aim-web2.1.0rc9

This commit is contained in:
admin_rb
2026-09-22 19:23:17 +02:00
parent d095887d2e
commit 3dfc80b782
438 changed files with 31613 additions and 1510 deletions
@@ -0,0 +1,40 @@
# UniFi mode replacement is the explicitly approved exception to separate cleanup.
# Unknown files and the active UniFi check are never removed here.
- name: Linux | Ensure local check directory
ansible.builtin.file:
path: '{{ checkmk_linux_local_dir }}'
state: directory
mode: '0755'
- name: Linux | Ensure configuration directory
ansible.builtin.file:
path: '{{ checkmk_linux_config_dir }}'
state: directory
mode: '0755'
- name: Linux | Write the single UniFi configuration
ansible.builtin.template:
src: unifi.cfg.j2
dest: '{{ checkmk_linux_config_dir }}/unifi.cfg'
owner: root
group: root
mode: '0600'
validate: /bin/sh -n %s
when: _checkmk_unifi_effective in ['network','os']
no_log: true
diff: false
register: _aim_unifi_write
- name: Linux | Deploy selected monitoring checks
ansible.builtin.copy:
src: '{{ item.source }}'
dest: '{{ checkmk_linux_local_dir }}/{{ item.filename }}'
mode: '0755'
loop: '{{ _checkmk_selected_scripts }}'
loop_control:
label: '{{ item.filename }}'
register: _aim_check_copies
- name: Linux | Remove only the opposite UniFi local check
ansible.builtin.file:
path: "{{ checkmk_linux_local_dir }}/{{ 'check_unifi-controller.sh' if _checkmk_unifi_effective == 'os' else
'check_unifi-os.sh' }}"
state: absent
when: _checkmk_unifi_effective in ['network','os']
register: _aim_opposite_remove
@@ -0,0 +1,10 @@
---
- name: Checkmk | Validate controller sources and required parameters
ansible.builtin.import_tasks: preflight.yml
- name: Checkmk | Deploy linux checks
ansible.builtin.include_tasks: linux.yml
when: ansible_facts.os_family != 'Windows'
- name: Checkmk | Deploy windows checks
ansible.builtin.include_tasks: windows.yml
when: ansible_facts.os_family == 'Windows'
@@ -0,0 +1,57 @@
---
- name: Checkmk | Inspect selected controller script sources
ansible.builtin.stat:
path: '{{ item.source }}'
delegate_to: localhost
become: false
loop: '{{ _checkmk_selected_scripts }}'
loop_control:
label: '{{ item.filename }}'
register: _checkmk_sources
- name: Checkmk | Require selected controller files
ansible.builtin.assert:
that:
- item.stat.exists | default(false)
- item.stat.isreg | default(false)
fail_msg: A selected monitoring script is missing on the controller. Sync the monitoring repository first.
quiet: true
loop: '{{ _checkmk_sources.results }}'
loop_control:
label: '{{ item.item.filename }}'
- name: Checkmk | Validate UniFi public settings
ansible.builtin.assert:
that:
- checkmk_unifi_username is string
- checkmk_unifi_username | length > 0
- checkmk_unifi_baseurl is match('^https?://[^\s]+$')
- checkmk_unifi_curl_options is string
- checkmk_unifi_status_provisioning | int in [0,1,2,3]
- checkmk_unifi_status_upgrading | int in [0,1,2,3]
- checkmk_unifi_status_upgradable | int in [0,1,2,3]
- checkmk_unifi_status_heartbeat_missed | int in [0,1,2,3]
- checkmk_unifi_status_noautobackup | int in [0,1,2,3]
fail_msg: Invalid UniFi username, base URL, curl options or status mapping.
quiet: true
when:
- ansible_facts.os_family != 'Windows'
- _checkmk_unifi_effective in ['network','os']
- name: Checkmk | Require a real UniFi monitoring password
when:
- ansible_facts.os_family != 'Windows'
- _checkmk_unifi_effective in ['network','os']
block:
- name: Checkmk | Validate secret
ansible.builtin.assert:
that:
- checkmk_unifi_password is string
- checkmk_unifi_password | length > 0
- checkmk_unifi_password != 'CHANGEME'
fail_msg: A real UniFi password is required.
quiet: true
no_log: true
rescue:
- name: Checkmk | Explain missing UniFi secret
ansible.builtin.fail:
msg: Set vault_checkmk_unifi_password in the customer Vault, or override checkmk_unifi_password with
a host-specific Vault reference. Empty values and CHANGEME are refused. No secret was logged.
@@ -0,0 +1,68 @@
---
- name: Windows | Ensure Checkmk local directory
ansible.windows.win_file:
path: '{{ checkmk_windows_local_dir }}'
state: directory
- name: Windows | Ensure Checkmk custom plugin directory
ansible.windows.win_file:
path: '{{ checkmk_windows_plugin_dir }}'
state: directory
when: >-
{{ _checkmk_selected_scripts
| selectattr('destination', 'defined')
| selectattr('destination', 'equalto', 'custom_plugin')
| list | length > 0 }}
- name: Windows | Deploy selected monitoring checks
ansible.windows.win_copy:
src: '{{ item.source }}'
dest: >-
{{ (checkmk_windows_plugin_dir
if item.destination | default('local') == 'custom_plugin'
else checkmk_windows_local_dir) }}\{{ item.filename }}
loop: '{{ _checkmk_selected_scripts }}'
loop_control:
label: '{{ item.filename }}'
register: _aim_check_copies
- name: Windows | Normalize ACL on AIM-managed monitoring checks
ansible.builtin.include_role:
name: checkmk_windows_acl
vars:
checkmk_windows_acl_paths:
- >-
{{ (checkmk_windows_plugin_dir
if checkmk_acl_script.destination | default('local') == 'custom_plugin'
else checkmk_windows_local_dir) }}\{{ checkmk_acl_script.filename }}
loop: '{{ _checkmk_selected_scripts }}'
loop_control:
loop_var: checkmk_acl_script
label: '{{ checkmk_acl_script.filename }}'
- name: Windows | Remove legacy local copies after custom plugin relocation
ansible.windows.win_file:
path: '{{ checkmk_windows_local_dir }}\{{ item.filename }}'
state: absent
loop: >-
{{ _checkmk_selected_scripts
| selectattr('destination', 'defined')
| selectattr('destination', 'equalto', 'custom_plugin')
| list }}
loop_control:
label: '{{ item.filename }}'
register: _aim_custom_plugin_legacy_local_remove
- name: Windows | Remove known legacy built-in copies after custom plugin relocation
ansible.windows.win_file:
path: '{{ checkmk_windows_builtin_plugin_dir }}\{{ item.filename }}'
state: absent
loop: >-
{{ _checkmk_selected_scripts
| selectattr('destination', 'defined')
| selectattr('destination', 'equalto', 'custom_plugin')
| selectattr('filename', 'in', ['veeam_o365_status.ps1', 'veeam_backup_status.ps1'])
| list }}
loop_control:
label: '{{ item.filename }}'
register: _aim_custom_plugin_legacy_builtin_remove