Skip to content

Operator Playbook

Task-oriented recipes, each shown twice: the abbreviated form you would actually type, and the full form you would write in a script or a change ticket.

Both columns are the same command. ibcli accepts any unambiguous prefix of a keyword at every position, so s g and show grid reach the same handler and send the same WAPI request. Every abbreviation on this page was generated by shortening each keyword to its shortest unambiguous prefix and then expanding it back through the parser to confirm it resolves to the full command - none of them are hand-written.

Which form to use where

Type the short form interactively; write the long form in .ibcli batch files and runbooks. An abbreviation is only unambiguous against the commands registered today - adding a sibling command later can make a previously valid abbreviation ambiguous, which is exactly what you do not want happening inside a scheduled job.


Reading the grid

Task Abbreviated Full
Grid name and ref s g show grid
WAPI version in use s se v show server version
Members s me show member
DNS views s vi show views
Zones s z show zone
Networks s network show network
Network containers s network c show network container
DHCP ranges s ra show range
Fixed addresses s fix show fixed
Leases s le show lease
RPZ zones s rpz show rpz

Words that cannot be shortened

network, record and rpz stay full. Each is a strict prefix of a longer sibling (network_view, network_discovery, record_name_policy, …), and a prefix that matches two or more words is ambiguous. A whole word is never ambiguous, though - network is accepted even though network_view starts with it.

Add fields= to any show to pull extra WAPI fields:

s network 10.10.0.0/24 fields=extattrs,comment
show network 10.10.0.0/24 fields=extattrs,comment

Extensible attributes

EA definitions are the schema; you must create them before any object can carry a value.

Define

c g a a Owner t s
configure grid attribute add Owner type string

Types are string, integer, email, url, date and enum.

A multi-word comment must be quoted - the tokenizer splits on whitespace, so an unquoted comment fails with ^--- Unknown argument at marker:

c g a a CostCode t i c "Finance tracking code"
configure grid attribute add CostCode type integer comment "Finance tracking code"

An enum needs its values inline, one list_value per choice. Without them NIOS rejects the create with "At least one value must be supplied for extensible attribute definition":

c g a a Tier t en l Gold l Silver
configure grid attribute add Tier type enum list_value Gold list_value Silver

Use, list and remove

Attach a value at add time with set <EA> <value>:

c network a 10.10.0.0/24 s Owner netops
configure network add 10.10.0.0/24 set Owner netops
s g a                     # list definitions
show grid attribute

c g a Owner d                  # remove a definition
configure grid attribute Owner delete

DNS: zones and records

Create a zone and populate it

c z a corp.example.com
configure zone add corp.example.com
c z corp.example.com a h web01 10.10.0.10
configure zone corp.example.com add host web01 10.10.0.10
c z corp.example.com a a www 10.10.0.20
configure zone corp.example.com add a www 10.10.0.20
c z corp.example.com a aa www6 2001:db8::20
configure zone corp.example.com add aaaa www6 2001:db8::20
c z corp.example.com a c portal www
configure zone corp.example.com add cname portal www
c z corp.example.com a m mail mail.corp.example.com 10
configure zone corp.example.com add mx mail mail.corp.example.com 10

A TXT value containing = or spaces must be quoted, or the tokenizer splits it:

c z corp.example.com a t spf "v=spf1 -all"
configure zone corp.example.com add txt spf "v=spf1 -all"

Read records back

s record all corp.example.com
show record all corp.example.com
s record a_ www
show record a_record www

Sign and tear down

c z corp.example.com dn s
configure zone corp.example.com dnssec sign

Note de versus dn below - at this point in the grammar d alone is ambiguous between delete and dnssec:

c z corp.example.com de h web01
configure zone corp.example.com delete host web01
c z corp.example.com de
configure zone corp.example.com delete

IPAM and DHCP

c network a 10.10.0.0/24
configure network add 10.10.0.0/24
c network 10.10.0.0/24 r a 10.10.0.100 10.10.0.200
configure network 10.10.0.0/24 range add 10.10.0.100 10.10.0.200
c network 10.10.0.0/24 f a 10.10.0.50 00:11:22:33:44:55
configure network 10.10.0.0/24 fixed add 10.10.0.50 00:11:22:33:44:55
c network fa a fo-01 p ns1.corp.example.com s ns2.corp.example.com
configure network failover add fo-01 primary ns1.corp.example.com secondary ns2.corp.example.com
c network 10.10.0.0/24 d
configure network 10.10.0.0/24 delete

Deletion order

A member that is a DHCP failover peer or an NS group primary cannot be deleted until those references are removed - NIOS answers "cannot be removed because it is the DHCP failover primary in <fo>". Tear down failover associations and NS groups first, then members.


Members

<grid> is the grid name from show grid, not the master's IP. A wrong name fails the add outright.

c g Infoblox m a ns1.corp.example.com ipaddress=10.10.0.5/24 gateway=10.10.0.1
configure grid Infoblox member add ns1.corp.example.com ipaddress=10.10.0.5/24 gateway=10.10.0.1
c g Infoblox m ns1.corp.example.com dn e
configure grid Infoblox member ns1.corp.example.com dns enable
c g Infoblox m ns1.corp.example.com dh e ipv4
configure grid Infoblox member ns1.corp.example.com dhcp enable ipv4
c g Infoblox m ns1.corp.example.com de
configure grid Infoblox member ns1.corp.example.com delete

VLAN tagging, MGMT, HA and port redundancy

These use key=value options, which are never abbreviated - only the keywords before them are. See Grid commands for the full field list.

configure grid Infoblox member add tagged.corp.example.com \
    ipaddress=10.70.10.5/24 gateway=10.70.10.1 vlan_id=110 \
    mgmt_ipaddress=10.71.10.5/24 mgmt_gateway=10.71.10.1

An HA pair needs a shared VRRP id plus, per node, its LAN1 and HA-port addresses - and a different MGMT address each:

configure grid Infoblox member add ha1.corp.example.com \
    ipaddress=10.70.20.5/24 gateway=10.70.20.1 router_id=55 \
    ha_node=10.70.20.6,10.70.20.8,10.71.20.6 \
    ha_node=10.70.20.7,10.70.20.9,10.71.20.7 \
    mgmt_ipaddress=10.71.20.5/24 mgmt_gateway=10.71.20.1

Port redundancy makes LAN2 a standby for LAN1, so LAN2 takes no address of its own:

configure grid Infoblox member add red1.corp.example.com \
    ipaddress=10.70.60.5/24 gateway=10.70.60.1 \
    port_redundancy=true port_redundancy_primary=true

DTC, admin and auth

s dt s                         # DTC servers
show dtc server

s dt p                         # DTC pools
show dtc pool

s dt l                         # DTC LBDNs
show dtc lbdn
s adm u
show admin user
c ad u a jdoe
configure admin user add jdoe
s au r
show auth radius

show auth radius is not radius:user

auth radius is the RADIUS authentication service. The old radius user / radius device commands were removed - NIOS 9.1 answers Unknown object type (radius:user).


Views

c vi a Internal
configure view add Internal

Files and restarts

u cs data.csv
upload csv data.csv
d da backup.bak
download database backup.bak
r dn                           # restart DNS
restart dns

r s                            # restart status
restart status

Running commands outside the REPL

One command and exit:

ibcli -k -s 10.64.50.220 -u admin -p "$PASSWORD" -e "show grid"

A batch file - batch files are positional, not a flag:

ibcli -k -i -s 10.64.50.220 -u admin -p "$PASSWORD" provision.ibcli
Flag Use it when
-k / --insecure The grid uses a self-signed certificate (the NIOS default). Without it TLS is verified.
-i / --idempotent Re-runnable scripts: "already exists" becomes Skipped: instead of Error:.
--timeout <s> A grid-wide aggregation exceeds the 30s default - show threat_protection statistics needs it.
--allow-restricted Your NIOS permits an operation the SDK's restriction table says it forbids.
-d 1..3 Trace: 1 dispatch, 2 adds HTTP method/URL/status, 3 adds WAPI params and retries.

-i is for 'already exists', not 'this failed'

Idempotent mode only demotes failures whose message says the object exists. A licensing wall or a restricted operation still reports Error: and still counts as a failure.


Writing an abbreviation you can trust

If you want to shorten a command yourself, let the parser prove it rather than counting letters:

ibcli -e "s g a"

If the abbreviation is ambiguous you get a caret pointing at the offending token rather than a wrong command:

              ^--- Ambiguous argument at marker

Tab completion shows the same information live - press Tab at any point to see the valid next words with a description of each.