feature: NEW PROVIDER: Infoblox NIOS DNS - #4846
Conversation
| a := rejectif.Auditor{} | ||
|
|
||
| a.Add("MX", rejectif.MxNull) | ||
|
|
There was a problem hiding this comment.
Please add something that rejects NS records
| - **TXT records are limited to 255 bytes.** Infoblox does not support multi-string TXT records or single strings longer than 255 bytes. | ||
| - **Empty TXT records are rejected.** | ||
| - **TXT records with backslashes are not supported.** | ||
| - **Concurrent operations are not supported.** The provider processes changes sequentially. |
There was a problem hiding this comment.
FYI: Concurrent operations only downloads zone's records in parallel. The updates are done sequentially. I'd be surprised if concurrent operations didn't work. Did you try it and see?
| providers.CanUseCAA: providers.Can(), | ||
| providers.CanUsePTR: providers.Can(), | ||
| providers.CanUseSRV: providers.Can(), | ||
| providers.DocCreateDomains: providers.Cannot("Infoblox zones must be pre-created"), |
There was a problem hiding this comment.
No need to repeat the name of the provider
| providers.DocCreateDomains: providers.Cannot("Infoblox zones must be pre-created"), | |
| providers.DocCreateDomains: providers.Cannot("zones must be pre-created"), |
| rc := &models.RecordConfig{ | ||
| Type: "CNAME", | ||
| TTL: effectiveTTL(r.UseTTL, r.TTL, defaultTTL), | ||
| Original: r.Ref, | ||
| } | ||
| rc.SetLabelFromFQDN(r.Name, domain) | ||
| if err := rc.PopulateFromString("CNAME", ensureTrailingDot(r.Canonical), domain); err != nil { | ||
| return nil, fmt.Errorf("failed to populate CNAME record: %w", err) | ||
| } |
There was a problem hiding this comment.
PopulateFromString() went away in v5.0, replaced by the much more powerful dc.NewRecordConfigParse/dc.NewRecordConfig.
This should be something like:
rc := dc.NewRecordConfig(dc.LabelFromShort(r.Name), effectiveTTL(r.UseTTL, r.TTL, defaultTTL), dnsv2.TypeCNAME, r.Canonical)
rc.Original = r.Ref
|
Added a new commit to address the 4 concerns raised |
|
Please resolve the conflicts and I'll merge asap. Thanks! |
- Disable HTTP compression to prevent 403 from Infoblox Apache proxy - Request non-standard return fields for CAA (ca_flag, ca_tag, ca_value) and PTR (name) record types - Remove ttl/use_ttl from NS record queries (unsupported by WAPI) - Remove NS from supportedTypes (requires addresses field that dnscontrol does not provide) - Strip ttl/use_ttl from NS record create/update bodies - Tighten TXT audit: reject empty TXT and strings longer than 255 bytes - Add INFOBLOX integration test profile
- Add provider documentation (documentation/provider/infoblox.md) - Add INFOBLOX to README.md provider table - Add CODEOWNERS entry for providers/infoblox - Add INFOBLOX env vars to pr_integration_tests.yml - Add INFOBLOX to documentation/SUMMARY.md - Update auto-generated files (labeler.yml, goreleaser.yml, index.md) - Reformat profiles.json via generate-all.sh
- Add NS record rejection via rejectif.NsAtApex in audit - Remove redundant provider name from DocCreateDomains message - Enable CanConcur (concurrent zone downloads work fine) - Replace PopulateFromString with SetTarget for A, AAAA, CNAME, NS, PTR - Update tests to match
Migrate all import paths from v4 to v5. Update convert.go to use dc.NewRecordConfig() factory instead of removed SetTarget*() methods. Replace direct field access (MxPreference, SrvPriority, etc.) with As*() type-assertion methods. Update AuditRecords signature to use models.Records type alias. Update all tests accordingly.
e55d490 to
a0bc85d
Compare
|
Thank you for contributing to this new provider, @matthewmgamble ! A few action items before we can merge this PR:
When I see the Github invite accepted and receive the email, I’ll merge this PR. Thanks again! P.S. The 3rd item on the list isn't usually possible for something like InfoBlox. What we did for PowerDNS (which is similar) is someone set up a server we could access over the internet. I realize that's a big ask. The 4th item might be more do-able. |
Summary
Details
The provider connects to the Infoblox Grid Master using WAPI with HTTP Basic Auth and manages DNS records in a configurable DNS view. Key implementation notes:
_return_fields+addressesfield (nameserver IPs) that DNSControl does not provideIntegration test results
Tested against Infoblox NIOS WAPI v2.12. Out of ~113 integration tests:
addressesarray, 256-byte TXT edge case)Files changed
Provider implementation (from prior commit):
providers/infoblox/— provider code, API client, type converters, audit rules, unit testsWAPI compatibility fixes:
providers/infoblox/api.go— DisableCompression, per-type return field handlingproviders/infoblox/convert.go— Remove NS from supported types, strip TTL from NS bodiesproviders/infoblox/auditrecords.go— Reject empty TXT, tighten to 255-byte limitSubmission files:
README.md— Added Infoblox to provider table.github/CODEOWNERS—providers/infoblox @matthewmgamble.github/workflows/pr_integration_tests.yml— INFOBLOX env varsdocumentation/provider/infoblox.md— Provider documentationdocumentation/SUMMARY.md,documentation/provider/index.md— Updated indexes.github/labeler.yml,.goreleaser.yml— Auto-generated updatesintegrationTest/profiles.json— INFOBLOX test profileTest plan
go test ./providers/infoblox/...)go vet ./providers/infoblox/...cleango generate ./...andbin/generate-all.shrun without errorsPlease create the GitHub label
provider-INFOBLOX.