and export, grid backup and restore, support bundles, notification rules and outbound integrations.
Commands cookbook Operator playbook
Verified, not just written¶
-
3,284 unit tests
Run in under ten seconds against a mocked WAPI using
httpx.MockTransport. No grid required, so the suite runs in CI on every push across Python 3.11, 3.12 and 3.13. -
Live-grid sweep
scripts/sweep-show.shruns every no-argshowcommand against a real grid and sorts each failure into friendly-usage, grid-config, or suspected bug. -
Smoke harness
scripts/smoke/builds, verifies and tears down roughly 10,000 objects across 30-plus types on a real grid, including HA pairs and port-redundant members. -
Integration contracts
A suite gated on
IBCLI_TEST_GRIDpins the NIOS behaviours a mock cannot reproduce, such as licence case sensitivity and dict-versus-string ref returns.
See Real Grid Status for the current verification matrix.
Where to go next¶
-
Installation, your first connection, and a tour of tab completion.
-
Invocation modes, the REPL, aliases, batch files and extensible attributes.
-
Per-domain reference, plus the cookbook and operator playbook.
-
WAPI object mapping, parser internals, CLI flags and troubleshooting.
-
Architecture, adding a command, and the testing workflow.
-
Licence, third-party dependencies and credits.