Skip to content

feature: NEW PROVIDER: Infoblox NIOS DNS - #4846

Merged
TomOnTime merged 5 commits into
DNSControl:mainfrom
matthewmgamble:master
Sep 28, 2026
Merged

TomOnTime merged 5 commits into
DNSControl:mainfrom
matthewmgamble:master

Conversation

@matthewmgamble

Copy link
Copy Markdown
Contributor

Summary

  • Adds a new DNS provider for Infoblox NIOS DDI appliances via the WAPI (Web API)
  • Supports A, AAAA, CAA, CNAME, MX, PTR, SRV, and TXT record types
  • Includes full provider documentation, integration test profile, and CI configuration

Details

The provider connects to the Infoblox Grid Master using WAPI with HTTP Basic Auth and manages DNS records in a configurable DNS view. Key implementation notes:

  • HTTP compression is disabled to avoid 403 responses from the Infoblox Apache reverse proxy
  • Non-standard WAPI fields (CAA, PTR) are explicitly requested via _return_fields+
  • NS records are excluded because Infoblox requires an addresses field (nameserver IPs) that DNSControl does not provide
  • TXT records are limited to 255 bytes per Infoblox's single-string constraint

Integration test results

Tested against Infoblox NIOS WAPI v2.12. Out of ~113 integration tests:

  • 110 pass
  • 3 known failures due to Infoblox limitations (NS delegation requires addresses array, 256-byte TXT edge case)

Files changed

Provider implementation (from prior commit):

  • providers/infoblox/ — provider code, API client, type converters, audit rules, unit tests

WAPI compatibility fixes:

  • providers/infoblox/api.go — DisableCompression, per-type return field handling
  • providers/infoblox/convert.go — Remove NS from supported types, strip TTL from NS bodies
  • providers/infoblox/auditrecords.go — Reject empty TXT, tighten to 255-byte limit

Submission files:

  • README.md — Added Infoblox to provider table
  • .github/CODEOWNERS — providers/infoblox @matthewmgamble
  • .github/workflows/pr_integration_tests.yml — INFOBLOX env vars
  • documentation/provider/infoblox.md — Provider documentation
  • documentation/SUMMARY.md, documentation/provider/index.md — Updated indexes
  • .github/labeler.yml, .goreleaser.yml — Auto-generated updates
  • integrationTest/profiles.json — INFOBLOX test profile

Test plan

  • Unit tests pass (go test ./providers/infoblox/...)
  • go vet ./providers/infoblox/... clean
  • go generate ./... and bin/generate-all.sh run without errors
  • Integration tests run against live Infoblox NIOS server (110/113 pass)

Please create the GitHub label provider-INFOBLOX.

a := rejectif.Auditor{}

a.Add("MX", rejectif.MxNull)

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please add something that rejects NS records

- **TXT records are limited to 255 bytes.** Infoblox does not support multi-string TXT records or single strings longer than 255 bytes.
- **Empty TXT records are rejected.**
- **TXT records with backslashes are not supported.**
- **Concurrent operations are not supported.** The provider processes changes sequentially.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

FYI: Concurrent operations only downloads zone's records in parallel. The updates are done sequentially. I'd be surprised if concurrent operations didn't work. Did you try it and see?

Comment thread providers/infoblox/infobloxProvider.go Outdated
providers.CanUseCAA: providers.Can(),
providers.CanUsePTR: providers.Can(),
providers.CanUseSRV: providers.Can(),
providers.DocCreateDomains: providers.Cannot("Infoblox zones must be pre-created"),

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No need to repeat the name of the provider

Suggested change
providers.DocCreateDomains: providers.Cannot("Infoblox zones must be pre-created"),
providers.DocCreateDomains: providers.Cannot("zones must be pre-created"),

Comment thread providers/infoblox/convert.go Outdated
Comment on lines +165 to +173
rc := &models.RecordConfig{
Type: "CNAME",
TTL: effectiveTTL(r.UseTTL, r.TTL, defaultTTL),
Original: r.Ref,
}
rc.SetLabelFromFQDN(r.Name, domain)
if err := rc.PopulateFromString("CNAME", ensureTrailingDot(r.Canonical), domain); err != nil {
return nil, fmt.Errorf("failed to populate CNAME record: %w", err)
}

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PopulateFromString() went away in v5.0, replaced by the much more powerful dc.NewRecordConfigParse/dc.NewRecordConfig.

This should be something like:

rc := dc.NewRecordConfig(dc.LabelFromShort(r.Name), effectiveTTL(r.UseTTL, r.TTL, defaultTTL), dnsv2.TypeCNAME, r.Canonical)
rc.Original = r.Ref

@matthewmgamble

Copy link
Copy Markdown
Contributor Author

Added a new commit to address the 4 concerns raised

@TomOnTime

Copy link
Copy Markdown
Collaborator

Please resolve the conflicts and I'll merge asap. Thanks!

- Disable HTTP compression to prevent 403 from Infoblox Apache proxy
- Request non-standard return fields for CAA (ca_flag, ca_tag, ca_value)
  and PTR (name) record types
- Remove ttl/use_ttl from NS record queries (unsupported by WAPI)
- Remove NS from supportedTypes (requires addresses field that
  dnscontrol does not provide)
- Strip ttl/use_ttl from NS record create/update bodies
- Tighten TXT audit: reject empty TXT and strings longer than 255 bytes
- Add INFOBLOX integration test profile
- Add provider documentation (documentation/provider/infoblox.md)
- Add INFOBLOX to README.md provider table
- Add CODEOWNERS entry for providers/infoblox
- Add INFOBLOX env vars to pr_integration_tests.yml
- Add INFOBLOX to documentation/SUMMARY.md
- Update auto-generated files (labeler.yml, goreleaser.yml, index.md)
- Reformat profiles.json via generate-all.sh
- Add NS record rejection via rejectif.NsAtApex in audit
- Remove redundant provider name from DocCreateDomains message
- Enable CanConcur (concurrent zone downloads work fine)
- Replace PopulateFromString with SetTarget for A, AAAA, CNAME, NS, PTR
- Update tests to match
Migrate all import paths from v4 to v5. Update convert.go to use
dc.NewRecordConfig() factory instead of removed SetTarget*() methods.
Replace direct field access (MxPreference, SrvPriority, etc.) with
As*() type-assertion methods. Update AuditRecords signature to use
models.Records type alias. Update all tests accordingly.
@TomOnTime

TomOnTime commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Thank you for contributing to this new provider, @matthewmgamble !

A few action items before we can merge this PR:

  1. By now you should have received a Github invite to join the Provider-maintainers github team, which gives you the "triage" role for this repo. Please accept the invite so we can assign bugs to you.
  2. @fm: Faisal Misle is our “liaison to maintainers”. Please send him an email from your preferred address to dnscontrol so we can stay in touch. Your email address will not be shared, only used for DNSControl communication. Please email f at faisal dot fm and CC tal at what exit dot org
  3. Please consider setting up a test account for use by our automated testing. This will mean we can test the provider every release in an automated manner. Info is here: https://docs.dnscontrol.org/developer-info/byo-secrets#donate-secrets-to-the-project (If a test account or OE&T environment isn't available, an API key restricted to a single domain is sufficient.) (This doesn't need to be part of this PR)
  4. Please make testing more repeatable using a "golden file". This is a file that records API interactions while running the integration tests. Later we can run tests against this data, instead of using the actual API. See https://docs.dnscontrol.org/developer-info/goldenfiles (This can be a future PR)

When I see the Github invite accepted and receive the email, I’ll merge this PR.

Thanks again!
Tom

P.S. The 3rd item on the list isn't usually possible for something like InfoBlox. What we did for PowerDNS (which is similar) is someone set up a server we could access over the internet. I realize that's a big ask. The 4th item might be more do-able.

@TomOnTime
TomOnTime merged commit 66037b8 into DNSControl:main Sep 28, 2026
3 checks passed
@TomOnTime TomOnTime changed the title FEATURE: Add Infoblox NIOS DNS provider feature: NEW PROVIDER: Infoblox NIOS DNS Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants