Operator Playbook¶
Task-oriented recipes, each shown twice: the abbreviated form you would actually type, and the full form you would write in a script or a change ticket.
Both columns are the same command. ibcli accepts any unambiguous prefix of a keyword at every
position, so s g and show grid reach the same handler and send the same WAPI request. Every
abbreviation on this page was generated by shortening each keyword to its shortest unambiguous
prefix and then expanding it back through the parser to confirm it resolves to the full command -
none of them are hand-written.
Which form to use where
Type the short form interactively; write the long form in .ibcli batch files and runbooks.
An abbreviation is only unambiguous against the commands registered today - adding a sibling
command later can make a previously valid abbreviation ambiguous, which is exactly what you do
not want happening inside a scheduled job.
Reading the grid¶
| Task | Abbreviated | Full |
|---|---|---|
| Grid name and ref | s g |
show grid |
| WAPI version in use | s se v |
show server version |
| Members | s me |
show member |
| DNS views | s vi |
show views |
| Zones | s z |
show zone |
| Networks | s network |
show network |
| Network containers | s network c |
show network container |
| DHCP ranges | s ra |
show range |
| Fixed addresses | s fix |
show fixed |
| Leases | s le |
show lease |
| RPZ zones | s rpz |
show rpz |
Words that cannot be shortened
network, record and rpz stay full. Each is a strict prefix of a longer sibling
(network_view, network_discovery, record_name_policy, …), and a prefix that matches two
or more words is ambiguous. A whole word is never ambiguous, though - network is accepted
even though network_view starts with it.
Add fields= to any show to pull extra WAPI fields:
Extensible attributes¶
EA definitions are the schema; you must create them before any object can carry a value.
Define¶
Types are string, integer, email, url, date and enum.
A multi-word comment must be quoted - the tokenizer splits on whitespace, so an unquoted comment
fails with ^--- Unknown argument at marker:
c g a a CostCode t i c "Finance tracking code"
configure grid attribute add CostCode type integer comment "Finance tracking code"
An enum needs its values inline, one list_value per choice. Without them NIOS rejects the
create with "At least one value must be supplied for extensible attribute definition":
c g a a Tier t en l Gold l Silver
configure grid attribute add Tier type enum list_value Gold list_value Silver
Use, list and remove¶
Attach a value at add time with set <EA> <value>:
s g a # list definitions
show grid attribute
c g a Owner d # remove a definition
configure grid attribute Owner delete
DNS: zones and records¶
Create a zone and populate it¶
c z corp.example.com a aa www6 2001:db8::20
configure zone corp.example.com add aaaa www6 2001:db8::20
c z corp.example.com a m mail mail.corp.example.com 10
configure zone corp.example.com add mx mail mail.corp.example.com 10
A TXT value containing = or spaces must be quoted, or the tokenizer splits it:
c z corp.example.com a t spf "v=spf1 -all"
configure zone corp.example.com add txt spf "v=spf1 -all"
Read records back¶
Sign and tear down¶
Note de versus dn below - at this point in the grammar d alone is ambiguous between
delete and dnssec:
IPAM and DHCP¶
c network 10.10.0.0/24 r a 10.10.0.100 10.10.0.200
configure network 10.10.0.0/24 range add 10.10.0.100 10.10.0.200
c network 10.10.0.0/24 f a 10.10.0.50 00:11:22:33:44:55
configure network 10.10.0.0/24 fixed add 10.10.0.50 00:11:22:33:44:55
c network fa a fo-01 p ns1.corp.example.com s ns2.corp.example.com
configure network failover add fo-01 primary ns1.corp.example.com secondary ns2.corp.example.com
Deletion order
A member that is a DHCP failover peer or an NS group primary cannot be deleted until those
references are removed - NIOS answers "cannot be removed because it is the DHCP failover
primary in <fo>". Tear down failover associations and NS groups first, then members.
Members¶
<grid> is the grid name from show grid, not the master's IP. A wrong name fails the add
outright.
c g Infoblox m a ns1.corp.example.com ipaddress=10.10.0.5/24 gateway=10.10.0.1
configure grid Infoblox member add ns1.corp.example.com ipaddress=10.10.0.5/24 gateway=10.10.0.1
c g Infoblox m ns1.corp.example.com dn e
configure grid Infoblox member ns1.corp.example.com dns enable
c g Infoblox m ns1.corp.example.com dh e ipv4
configure grid Infoblox member ns1.corp.example.com dhcp enable ipv4
VLAN tagging, MGMT, HA and port redundancy¶
These use key=value options, which are never abbreviated - only the keywords before them are.
See Grid commands for the full field list.
configure grid Infoblox member add tagged.corp.example.com \
ipaddress=10.70.10.5/24 gateway=10.70.10.1 vlan_id=110 \
mgmt_ipaddress=10.71.10.5/24 mgmt_gateway=10.71.10.1
An HA pair needs a shared VRRP id plus, per node, its LAN1 and HA-port addresses - and a different MGMT address each:
configure grid Infoblox member add ha1.corp.example.com \
ipaddress=10.70.20.5/24 gateway=10.70.20.1 router_id=55 \
ha_node=10.70.20.6,10.70.20.8,10.71.20.6 \
ha_node=10.70.20.7,10.70.20.9,10.71.20.7 \
mgmt_ipaddress=10.71.20.5/24 mgmt_gateway=10.71.20.1
Port redundancy makes LAN2 a standby for LAN1, so LAN2 takes no address of its own:
configure grid Infoblox member add red1.corp.example.com \
ipaddress=10.70.60.5/24 gateway=10.70.60.1 \
port_redundancy=true port_redundancy_primary=true
DTC, admin and auth¶
s dt s # DTC servers
show dtc server
s dt p # DTC pools
show dtc pool
s dt l # DTC LBDNs
show dtc lbdn
show auth radius is not radius:user
auth radius is the RADIUS authentication service. The old radius user / radius device
commands were removed - NIOS 9.1 answers Unknown object type (radius:user).
Views¶
Files and restarts¶
Running commands outside the REPL¶
One command and exit:
A batch file - batch files are positional, not a flag:
| Flag | Use it when |
|---|---|
-k / --insecure |
The grid uses a self-signed certificate (the NIOS default). Without it TLS is verified. |
-i / --idempotent |
Re-runnable scripts: "already exists" becomes Skipped: instead of Error:. |
--timeout <s> |
A grid-wide aggregation exceeds the 30s default - show threat_protection statistics needs it. |
--allow-restricted |
Your NIOS permits an operation the SDK's restriction table says it forbids. |
-d 1..3 |
Trace: 1 dispatch, 2 adds HTTP method/URL/status, 3 adds WAPI params and retries. |
-i is for 'already exists', not 'this failed'
Idempotent mode only demotes failures whose message says the object exists. A licensing wall or
a restricted operation still reports Error: and still counts as a failure.
Writing an abbreviation you can trust¶
If you want to shorten a command yourself, let the parser prove it rather than counting letters:
If the abbreviation is ambiguous you get a caret pointing at the offending token rather than a wrong command:
Tab completion shows the same information live - press Tab at any point to see the valid next words with a description of each.