Infoblox Networks
Tasks to manage IPv4 networks in Infoblox via the WAPI REST API.
Infoblox DDI (DNS, DHCP, IPAM) tasks and triggers for Kestra, covering both NIOS Grid Manager (WAPI REST API) and Universal DDI (Cloud Services Portal API).
Automate Infoblox NIOS Grid Manager: manage IPv4/IPv6 networks, fixed addresses, DHCP ranges, DNS A/AAAA/CNAME/PTR/host records, list DHCP leases, and trigger flows on IP allocation events. Automate Infoblox Universal DDI (Cloud Services Portal): manage IP spaces, address blocks, subnets, addresses, DHCP ranges and fixed addresses, authoritative zones, and type-discriminated DNS records under the csp.* tasks.
Manage Infoblox DDI — IPv4/IPv6 networks, addresses, DHCP ranges, fixed addresses, DNS records, and leases — from Kestra flows. The plugin covers two separate Infoblox products with two separate task families:
ipam.*.csp.*.They are not interchangeable: pointing a NIOS task at a CSP host (or vice versa) fails, since auth, object identifiers, and the object model all differ. Pick the family matching your Infoblox deployment.
NIOS Grid Manager (ipam.*): all tasks and the trigger require url (the Grid Manager base URL, e.g. https://infoblox.example.com), username, and password (HTTP Basic credentials; password is a secret) — all required. Optionally set wapiVersion (default v2.12) and options for HTTP client configuration, including relaxing TLS verification for appliances with self-signed certificates.
Universal DDI (csp.*): all tasks require apiKey (a Cloud Services Portal API key, sent as Authorization: Token <apiKey>; secret, required). url is optional and defaults to https://csp.infoblox.com (US region) — set it to your tenant's regional host, e.g. https://csp.eu.infoblox.com (EU). Optionally set options for HTTP client configuration. There is no wapiVersion equivalent — the base path is fixed at /api/ddi/v1.
Store secrets in secrets and set connection properties on each task.
url must point at a NIOS Grid Manager exposing the WAPI. The Infoblox Cloud Services Portal (Universal DDI) is a different product with its own API and is not supported — pointing url at a CSP host fails with a diagnostic error explaining that the endpoint did not return a WAPI response.
Tasks are grouped by resource type under ipam.*. A few conventions apply across all of them:
_ref strings, not numeric IDs. Run a List (or Get) task to retrieve a _ref, then pass it as ref to Get, Update, and Delete.List tasks share one shape: optional filters (a map of WAPI search parameters) and returnFields (replaces the default field set — only the fields you name, plus _ref, are returned), with maxResults (default 1000) and fetchType (FETCH, FETCH_ONE, STORE, or NONE; default FETCH).Update tasks require ref plus at least one mutable field, and reject an empty payload.ttl; when set, the plugin enables use_ttl automatically.ipam.network — List, Get, Create, Update, Delete. Create requires network (CIDR); optional networkView, comment. Update changes comment.ipam.networkview — List, Create, Delete. Create requires name; optional comment.ipam.address — List, plus AllocateNextAvailable and Release. AllocateNextAvailable requires networkRef (a network _ref or CIDR; optional networkView); it atomically reserves one address as a RESERVED fixed address and returns its _ref. Pass that to Release (ref) to delete the reservation. Allocation fails if the network is exhausted.ipam.fixedaddress — List, Create, Update, Delete. Create requires ipv4addr; optional mac, matchClient, name, networkView, comment. With the WAPI-default matchClient (MAC_ADDRESS), mac is required — set matchClient: RESERVED for a placeholder without a MAC.ipam.range — List, Create, Update, Delete. Create requires startAddr and endAddr; optional network, networkView, comment.ipam.ipv6network — List, Create, Update, Delete. Create requires network (CIDR); optional networkView, comment.ipam.ipv6address — List, plus AllocateNextAvailable (requires networkRef; optional networkView) and Release (requires ref), with the same reserve-one-address semantics as ipam.address.ipam.ipv6fixedaddress — List, Create, Delete. Create requires ipv6addr; optional duid, matchClient, name, comment. With the WAPI-default matchClient (DUID), duid is required — set matchClient: RESERVED for a placeholder without a DUID.ipam.ipv6range — List, Create, Delete. Create requires startAddr and endAddr; optional comment.ipam.dns.arecord — List, Create, Update, Delete. Create requires name (FQDN) and ipv4addr; optional dnsView, ttl, comment.ipam.dns.aaaarecord — List, Create, Update, Delete. Create requires name and ipv6addr; optional dnsView, ttl, comment.ipam.dns.cnamerecord — List, Create, Update, Delete. Create requires name (alias FQDN) and canonical (target FQDN); optional dnsView, ttl, comment.ipam.dns.ptrrecord — List, Create, Update, Delete. Create requires name and ptrdName, plus either ipv4addr or ipv6addr; optional dnsView, ttl, comment.ipam.dns.hostrecord — List, Create, Update, Delete. Create requires name and ipv4Addrs (a list of address entries, each with at least ipv4addr); optional dnsView, comment. Update changes comment.ipam.lease — List only (read-only DHCP lease lookup).Tasks are grouped by resource type under csp.*. A few conventions apply across all of them:
id, itself a resource path (e.g. ipam/subnet/<uuid>), not a bare UUID and not a WAPI _ref. Run a List (or Get) task to retrieve an id, then pass it as objectId to Get, Update, and Delete (id/type are reserved property names on Kestra tasks, so these properties are named objectId/recordType instead of id/type).List tasks share one shape: optional filters (a map of search parameters), limit (the _limit page size, default 100), and fetchType (FETCH, FETCH_ONE, STORE, or NONE; default FETCH). Paging is offset-based and stops at the first short page.Update tasks require objectId plus at least one mutable field, and reject an empty payload.Task groups:
csp.ipam.ipspace — List, Create, Delete. Create requires name; optional comment. The Universal DDI equivalent of a NIOS network view.csp.ipam.addressblock — List, Create, Update, Delete. Create requires addressBlock (CIDR string, split locally into address+cidr) and space (an ipam/ip_space id); optional comment.csp.ipam.subnet — List, Get, Create, Update, Delete. Create requires subnet (CIDR string, split locally into address+cidr) and space; a malformed CIDR (missing prefix, out-of-range prefix, non-numeric prefix) is rejected locally before any HTTP call.csp.ipam.address — List, plus AllocateNextAvailable and Release. AllocateNextAvailable requires parentId (a subnet or address block id) and space; it fetches a candidate from the nextavailableip endpoint then creates the address — a best-effort two-step sequence, unlike NIOS WAPI's confirmed-atomic func: nextavailableip. Pass the output id to Release to delete the reservation.csp.ipam.range — List, Create, Update, Delete. Create requires start, end, and space.csp.dns.authzone — List, Create, Delete. Create requires fqdn; optional comment.csp.dns.record — List, Create, Update, Delete. Universal DDI unifies A, AAAA, CNAME, PTR, TXT, MX, NS, and SRV into one object discriminated by recordType. Create requires zone, nameInZone, recordType, and rdata; rdata must carry the key recordType requires (address for A/AAAA, dname for CNAME/PTR/NS, text for TXT, exchange for MX, target for SRV) or the task rejects it, naming the missing key. Update requires recordType alongside rdata to validate it. Both accept an optional ttl; when set, use_ttl is enabled alongside it, mirroring the WAPI convention (unverified against a live CSP tenant).csp.dhcp.fixedaddress — List, Create, Delete. Universal DDI has no dedicated fixed-address endpoint in its public API surface, so this is implemented as an ipam/address create tagged kestra_fixed=true (documented assumption). Create requires address and space; optional mac, comment, and tags (merged with the always-set kestra_fixed=true tag, which cannot be overridden). List always filters on _tfilter=kestra_fixed==true (unless filters already sets its own _tfilter) so it only returns tagged reservations.ipam.trigger.IpAllocationTrigger (NIOS only — no Universal DDI trigger exists yet) fires when IP allocation state changes — set network (an IPv4 or IPv6 CIDR; the address family is detected automatically, required). Optionally set watchStatus (USED for allocated addresses, UNUSED for released ones; default USED) and interval (default PT1M). Each poll compares matching addresses against the previous poll (state persisted in the namespace KV store) and fires only on the delta; an empty delta does not fire. Outputs addedEvents, removedEvents, addedCount, removedCount, and network.