aim-web2.1.0rc9
This commit is contained in:
@@ -0,0 +1,48 @@
|
||||
# checkmk_deploy_scripts
|
||||
|
||||
Operator defaults are intentionally low-precedence; inventory and explicit run options may override them.
|
||||
|
||||
```yaml
|
||||
---
|
||||
# unifi.cfg is role-managed and replaced, mode 0600. Password comes from Vault.
|
||||
# An absent/CHANGEME password fails before deployment; no credentials are logged.
|
||||
checkmk_linux_plugin_dir: /usr/lib/check_mk_agent/plugins
|
||||
checkmk_linux_local_dir: /usr/lib/check_mk_agent/local
|
||||
checkmk_linux_config_dir: /etc/check_mk
|
||||
checkmk_windows_plugin_dir: C:\ProgramData\checkmk\agent\plugins
|
||||
checkmk_windows_builtin_plugin_dir: C:\Program Files (x86)\checkmk\service\plugins
|
||||
checkmk_windows_local_dir: C:\ProgramData\checkmk\agent\local
|
||||
checkmk_monitoring_scripts_dir: '{{ lookup(''ansible.builtin.env'', ''AIM_CHECKMK_MONITORING_SCRIPTS_DIR'')
|
||||
| default(''/etc/checkmk_monitoring_scripts'', true) }}'
|
||||
checkmk_windows_scripts_dir: '{{ checkmk_monitoring_scripts_dir }}/Scripts Windows'
|
||||
checkmk_linux_scripts_dir: '{{ checkmk_monitoring_scripts_dir }}/Scripts Linux'
|
||||
checkmk_unifi_mode: auto
|
||||
want_linux_check_certificate: false
|
||||
want_windows_citrix: false
|
||||
want_windows_surebackup: false
|
||||
want_windows_backup: false
|
||||
want_windows_nsp_mailqueue: false
|
||||
want_windows_certificate: false
|
||||
want_windows_veeam_cloud_connect: false
|
||||
want_windows_veeam_backup: false
|
||||
checkmk_unifi_username: bf-monitoring
|
||||
checkmk_unifi_password: '{{ vault_checkmk_unifi_password | default('''') }}'
|
||||
checkmk_unifi_baseurl: '{{ ''https://127.0.0.1:11443'' if _checkmk_unifi_effective == ''os'' else ''https://127.0.0.1:8443''
|
||||
}}'
|
||||
checkmk_unifi_curl_options: ' --insecure --tlsv1.2'
|
||||
checkmk_unifi_status_provisioning: 1
|
||||
checkmk_unifi_status_upgrading: 1
|
||||
checkmk_unifi_status_upgradable: 0
|
||||
checkmk_unifi_status_heartbeat_missed: 1
|
||||
checkmk_unifi_status_noautobackup: 0
|
||||
```
|
||||
|
||||
`unifi.cfg` is generated from the supplied schema, POSIX-shell quoted, mode `0600`, and protected with `no_log` and `diff: false`. Use a Vault reference for the password. `CHANGEME` and empty passwords fail before deployment. The active UniFi mode replaces the alternative local check. Other obsolete scripts are removed only by explicit cleanup.
|
||||
|
||||
## Structured result integration
|
||||
|
||||
Current reporting behavior and field semantics are specified in
|
||||
[scripts/docs/OPERATION_RESULTS.md](../../scripts/docs/OPERATION_RESULTS.md).
|
||||
The calling catalog playbook owns publication; helper roles do not implicitly export
|
||||
arbitrary facts, module results or debug data. Existing defaults above retain their
|
||||
precedence. See the current validation/sanity documents before using the new candidate.
|
||||
@@ -0,0 +1,32 @@
|
||||
---
|
||||
# unifi.cfg is role-managed and replaced, mode 0600. Password comes from Vault.
|
||||
# An absent/CHANGEME password fails before deployment; no credentials are logged.
|
||||
checkmk_linux_plugin_dir: /usr/lib/check_mk_agent/plugins
|
||||
checkmk_linux_local_dir: /usr/lib/check_mk_agent/local
|
||||
checkmk_linux_config_dir: /etc/check_mk
|
||||
checkmk_windows_plugin_dir: C:\ProgramData\checkmk\agent\plugins
|
||||
checkmk_windows_builtin_plugin_dir: C:\Program Files (x86)\checkmk\service\plugins
|
||||
checkmk_windows_local_dir: C:\ProgramData\checkmk\agent\local
|
||||
checkmk_monitoring_scripts_dir: '{{ lookup(''ansible.builtin.env'', ''AIM_CHECKMK_MONITORING_SCRIPTS_DIR'')
|
||||
| default(''/etc/checkmk_monitoring_scripts'', true) }}'
|
||||
checkmk_windows_scripts_dir: '{{ checkmk_monitoring_scripts_dir }}/Scripts Windows'
|
||||
checkmk_linux_scripts_dir: '{{ checkmk_monitoring_scripts_dir }}/Scripts Linux'
|
||||
checkmk_unifi_mode: auto
|
||||
want_linux_check_certificate: false
|
||||
want_windows_citrix: false
|
||||
want_windows_surebackup: false
|
||||
want_windows_backup: false
|
||||
want_windows_nsp_mailqueue: false
|
||||
want_windows_certificate: false
|
||||
want_windows_veeam_cloud_connect: false
|
||||
want_windows_veeam_backup: false
|
||||
checkmk_unifi_username: bf-monitoring
|
||||
checkmk_unifi_password: '{{ vault_checkmk_unifi_password | default('''') }}'
|
||||
checkmk_unifi_baseurl: '{{ ''https://127.0.0.1:11443'' if _checkmk_unifi_effective == ''os'' else ''https://127.0.0.1:8443''
|
||||
}}'
|
||||
checkmk_unifi_curl_options: ' --insecure --tlsv1.2'
|
||||
checkmk_unifi_status_provisioning: 1
|
||||
checkmk_unifi_status_upgrading: 1
|
||||
checkmk_unifi_status_upgradable: 0
|
||||
checkmk_unifi_status_heartbeat_missed: 1
|
||||
checkmk_unifi_status_noautobackup: 0
|
||||
@@ -0,0 +1,40 @@
|
||||
# UniFi mode replacement is the explicitly approved exception to separate cleanup.
|
||||
# Unknown files and the active UniFi check are never removed here.
|
||||
- name: Linux | Ensure local check directory
|
||||
ansible.builtin.file:
|
||||
path: '{{ checkmk_linux_local_dir }}'
|
||||
state: directory
|
||||
mode: '0755'
|
||||
- name: Linux | Ensure configuration directory
|
||||
ansible.builtin.file:
|
||||
path: '{{ checkmk_linux_config_dir }}'
|
||||
state: directory
|
||||
mode: '0755'
|
||||
- name: Linux | Write the single UniFi configuration
|
||||
ansible.builtin.template:
|
||||
src: unifi.cfg.j2
|
||||
dest: '{{ checkmk_linux_config_dir }}/unifi.cfg'
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0600'
|
||||
validate: /bin/sh -n %s
|
||||
when: _checkmk_unifi_effective in ['network','os']
|
||||
no_log: true
|
||||
diff: false
|
||||
register: _aim_unifi_write
|
||||
- name: Linux | Deploy selected monitoring checks
|
||||
ansible.builtin.copy:
|
||||
src: '{{ item.source }}'
|
||||
dest: '{{ checkmk_linux_local_dir }}/{{ item.filename }}'
|
||||
mode: '0755'
|
||||
loop: '{{ _checkmk_selected_scripts }}'
|
||||
loop_control:
|
||||
label: '{{ item.filename }}'
|
||||
register: _aim_check_copies
|
||||
- name: Linux | Remove only the opposite UniFi local check
|
||||
ansible.builtin.file:
|
||||
path: "{{ checkmk_linux_local_dir }}/{{ 'check_unifi-controller.sh' if _checkmk_unifi_effective == 'os' else
|
||||
'check_unifi-os.sh' }}"
|
||||
state: absent
|
||||
when: _checkmk_unifi_effective in ['network','os']
|
||||
register: _aim_opposite_remove
|
||||
@@ -0,0 +1,10 @@
|
||||
---
|
||||
|
||||
- name: Checkmk | Validate controller sources and required parameters
|
||||
ansible.builtin.import_tasks: preflight.yml
|
||||
- name: Checkmk | Deploy linux checks
|
||||
ansible.builtin.include_tasks: linux.yml
|
||||
when: ansible_facts.os_family != 'Windows'
|
||||
- name: Checkmk | Deploy windows checks
|
||||
ansible.builtin.include_tasks: windows.yml
|
||||
when: ansible_facts.os_family == 'Windows'
|
||||
@@ -0,0 +1,57 @@
|
||||
---
|
||||
|
||||
- name: Checkmk | Inspect selected controller script sources
|
||||
ansible.builtin.stat:
|
||||
path: '{{ item.source }}'
|
||||
delegate_to: localhost
|
||||
become: false
|
||||
loop: '{{ _checkmk_selected_scripts }}'
|
||||
loop_control:
|
||||
label: '{{ item.filename }}'
|
||||
register: _checkmk_sources
|
||||
- name: Checkmk | Require selected controller files
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- item.stat.exists | default(false)
|
||||
- item.stat.isreg | default(false)
|
||||
fail_msg: A selected monitoring script is missing on the controller. Sync the monitoring repository first.
|
||||
quiet: true
|
||||
loop: '{{ _checkmk_sources.results }}'
|
||||
loop_control:
|
||||
label: '{{ item.item.filename }}'
|
||||
- name: Checkmk | Validate UniFi public settings
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- checkmk_unifi_username is string
|
||||
- checkmk_unifi_username | length > 0
|
||||
- checkmk_unifi_baseurl is match('^https?://[^\s]+$')
|
||||
- checkmk_unifi_curl_options is string
|
||||
- checkmk_unifi_status_provisioning | int in [0,1,2,3]
|
||||
- checkmk_unifi_status_upgrading | int in [0,1,2,3]
|
||||
- checkmk_unifi_status_upgradable | int in [0,1,2,3]
|
||||
- checkmk_unifi_status_heartbeat_missed | int in [0,1,2,3]
|
||||
- checkmk_unifi_status_noautobackup | int in [0,1,2,3]
|
||||
fail_msg: Invalid UniFi username, base URL, curl options or status mapping.
|
||||
quiet: true
|
||||
when:
|
||||
- ansible_facts.os_family != 'Windows'
|
||||
- _checkmk_unifi_effective in ['network','os']
|
||||
- name: Checkmk | Require a real UniFi monitoring password
|
||||
when:
|
||||
- ansible_facts.os_family != 'Windows'
|
||||
- _checkmk_unifi_effective in ['network','os']
|
||||
block:
|
||||
- name: Checkmk | Validate secret
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- checkmk_unifi_password is string
|
||||
- checkmk_unifi_password | length > 0
|
||||
- checkmk_unifi_password != 'CHANGEME'
|
||||
fail_msg: A real UniFi password is required.
|
||||
quiet: true
|
||||
no_log: true
|
||||
rescue:
|
||||
- name: Checkmk | Explain missing UniFi secret
|
||||
ansible.builtin.fail:
|
||||
msg: Set vault_checkmk_unifi_password in the customer Vault, or override checkmk_unifi_password with
|
||||
a host-specific Vault reference. Empty values and CHANGEME are refused. No secret was logged.
|
||||
@@ -0,0 +1,68 @@
|
||||
---
|
||||
- name: Windows | Ensure Checkmk local directory
|
||||
ansible.windows.win_file:
|
||||
path: '{{ checkmk_windows_local_dir }}'
|
||||
state: directory
|
||||
|
||||
- name: Windows | Ensure Checkmk custom plugin directory
|
||||
ansible.windows.win_file:
|
||||
path: '{{ checkmk_windows_plugin_dir }}'
|
||||
state: directory
|
||||
when: >-
|
||||
{{ _checkmk_selected_scripts
|
||||
| selectattr('destination', 'defined')
|
||||
| selectattr('destination', 'equalto', 'custom_plugin')
|
||||
| list | length > 0 }}
|
||||
|
||||
- name: Windows | Deploy selected monitoring checks
|
||||
ansible.windows.win_copy:
|
||||
src: '{{ item.source }}'
|
||||
dest: >-
|
||||
{{ (checkmk_windows_plugin_dir
|
||||
if item.destination | default('local') == 'custom_plugin'
|
||||
else checkmk_windows_local_dir) }}\{{ item.filename }}
|
||||
loop: '{{ _checkmk_selected_scripts }}'
|
||||
loop_control:
|
||||
label: '{{ item.filename }}'
|
||||
register: _aim_check_copies
|
||||
|
||||
- name: Windows | Normalize ACL on AIM-managed monitoring checks
|
||||
ansible.builtin.include_role:
|
||||
name: checkmk_windows_acl
|
||||
vars:
|
||||
checkmk_windows_acl_paths:
|
||||
- >-
|
||||
{{ (checkmk_windows_plugin_dir
|
||||
if checkmk_acl_script.destination | default('local') == 'custom_plugin'
|
||||
else checkmk_windows_local_dir) }}\{{ checkmk_acl_script.filename }}
|
||||
loop: '{{ _checkmk_selected_scripts }}'
|
||||
loop_control:
|
||||
loop_var: checkmk_acl_script
|
||||
label: '{{ checkmk_acl_script.filename }}'
|
||||
|
||||
- name: Windows | Remove legacy local copies after custom plugin relocation
|
||||
ansible.windows.win_file:
|
||||
path: '{{ checkmk_windows_local_dir }}\{{ item.filename }}'
|
||||
state: absent
|
||||
loop: >-
|
||||
{{ _checkmk_selected_scripts
|
||||
| selectattr('destination', 'defined')
|
||||
| selectattr('destination', 'equalto', 'custom_plugin')
|
||||
| list }}
|
||||
loop_control:
|
||||
label: '{{ item.filename }}'
|
||||
register: _aim_custom_plugin_legacy_local_remove
|
||||
|
||||
- name: Windows | Remove known legacy built-in copies after custom plugin relocation
|
||||
ansible.windows.win_file:
|
||||
path: '{{ checkmk_windows_builtin_plugin_dir }}\{{ item.filename }}'
|
||||
state: absent
|
||||
loop: >-
|
||||
{{ _checkmk_selected_scripts
|
||||
| selectattr('destination', 'defined')
|
||||
| selectattr('destination', 'equalto', 'custom_plugin')
|
||||
| selectattr('filename', 'in', ['veeam_o365_status.ps1', 'veeam_backup_status.ps1'])
|
||||
| list }}
|
||||
loop_control:
|
||||
label: '{{ item.filename }}'
|
||||
register: _aim_custom_plugin_legacy_builtin_remove
|
||||
@@ -0,0 +1,13 @@
|
||||
# Managed by Ansible - checkmk_deploy_scripts. One UniFi variant per host.
|
||||
# Values are POSIX-shell quoted because the monitoring scripts source this file.
|
||||
USERNAME={{ checkmk_unifi_username | quote }}
|
||||
PASSWORD={{ checkmk_unifi_password | quote }}
|
||||
BASEURL={{ checkmk_unifi_baseurl | quote }}
|
||||
CURLOPTS={{ checkmk_unifi_curl_options | quote }}
|
||||
|
||||
# 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN
|
||||
STATUS_PROVISIONING={{ checkmk_unifi_status_provisioning | int }}
|
||||
STATUS_UPGRADING={{ checkmk_unifi_status_upgrading | int }}
|
||||
STATUS_UPGRADABLE={{ checkmk_unifi_status_upgradable | int }}
|
||||
STATUS_HEARTBEAT_MISSED={{ checkmk_unifi_status_heartbeat_missed | int }}
|
||||
STATUS_NOAUTOBACKUP={{ checkmk_unifi_status_noautobackup | int }}
|
||||
Reference in New Issue
Block a user