delete_group
Check what would be affected by removing an unwanted NSX security group, then delete it after confirmation; deletion is blocked if anything still references it.
Instructions
[WRITE] Delete an NSX security group; refuses while anything references it.
Use it once get_group shows the group is unwanted. Without confirm=True this only previews: it returns blast_radius (the group's name, path, expression_count, reference_count and references, blockers, unmeasured) and deletes nothing. Show that to the user and get their decision. Do not set confirm=True on your own because the user asked to delete earlier: they have not seen the blast radius yet.
confirm=True refuses if anything still references the group (parent groups from NSX's group-associations API; DFW and gateway-firewall rules and policy applied-to, by walking the rules), and refuses if that check itself fails (fail-safe). When the refusal names a DFW rule, retarget it with update_dfw_rule or drop it with delete_dfw_rule first. Returns {"action": "preview" | "deleted", "blast_radius": ...}, else {"error", "hint", "blast_radius"?}.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| target | No | Optional NSX Manager target from config. | |
| confirm | No | False (default) returns the blast radius and changes nothing. True applies it. | |
| group_id | Yes | ID of the group to delete. |