aim-web2.1.0rc9

This commit is contained in:
admin_rb
2026-09-22 19:23:17 +02:00
parent d095887d2e
commit 3dfc80b782
438 changed files with 31613 additions and 1510 deletions
+48
View File
@@ -0,0 +1,48 @@
# checkmk_deploy_scripts
Operator defaults are intentionally low-precedence; inventory and explicit run options may override them.
```yaml
---
# unifi.cfg is role-managed and replaced, mode 0600. Password comes from Vault.
# An absent/CHANGEME password fails before deployment; no credentials are logged.
checkmk_linux_plugin_dir: /usr/lib/check_mk_agent/plugins
checkmk_linux_local_dir: /usr/lib/check_mk_agent/local
checkmk_linux_config_dir: /etc/check_mk
checkmk_windows_plugin_dir: C:\ProgramData\checkmk\agent\plugins
checkmk_windows_builtin_plugin_dir: C:\Program Files (x86)\checkmk\service\plugins
checkmk_windows_local_dir: C:\ProgramData\checkmk\agent\local
checkmk_monitoring_scripts_dir: '{{ lookup(''ansible.builtin.env'', ''AIM_CHECKMK_MONITORING_SCRIPTS_DIR'')
| default(''/etc/checkmk_monitoring_scripts'', true) }}'
checkmk_windows_scripts_dir: '{{ checkmk_monitoring_scripts_dir }}/Scripts Windows'
checkmk_linux_scripts_dir: '{{ checkmk_monitoring_scripts_dir }}/Scripts Linux'
checkmk_unifi_mode: auto
want_linux_check_certificate: false
want_windows_citrix: false
want_windows_surebackup: false
want_windows_backup: false
want_windows_nsp_mailqueue: false
want_windows_certificate: false
want_windows_veeam_cloud_connect: false
want_windows_veeam_backup: false
checkmk_unifi_username: bf-monitoring
checkmk_unifi_password: '{{ vault_checkmk_unifi_password | default('''') }}'
checkmk_unifi_baseurl: '{{ ''https://127.0.0.1:11443'' if _checkmk_unifi_effective == ''os'' else ''https://127.0.0.1:8443''
}}'
checkmk_unifi_curl_options: ' --insecure --tlsv1.2'
checkmk_unifi_status_provisioning: 1
checkmk_unifi_status_upgrading: 1
checkmk_unifi_status_upgradable: 0
checkmk_unifi_status_heartbeat_missed: 1
checkmk_unifi_status_noautobackup: 0
```
`unifi.cfg` is generated from the supplied schema, POSIX-shell quoted, mode `0600`, and protected with `no_log` and `diff: false`. Use a Vault reference for the password. `CHANGEME` and empty passwords fail before deployment. The active UniFi mode replaces the alternative local check. Other obsolete scripts are removed only by explicit cleanup.
## Structured result integration
Current reporting behavior and field semantics are specified in
[scripts/docs/OPERATION_RESULTS.md](../../scripts/docs/OPERATION_RESULTS.md).
The calling catalog playbook owns publication; helper roles do not implicitly export
arbitrary facts, module results or debug data. Existing defaults above retain their
precedence. See the current validation/sanity documents before using the new candidate.
@@ -0,0 +1,32 @@
---
# unifi.cfg is role-managed and replaced, mode 0600. Password comes from Vault.
# An absent/CHANGEME password fails before deployment; no credentials are logged.
checkmk_linux_plugin_dir: /usr/lib/check_mk_agent/plugins
checkmk_linux_local_dir: /usr/lib/check_mk_agent/local
checkmk_linux_config_dir: /etc/check_mk
checkmk_windows_plugin_dir: C:\ProgramData\checkmk\agent\plugins
checkmk_windows_builtin_plugin_dir: C:\Program Files (x86)\checkmk\service\plugins
checkmk_windows_local_dir: C:\ProgramData\checkmk\agent\local
checkmk_monitoring_scripts_dir: '{{ lookup(''ansible.builtin.env'', ''AIM_CHECKMK_MONITORING_SCRIPTS_DIR'')
| default(''/etc/checkmk_monitoring_scripts'', true) }}'
checkmk_windows_scripts_dir: '{{ checkmk_monitoring_scripts_dir }}/Scripts Windows'
checkmk_linux_scripts_dir: '{{ checkmk_monitoring_scripts_dir }}/Scripts Linux'
checkmk_unifi_mode: auto
want_linux_check_certificate: false
want_windows_citrix: false
want_windows_surebackup: false
want_windows_backup: false
want_windows_nsp_mailqueue: false
want_windows_certificate: false
want_windows_veeam_cloud_connect: false
want_windows_veeam_backup: false
checkmk_unifi_username: bf-monitoring
checkmk_unifi_password: '{{ vault_checkmk_unifi_password | default('''') }}'
checkmk_unifi_baseurl: '{{ ''https://127.0.0.1:11443'' if _checkmk_unifi_effective == ''os'' else ''https://127.0.0.1:8443''
}}'
checkmk_unifi_curl_options: ' --insecure --tlsv1.2'
checkmk_unifi_status_provisioning: 1
checkmk_unifi_status_upgrading: 1
checkmk_unifi_status_upgradable: 0
checkmk_unifi_status_heartbeat_missed: 1
checkmk_unifi_status_noautobackup: 0
@@ -0,0 +1,40 @@
# UniFi mode replacement is the explicitly approved exception to separate cleanup.
# Unknown files and the active UniFi check are never removed here.
- name: Linux | Ensure local check directory
ansible.builtin.file:
path: '{{ checkmk_linux_local_dir }}'
state: directory
mode: '0755'
- name: Linux | Ensure configuration directory
ansible.builtin.file:
path: '{{ checkmk_linux_config_dir }}'
state: directory
mode: '0755'
- name: Linux | Write the single UniFi configuration
ansible.builtin.template:
src: unifi.cfg.j2
dest: '{{ checkmk_linux_config_dir }}/unifi.cfg'
owner: root
group: root
mode: '0600'
validate: /bin/sh -n %s
when: _checkmk_unifi_effective in ['network','os']
no_log: true
diff: false
register: _aim_unifi_write
- name: Linux | Deploy selected monitoring checks
ansible.builtin.copy:
src: '{{ item.source }}'
dest: '{{ checkmk_linux_local_dir }}/{{ item.filename }}'
mode: '0755'
loop: '{{ _checkmk_selected_scripts }}'
loop_control:
label: '{{ item.filename }}'
register: _aim_check_copies
- name: Linux | Remove only the opposite UniFi local check
ansible.builtin.file:
path: "{{ checkmk_linux_local_dir }}/{{ 'check_unifi-controller.sh' if _checkmk_unifi_effective == 'os' else
'check_unifi-os.sh' }}"
state: absent
when: _checkmk_unifi_effective in ['network','os']
register: _aim_opposite_remove
@@ -0,0 +1,10 @@
---
- name: Checkmk | Validate controller sources and required parameters
ansible.builtin.import_tasks: preflight.yml
- name: Checkmk | Deploy linux checks
ansible.builtin.include_tasks: linux.yml
when: ansible_facts.os_family != 'Windows'
- name: Checkmk | Deploy windows checks
ansible.builtin.include_tasks: windows.yml
when: ansible_facts.os_family == 'Windows'
@@ -0,0 +1,57 @@
---
- name: Checkmk | Inspect selected controller script sources
ansible.builtin.stat:
path: '{{ item.source }}'
delegate_to: localhost
become: false
loop: '{{ _checkmk_selected_scripts }}'
loop_control:
label: '{{ item.filename }}'
register: _checkmk_sources
- name: Checkmk | Require selected controller files
ansible.builtin.assert:
that:
- item.stat.exists | default(false)
- item.stat.isreg | default(false)
fail_msg: A selected monitoring script is missing on the controller. Sync the monitoring repository first.
quiet: true
loop: '{{ _checkmk_sources.results }}'
loop_control:
label: '{{ item.item.filename }}'
- name: Checkmk | Validate UniFi public settings
ansible.builtin.assert:
that:
- checkmk_unifi_username is string
- checkmk_unifi_username | length > 0
- checkmk_unifi_baseurl is match('^https?://[^\s]+$')
- checkmk_unifi_curl_options is string
- checkmk_unifi_status_provisioning | int in [0,1,2,3]
- checkmk_unifi_status_upgrading | int in [0,1,2,3]
- checkmk_unifi_status_upgradable | int in [0,1,2,3]
- checkmk_unifi_status_heartbeat_missed | int in [0,1,2,3]
- checkmk_unifi_status_noautobackup | int in [0,1,2,3]
fail_msg: Invalid UniFi username, base URL, curl options or status mapping.
quiet: true
when:
- ansible_facts.os_family != 'Windows'
- _checkmk_unifi_effective in ['network','os']
- name: Checkmk | Require a real UniFi monitoring password
when:
- ansible_facts.os_family != 'Windows'
- _checkmk_unifi_effective in ['network','os']
block:
- name: Checkmk | Validate secret
ansible.builtin.assert:
that:
- checkmk_unifi_password is string
- checkmk_unifi_password | length > 0
- checkmk_unifi_password != 'CHANGEME'
fail_msg: A real UniFi password is required.
quiet: true
no_log: true
rescue:
- name: Checkmk | Explain missing UniFi secret
ansible.builtin.fail:
msg: Set vault_checkmk_unifi_password in the customer Vault, or override checkmk_unifi_password with
a host-specific Vault reference. Empty values and CHANGEME are refused. No secret was logged.
@@ -0,0 +1,68 @@
---
- name: Windows | Ensure Checkmk local directory
ansible.windows.win_file:
path: '{{ checkmk_windows_local_dir }}'
state: directory
- name: Windows | Ensure Checkmk custom plugin directory
ansible.windows.win_file:
path: '{{ checkmk_windows_plugin_dir }}'
state: directory
when: >-
{{ _checkmk_selected_scripts
| selectattr('destination', 'defined')
| selectattr('destination', 'equalto', 'custom_plugin')
| list | length > 0 }}
- name: Windows | Deploy selected monitoring checks
ansible.windows.win_copy:
src: '{{ item.source }}'
dest: >-
{{ (checkmk_windows_plugin_dir
if item.destination | default('local') == 'custom_plugin'
else checkmk_windows_local_dir) }}\{{ item.filename }}
loop: '{{ _checkmk_selected_scripts }}'
loop_control:
label: '{{ item.filename }}'
register: _aim_check_copies
- name: Windows | Normalize ACL on AIM-managed monitoring checks
ansible.builtin.include_role:
name: checkmk_windows_acl
vars:
checkmk_windows_acl_paths:
- >-
{{ (checkmk_windows_plugin_dir
if checkmk_acl_script.destination | default('local') == 'custom_plugin'
else checkmk_windows_local_dir) }}\{{ checkmk_acl_script.filename }}
loop: '{{ _checkmk_selected_scripts }}'
loop_control:
loop_var: checkmk_acl_script
label: '{{ checkmk_acl_script.filename }}'
- name: Windows | Remove legacy local copies after custom plugin relocation
ansible.windows.win_file:
path: '{{ checkmk_windows_local_dir }}\{{ item.filename }}'
state: absent
loop: >-
{{ _checkmk_selected_scripts
| selectattr('destination', 'defined')
| selectattr('destination', 'equalto', 'custom_plugin')
| list }}
loop_control:
label: '{{ item.filename }}'
register: _aim_custom_plugin_legacy_local_remove
- name: Windows | Remove known legacy built-in copies after custom plugin relocation
ansible.windows.win_file:
path: '{{ checkmk_windows_builtin_plugin_dir }}\{{ item.filename }}'
state: absent
loop: >-
{{ _checkmk_selected_scripts
| selectattr('destination', 'defined')
| selectattr('destination', 'equalto', 'custom_plugin')
| selectattr('filename', 'in', ['veeam_o365_status.ps1', 'veeam_backup_status.ps1'])
| list }}
loop_control:
label: '{{ item.filename }}'
register: _aim_custom_plugin_legacy_builtin_remove
@@ -0,0 +1,13 @@
# Managed by Ansible - checkmk_deploy_scripts. One UniFi variant per host.
# Values are POSIX-shell quoted because the monitoring scripts source this file.
USERNAME={{ checkmk_unifi_username | quote }}
PASSWORD={{ checkmk_unifi_password | quote }}
BASEURL={{ checkmk_unifi_baseurl | quote }}
CURLOPTS={{ checkmk_unifi_curl_options | quote }}
# 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN
STATUS_PROVISIONING={{ checkmk_unifi_status_provisioning | int }}
STATUS_UPGRADING={{ checkmk_unifi_status_upgrading | int }}
STATUS_UPGRADABLE={{ checkmk_unifi_status_upgradable | int }}
STATUS_HEARTBEAT_MISSED={{ checkmk_unifi_status_heartbeat_missed | int }}
STATUS_NOAUTOBACKUP={{ checkmk_unifi_status_noautobackup | int }}