aim-web2.1.0rc9
This commit is contained in:
@@ -0,0 +1,16 @@
|
||||
# checkmk_windows_acl
|
||||
|
||||
Normalizes access on AIM-managed persistent Windows Checkmk files without recursively
|
||||
changing Checkmk directories or unknown/operator files.
|
||||
|
||||
The role enables parent ACL inheritance and guarantees locale-independent well-known
|
||||
principals by SID:
|
||||
|
||||
- SYSTEM (`S-1-5-18`): FullControl
|
||||
- local Administrators (`S-1-5-32-544`): FullControl
|
||||
- ALL APPLICATION PACKAGES (`S-1-15-2-1`): ReadAndExecute
|
||||
- ALL RESTRICTED APPLICATION PACKAGES (`S-1-15-2-2`): ReadAndExecute
|
||||
|
||||
AIM does not add customer-specific administrator/user ACEs. Existing intentional parent
|
||||
or explicit ACEs are not blindly purged. Pass persistent AIM-owned file paths through
|
||||
`checkmk_windows_acl_paths`.
|
||||
@@ -0,0 +1,15 @@
|
||||
---
|
||||
# Locale-independent well-known SIDs used by the native Checkmk Windows tree.
|
||||
checkmk_windows_managed_acl_entries:
|
||||
- sid: S-1-5-18
|
||||
rights: FullControl
|
||||
description: SYSTEM
|
||||
- sid: S-1-5-32-544
|
||||
rights: FullControl
|
||||
description: Local Administrators
|
||||
- sid: S-1-15-2-1
|
||||
rights: ReadAndExecute
|
||||
description: ALL APPLICATION PACKAGES
|
||||
- sid: S-1-15-2-2
|
||||
rights: ReadAndExecute
|
||||
description: ALL RESTRICTED APPLICATION PACKAGES
|
||||
@@ -0,0 +1,30 @@
|
||||
---
|
||||
- name: Windows ACL | Validate managed paths
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- checkmk_windows_acl_paths is defined
|
||||
- checkmk_windows_acl_paths is sequence
|
||||
- checkmk_windows_acl_paths is not string
|
||||
- checkmk_windows_acl_paths | length > 0
|
||||
fail_msg: checkmk_windows_acl_paths must contain one or more AIM-managed Windows files.
|
||||
quiet: true
|
||||
|
||||
- name: Windows ACL | Ensure managed files inherit parent permissions
|
||||
ansible.windows.win_acl_inheritance:
|
||||
path: '{{ item }}'
|
||||
state: present
|
||||
reorganize: true
|
||||
loop: '{{ checkmk_windows_acl_paths }}'
|
||||
loop_control:
|
||||
label: '{{ item }}'
|
||||
|
||||
- name: Windows ACL | Ensure Checkmk-style administrative and application access
|
||||
ansible.windows.win_acl:
|
||||
path: '{{ item.0 }}'
|
||||
user: '{{ item.1.sid }}'
|
||||
rights: '{{ item.1.rights }}'
|
||||
type: allow
|
||||
state: present
|
||||
loop: '{{ checkmk_windows_acl_paths | product(checkmk_windows_managed_acl_entries) | list }}'
|
||||
loop_control:
|
||||
label: '{{ item.0 }} | {{ item.1.description }}'
|
||||
Reference in New Issue
Block a user