aim-web2.1.0rc9
This commit is contained in:
@@ -0,0 +1,268 @@
|
||||
# Changelog
|
||||
|
||||
## 3.3.0rc8
|
||||
|
||||
- Normalize ACLs on persistent AIM-managed Windows Checkmk scripts and `check_mk.user.yml` after creation/update.
|
||||
- Re-enable parent ACL inheritance per managed file and guarantee locale-independent well-known principals by SID: SYSTEM and local Administrators with FullControl; ALL APPLICATION PACKAGES and ALL RESTRICTED APPLICATION PACKAGES with ReadAndExecute.
|
||||
- Do not add customer-specific administrator/user ACEs and do not recursively rewrite Checkmk directories or unknown/operator files. Existing intentional parent/explicit ACEs are not blindly purged.
|
||||
- Add the reusable `checkmk_windows_acl` role and apply it only to the exact AIM-managed persistent file paths.
|
||||
- Keep Checkmk script placement, structured-result contracts, service/wire/event API 1.0, and Ansible Core 2.19.11 unchanged.
|
||||
|
||||
## 3.3.0rc7
|
||||
|
||||
- Move `veeam_o365_status.ps1` from the Windows Checkmk local-check directory to `C:\ProgramData\checkmk\agent\plugins`.
|
||||
- If an earlier rc7 build placed that file under the Checkmk built-in plugin directory, selected deployment removes that known stale copy after the custom plugin is staged.
|
||||
- Add the exact `$CUSTOM_PLUGINS_PATH$\veeam_o365_status.ps1` execution rule when Veeam VBO is detected, ahead of the built-in plugin deny catch-all.
|
||||
- Remove the legacy AIM-managed local copy after selected deployment and teach explicit cleanup to remove the current custom-plugin path plus both known legacy locations without touching unknown files.
|
||||
- Keep Checkmk public structured-result schemas and service/wire/event API 1.0 unchanged.
|
||||
|
||||
- Replaced the Windows disk-usage PowerShell/Get-PSDrive collector with `community.windows.win_disk_facts`; Windows capacity reports now describe attached local volumes and intentionally exclude mapped/network drives.
|
||||
- Kept the public `filesystem_usage_v1` result schema stable while normalizing native disk/partition/volume facts into the existing fields.
|
||||
|
||||
- Audited the complete playbook/role tree for native Ansible module coverage.
|
||||
- Replaced custom Windows pending-reboot registry probing with `ansible.windows.win_reboot_info` and added bounded reboot-source reporting.
|
||||
- Raised the supported ansible.windows baseline to >=3.8.0,<4.0.0 and added explicit readiness/terminal version checks.
|
||||
- Replaced Checkmk Windows config file shell reads with `win_stat` + `slurp`.
|
||||
- Replaced Linux package snapshot/version commands with `package_facts` and Linux Checkmk final service-state command reporting with `service_facts`.
|
||||
- Documented reviewed custom command/PowerShell/raw call sites that remain because native modules do not preserve the required behavior.
|
||||
|
||||
## 3.3.0rc3
|
||||
|
||||
- Change Windows OS patching from one broad `win_updates` install request to an explicit discovery queue with one update installed per invocation. The queue is deterministic and places drivers last.
|
||||
- Add Windows-only catalog option `os_patching_rescan_after_reboot` (`false` by default). A patch-triggered reboot ends the run by default; post-reboot discovery/install continuation requires explicit operator opt-in.
|
||||
- Preserve one operator-approved patch wave per run by default. A completed reboot boundary reports `continuation_required: true` and does not perform a post-reboot search unless continuation was enabled.
|
||||
- After a wave completes without reboot, perform one read-only final discovery for reporting only; do not append newly applicable updates to the already-approved install queue.
|
||||
- Expand `patch_summary_v1` with Windows patch-cycle/continuation facts and bounded per-update HRESULT classification. `0x80240016` is reported as `install_not_allowed`, not treated as proof of a reboot.
|
||||
- Stop the Windows wave on an individual update failure, publish already completed updates plus the bounded failure, and never replay the update/job automatically.
|
||||
- Keep reboot notification/delay, Linux patching, service/wire/event API 1.0, Ansible Core 2.19.11 and the generic operation-result transport unchanged.
|
||||
- Native Windows controller acceptance of the sequential queue and post-reboot continuation remains required before stable promotion.
|
||||
|
||||
## 3.3.0rc2
|
||||
|
||||
- Improve OS patch reboot handling without changing Core API/wire/event 1.0: expose a cross-platform reboot delay (minutes) and reboot notification message through catalog metadata.
|
||||
- Windows patching now disables win_updates implicit reboot and uses an explicit win_reboot so the configured message/delay is honored; Linux uses the corresponding reboot module message/delay semantics.
|
||||
- Detect a pre-existing pending reboot before starting new patch work where the platform provides a supported signal. If automatic reboot is disabled, publish a structured blocked patch result and fail with an explicit reboot-required message instead of a generic later fatal.
|
||||
- When a patch run newly requires reboot and automatic reboot is disabled, keep the successful update run successful but report reboot_required/reboot_deferred in patch_summary_v1. A later run remains blocked until the host is rebooted.
|
||||
- Extend patch_summary_v1 with pre/post/deferred reboot facts, configured delay and a typed preexisting_reboot_required block reason; package/update reporting remains unchanged.
|
||||
- Add the current fresh-install INSTALLATION.md to the consolidated documentation set.
|
||||
- Native Windows/Linux controller acceptance for these rc2 patching changes remains pending; see VALIDATION.md and SANITY.md.
|
||||
|
||||
## 3.2.1rc2 - inventory hierarchy, split-home staging and per-target outcomes
|
||||
|
||||
- Adds read-only `inventory_hierarchy` discovery with nested parent/subgroup relationships and direct host membership. The public tree exposes group names/paths and host names only; variables remain private and execution still requires explicit reviewed host names.
|
||||
- Corrects controller staging preflight for hardened executors whose process `$HOME` differs from the execution account passwd home. Core now probes controller `local_tmp` using the process/config home and the default delegated `connection: local` POSIX temp path using the passwd/NSS account home. No home, permission or service-unit mutation is performed.
|
||||
- Adds additive `target_outcome_summary_v1` data to every execution `RunResult`. Overall Core status/exit semantics remain unchanged; consumers receive requested-target accounting plus per-target `successful`, `failed`, `unreachable`, `not_started` or `indeterminate` outcomes derived from native final host stats.
|
||||
- Target summaries are available in both summary and detail progress modes and do not require consumers to reconstruct task events. Incomplete/cancelled execution without final stats never fabricates target success.
|
||||
- Keeps service/wire/event API 1.0, canonical Ansible Core 2.19.11, credentials, playbooks, roles, WinRM and remote execution semantics unchanged. This is an additive discovery/readiness/result candidate.
|
||||
|
||||
## 3.2.1rc1 - controller staging preflight and hardened-executor default
|
||||
|
||||
- Makes a writable, private controller staging directory an always-checked service requirement. Readiness and execution validate staging before credentials/native runtime inspection, with a second check before playbook launch. Failures return fixed readiness errors rather than late delegated-task unreachable results.
|
||||
- Adds protected `staging_check` / `AimService.staging_check()` and `aimctl staging-check`, plus additive capability/readiness fields. No credentials, customer inventory or native Ansible command is needed for the local probe.
|
||||
- Performs real create/write/flush/read/remove operations under the current UID and sandbox, bounded to ten seconds. Missing directories are privately created; existing permissions, owners and contents are never repaired or purged.
|
||||
- Preserves native controller temporary configuration and remote-host settings. Checks the default POSIX local-connection staging path; explicitly warns when global remote_tmp overrides or inventory-specific settings are outside probe coverage.
|
||||
- Establishes the generic add-on deployment default: provision private staging, append a directory-specific ReadWritePaths exception and an in-sandbox startup check while retaining ProtectHome/ProtectSystem/PrivateTmp/NoNewPrivileges. Core never edits independent service units or add-on code.
|
||||
- Records operator confirmation that the narrow staging exception allowed the Checkmk service job to install successfully on a Windows 11 client. New candidate acceptance and detailed-progress/other-target qualification remain separate.
|
||||
- Keeps API/wire/event 1.0, Ansible Core 2.19.11, existing roles/playbooks, WinRM, credentials, terminal behavior and deployment logic unchanged. Full replacement ZIP plus checksum; no patches or bundled validators.
|
||||
|
||||
## 3.2.0 - safe detailed execution progress
|
||||
|
||||
- Adds optional `progress_mode: detail` to the stable service/wire/event 1.0 contract. The default `summary` mode retains anonymous progress and existing consumers. Capabilities advertise `play_task_host_v1`; clients opt in before requesting it.
|
||||
- Detailed events expose plays, no-host skips, tasks/handlers, per-host outcomes, retry/poll notices and recaps, with run/play/task correlation. Native first-party terminal output remains unchanged.
|
||||
- Uses bounded unexpanded source labels, explicit reviewed host names and fixed diagnostic hints. Suppresses unsafe/template/no_log labels and protected result details; never forwards raw stdout/stderr, module arguments, variable/config dumps, exception fields or loop-item payloads.
|
||||
- Revalidates native frames, sequences and recap totals before public emission. Missing, incomplete, malformed or over-limit detailed progress cannot silently become a successful result. No automatic replay or rollback of remote work is introduced.
|
||||
- Keeps Ansible Core 2.19.11 canonical, external execution disabled by default, and existing credential/ownership/deployment policies. No playbook, role, WinRM helper, inventory, key, add-on or deployment behavior is changed.
|
||||
- Updates release notes, additive API contract, support metadata, renderer guidance and the controller acceptance checklist. Local tests use simulated Ansible callbacks/CLIs; new detailed execution still requires native controller/target acceptance.
|
||||
|
||||
## 3.1.0 - accepted service-v1 baseline
|
||||
|
||||
- Promotes the controller-accepted 3.0.0rc21 candidate to the stable 3.1.0 minor release without changing playbook, role, credential, WinRM, Checkmk, deployment, or service behavior.
|
||||
- Freezes AIM service/wire/event API **1.0** for additive 1.x evolution. AIM continues to ship the built-in terminal plus `aimctl`; add-ons consume only the documented service boundary.
|
||||
- Records real-controller acceptance of Windows 11 terminal management, Vault retry behavior, group/subgroup select-all, launcher deployment, `aimctl` discovery/preparation, and native Ansible Core 2.19.11 readiness.
|
||||
- External non-interactive execution remains disabled by default and requires separate acceptance by the chosen add-on/runtime identity. Unsupported boundaries remain unchanged: cross-UID execution, forced Custom password override, private-key export, API inventory/Vault mutation, raw sensitive task output, and automatic replay after remote work may have started.
|
||||
- Release delivery remains a complete replacement ZIP plus SHA-256 sidecar; no Git, `.patch`, release manifest, or bundled development validator is used.
|
||||
|
||||
## 3.0.0rc21 - launcher symlink deployment hotfix
|
||||
|
||||
- Fixes the rc20 ZIP deployer rejecting an existing `/usr/local/bin/aim` symlink before it could refresh the installed `aim` and `aimctl` launchers.
|
||||
- Allows only recognized existing AIM launcher symlinks at the final launcher path; symlinked parent directories, broken links, non-regular targets, and unrecognized launcher contents remain rejected.
|
||||
- Deployment now backs up the symlink itself, atomically replaces it with the managed launcher, verifies `aim` and `aimctl`, and restores the original symlink target during rollback.
|
||||
- No service API, terminal workflow, playbook, role, WinRM, Checkmk, credential, or remote-execution behavior changes from rc20. Service API / wire / event remain 1.0 and Ansible Core 2.19.11 remains canonical.
|
||||
- Records the operator-observed rc20 deployment failure as the regression target. Local disposable testing passed dry-run, symlink replacement, installed command verification, and rollback restoration.
|
||||
|
||||
## 3.0.0rc20 - terminal stabilization and stable services v1 handoff
|
||||
|
||||
- Adds interface-supplied, operation-scoped Vault unlock/retry before terminal Vault edits, reads and normal catalog playbook launches. A rejected password keeps the selected workflow. Empty/invalid input re-prompts; Ctrl+C cancels. Only the native Vault decryption rejection from a bounded local `ansible-vault view` preflight is retried, never an editor or launched playbook.
|
||||
- Reuses the private same-UID password-client channel for the validated operation: no password in argv/environment/helper contents and no second Vault prompt after successful prevalidation. Terminal Vault-password input preserves literal whitespace. Legacy internal manager callers without terminal interaction retain native prompts. Additional/inline Vault files are not exhaustively prevalidated; late failures are never automatically replayed. Vault create/new-encryption prompts remain native.
|
||||
- Adds "Select all hosts in this group/subgroup" versus individual selection after group selection. Parent scopes include descendant subgroups; overlapping memberships are deduplicated. Execution still uses explicit host names and the existing final run review/confirmation.
|
||||
- ZIP deployment now installs/refreshes and smoke-tests both `aim` and `aimctl` launchers with the existing AIM Python, without pip, dependency installation or changes to the Ansible environment. Adds `--aim-python` and `--bin-dir`, conservative interpreter discovery, previewed launcher changes and launcher recovery alongside source recovery. Unknown commands/symlinks are refused. A separate target requires its own explicit command directory.
|
||||
- Returns safe `invalid_target` and `invalid_options` service errors for known validation failures; actual inaccessible/invalid source remains `source_invalid`. Error-code fallback remains required for v1 clients.
|
||||
- Adds optional `credential_requirement_reasons` to prepared results and advertises `credential_requirements_policy`. A present conventional customer Vault remains conservatively required even with `require_vault: false`; this is not a claim of full effective-variable credential analysis.
|
||||
- Freezes the documented service/wire/event 1.0 contract as the supported additive 1.x boundary. AIM keeps its built-in terminal and machine client; internal managers remain private. No add-on source or interface framework is required.
|
||||
- Records operator-reported rc19 Windows 11 terminal onboarding/service-account authentication, targeting, interruption, metadata/prepare and native 2.19.11 readiness results separately from rc20 local regression evidence and pending controller re-tests. External execution remains opt-in/disabled by default; neither readiness nor CLI success proves the non-interactive execution path.
|
||||
- Updates add-on guidelines, API/support contract, deployment instructions, `RC20_SANITY_TESTS.md` and `RC20_HANDOFF.md`. No WinRM/Checkmk/other remote playbook or role behavior is changed. No Git/patches/release manifest/development validators are shipped.
|
||||
|
||||
## 3.0.0rc19 - independent add-on service foundation and ZIP deployment
|
||||
|
||||
- Adds `aim.services.v1`, `aimctl` and a source-tree machine wrapper. Generic API/wire/event version 1.0; no add-on/web-framework imports or need to inspect an add-on codebase.
|
||||
- Adds capabilities, authorized metadata reads, typed explicit-host/catalog preparation, bounded known-source revisions, local readiness and opt-in same-UID native Ansible execution. Shared target validation now protects direct CLI manager calls as well as the UI.
|
||||
- Establishes **ansible-core 2.19.11** as the canonical supported runtime, separately from the AIM/add-on Python environments. Native sibling CLI identity and required collections are checked without installation side effects.
|
||||
- Adds private one-run credential providers, inherited credential-FD support, native executable password sources and safe progress/results. Keeps native inventory/Vault precedence: supplied connection/become passwords are defaults, not a forced Custom override. Existing terminal `@prompt` behavior is retained; `--ask-vault-pass` is also interactive and does not solve unattended input.
|
||||
- Adds bounded Vault preflight, owned per-run SSH agents/process groups, cancellation and conservative remote-work reporting. Unencrypted keys no longer require a Vault passphrase. CLI agent probing rejects stale sockets and no longer transports key passphrases through environment values.
|
||||
- Preserves owner/group/mode/attributes before atomic replacements, including inventory/configuration/Vault publication and restore paths. Existing non-root shared-group writers retain their legacy owner-transfer exception with a warning; full managed single-writer ownership is not claimed.
|
||||
- Makes cooperative customer locks persistent and reentrant instead of unlinking their inode. Extends locking across key/Vault/config mutations and playbook execution. Direct shell edits and arbitrary external writers remain outside advisory-lock guarantees.
|
||||
- Adds optional `runtime.private_key_owner` for new keys only, with exclusive staged keypair publication. Does not rename keys, change remote `service_user`, re-own existing keys, switch UIDs or migrate permissions automatically.
|
||||
- Adds the operator-approved standard-library `deploy/deploy.py`, dry-run-first source replacement, explicit quiescence and protected source recovery. Delivers a ZIP plus SHA-256 sidecar without Git, patches, release manifests or bundled development validators. Existing aim.yml, add-ons/runtime state, inventories/Vaults/keys, environments and unknown customer files are preserved.
|
||||
- Publishes `ADDON_AGENTS.md`, `ADDON_API.md`, `ADDON_SUPPORT.md`, `addon-support-v1.json`, and `RC19_HANDOFF.md`. Exposes unsupported capabilities explicitly: Custom overrides, cross-UID launchers, key export, API mutations and raw sensitive task results.
|
||||
- External execution defaults to disabled. Development validation includes real Python/Unix IPC/filesystem/process tests and simulated native CLI contract fixtures, **not** live Ansible 2.19.11, SSH or WinRM acceptance. See the handoff for evidence and controller gates.
|
||||
- No Checkmk task/template, WinRM bootstrap or remote configuration behavior was changed. The earlier question about a remote Checkmk configuration backup remains separate and unimplemented.
|
||||
|
||||
## 3.0.0rc18 - Checkmk Windows config parser hotfix
|
||||
|
||||
- Fixes the `checkmk_configure_agent` Windows plugins-section update task failing during Ansible argument parsing before reaching the managed host.
|
||||
- Removes an unmatched apostrophe from an embedded `win_shell` PowerShell comment; Ansible free-form shell argument parsing still scans quote characters inside the script text, including comments.
|
||||
- Does not change Checkmk configuration behavior: AIM still replaces only the marked top-level `plugins:` section and preserves all other `check_mk.user.yml` content.
|
||||
|
||||
## 3.0.0rc17 - read-only Windows Checkmk configuration inspection
|
||||
|
||||
- Adds `checkmk_read_windows_config.yml`, a read-only Windows playbook that displays the current `check_mk.user.yml` without changing the host.
|
||||
- Reports the resolved configuration path, file size, UTC last-write timestamp, and complete current file contents; a missing file is reported without failing or creating it.
|
||||
- Adds an optional `checkmk_windows_user_cfg` path override for nonstandard agent layouts while retaining `C:\ProgramData\checkmk\agent\check_mk.user.yml` as the default.
|
||||
- Exposes the operation in the AIM Checkmk catalog and documents it as a safe pre/post-rollout inspection tool.
|
||||
- Uses the standard Windows shell path rather than `win_powershell`, keeping this inspection operation usable on legacy PowerShell 4 hosts such as Windows Server 2012 R2.
|
||||
|
||||
## 3.0.0rc16 - section-scoped Checkmk user configuration
|
||||
|
||||
- Changes Windows `check_mk.user.yml` handling from full-file rendering to section-scoped editing. AIM now replaces or appends only the top-level `plugins:` section.
|
||||
- Preserves existing `global`, `winperf`, `fileinfo`, `logwatch`, `local`, `mrpe`, unknown top-level sections, and unrelated comments instead of resetting them to AIM defaults.
|
||||
- Keeps an AIM ownership notice on the first line and adds a dedicated ownership comment immediately before the AIM-managed `plugins:` section so the management boundary is explicit.
|
||||
- Removes the rc15 `checkmk_manage_local_execution` / `checkmk_extra_local_patterns` rollout controls: local-check execution is no longer managed by this role at all. Existing local execution policy is preserved.
|
||||
- Preserves existing MRPE configuration instead of writing `mrpe.config: []`.
|
||||
- Retains the existing AIM plugin execution ordering and role-based plugin rules; unknown local/plugin files remain untouched.
|
||||
- Existing hosts already overwritten by an earlier full-file rollout cannot have lost settings reconstructed automatically; restore those settings from the host's previous configuration/backup if needed, then rc16 will preserve them on subsequent runs.
|
||||
|
||||
## 3.0.0rc15 - Checkmk local execution inheritance hotfix
|
||||
|
||||
- Fixes Windows Checkmk user configuration generation so `checkmk_manage_local_execution: false` omits the `local` section instead of writing `local: {}`.
|
||||
- This preserves the effective local-check execution policy inherited from Checkmk default/bakery configuration and prevents custom files in `C:\ProgramData\checkmk\agent\local` from becoming non-executable merely because AIM rendered the user configuration.
|
||||
- When `checkmk_manage_local_execution: true`, AIM now explicitly writes `local.enabled: true` together with the managed `local.execution` rules.
|
||||
- Does not change Checkmk script-file ownership: unknown local/plugin files remain untouched, while known AIM-managed filenames may still be replaced.
|
||||
- The Checkmk user configuration file remains fully rendered by AIM in this hotfix; merge-preserving ownership of arbitrary pre-existing user-config keys is a separate design change.
|
||||
|
||||
## 3.0.0rc14 - clean replacement bundle layout
|
||||
|
||||
- Changed release packaging to a complete replacement/fresh-install model instead of shipping patch/merge deployment mechanics.
|
||||
- Removed `release-manifest.json`, release updater/deployer tooling, bundled release-validation tooling, historical migration guides, `.patch` artifacts, and generated Python caches from the distributable archive.
|
||||
- Moved the controller-wide AIM configuration from `/etc/ansible/aim.yml` to `/etc/ansible/scripts/aim.yml` and included a clean default `scripts/aim.yml` in the bundle.
|
||||
- Moved the maintained one-time WinRM bootstrap helper to `scripts/AIM-WinRM-OneTime.ps1`.
|
||||
- Retained operational documentation, changelog, playbooks, roles, collection requirements, and the complete AIM application source required for a new installation.
|
||||
|
||||
|
||||
## 3.0.0rc13 - forgiving WinRM password prompts
|
||||
|
||||
- Temporary/bootstrap WinRM credentials are validated before the requested Windows access operation begins.
|
||||
- A failed WinRM credential probe now re-prompts for the password instead of consuming/skipping the host operation. Ctrl+C still cancels normally.
|
||||
- Empty temporary passwords are re-prompted instead of failing the workflow.
|
||||
- Service-account password entry now loops on empty values or confirmation mismatches instead of aborting back to the menu.
|
||||
- Introduces a dedicated `WinRMConnectionFailed` error so only an actual WinRM probe failure triggers credential re-entry; missing commands and unrelated controller errors still fail normally.
|
||||
|
||||
## 3.0.0rc12 - Windows Server 2012 R2 WinRM certificate hotfix
|
||||
|
||||
- Fixes `New-SelfSignedCertificate` on Windows Server 2012 R2 / PowerShell 4 systems that expose `-CertStoreLocation` but reject `Cert:\LocalMachine\My` with `InvalidStorePathException`.
|
||||
- Certificate creation now retries only that specific failure from inside `Cert:\LocalMachine\My`, preserving normal behavior and error reporting on newer Windows versions.
|
||||
- Keeps capability detection for optional `-FriendlyName` and `-TextExtension` parameters and applies the friendly name after creation when required.
|
||||
- Adds `scripts/tools/AIM-WinRM-OneTime.ps1` as the maintained standalone one-time WinRM HTTPS bootstrap script using the same compatibility logic.
|
||||
- Adds top-level `AGENTS.md` as the authoritative development/release/compatibility guideline for continued AIM development.
|
||||
|
||||
## 3.0.0rc11 - Windows local host_vars credential-model repair hotfix
|
||||
|
||||
- `Prepare local account` now inspects every selected host's `host_vars/<fqdn>/main.yml` before prompting for credentials.
|
||||
- Empty legacy host-vars files and partial overrides are explicitly identified as incomplete when `ansible_user` or `ansible_password` is missing/blank.
|
||||
- The operator chooses the desired local credential model: shared-local, host-specific local, or retain complete existing overrides.
|
||||
- `Retain existing` is rejected while any selected host has incomplete credential overrides, preventing a successful account bootstrap from leaving an unusable empty/partial host-vars file behind.
|
||||
- After the local account bootstrap and independent WinRM verification succeed, AIM reapplies the selected shared-local or host-specific model to `host_vars`, preserving unrelated custom variables/comments.
|
||||
|
||||
## 3.0.0rc10 - legacy inventory consolidation/template comments hotfix
|
||||
|
||||
- Template consolidation now creates missing platform `group_vars/<platform>/` directories and `main.yml` files, matching the existing preview message instead of silently skipping absent parent directories.
|
||||
- Existing group-vars values/custom variables remain non-destructively preserved; malformed YAML continues to be skipped rather than repaired implicitly.
|
||||
- Windows shared-local and host-specific credential overrides now write a clear AIM ownership/context comment as the first line of `host_vars/<host>/main.yml`.
|
||||
- Template validation/consolidation also detects older AIM local-credential `host_vars/<host>/main.yml` files that lack that header and adds it without changing existing credential values or custom variables.
|
||||
- Switching a host back to the domain credential model removes only AIM's known local-credential header while preserving unrelated custom comments/keys.
|
||||
|
||||
## 3.0.0rc9 - Standalone Windows WinRM local-admin hotfix
|
||||
|
||||
- `Prepare local account` now idempotently sets `LocalAccountTokenFilterPolicy=1` before the service-account WinRM verification.
|
||||
- Keeps the existing bare `svc_bf-ansible` username behavior because that is known to work once remote UAC token filtering is disabled.
|
||||
- Domain-account and domain-GPO behavior are unchanged.
|
||||
- The GPO WinRM payload retains direct `Get-NetIPAddress` discovery and optional additional SANs for Hyper-V/complex networking cases.
|
||||
|
||||
## 3.0.0rc8 - Consolidation permission handling hotfix
|
||||
|
||||
- Treat existing shared inventory mode `0660` as already correct and avoid redundant chmod attempts.
|
||||
- Template consolidation uses best-effort permission normalization after a successful content update.
|
||||
- `EPERM`/`EACCES` during consolidation permission normalization is reported as a warning instead of failing the operation.
|
||||
- Security-sensitive permission operations outside template consolidation remain strict.
|
||||
|
||||
|
||||
## 3.0.0rc7 - WinRM certificate compatibility hotfix
|
||||
|
||||
- Makes the generated `AIM-WinRM-Setup.ps1` compatible with PKI cmdlet implementations that do not expose `New-SelfSignedCertificate -TextExtension` and/or `-FriendlyName`.
|
||||
- Builds the certificate call from the parameters actually supported by the target host. The base `-DnsName` + `CertStoreLocation` path remains an SSL server certificate; the explicit Server Authentication EKU extension is added when `TextExtension` is available.
|
||||
- Applies the `WinRM` friendly name after creation when it could not be supplied as a cmdlet parameter, preserving AIM's existing certificate-reuse behavior.
|
||||
- Does not change listener, firewall, GPO link, scheduled-task timing, service-account or access-policy behavior.
|
||||
|
||||
## 3.0.0rc6 - coordinated playbook/role migration candidate
|
||||
|
||||
- Adds top-level `Multi-customer operations` next to `Open customer`; it is never launched from inside a customer context.
|
||||
- Adds multi-customer catalog playbook execution with per-customer `hosts.yml` target selection, shared typed run options and one isolated Ansible invocation per customer.
|
||||
- Runs selected customers sequentially, keeps native Ansible/Vault/password prompts live, continues with the next customer after an ordinary playbook failure, and stops the remaining batch when the operator interrupts the current command.
|
||||
- Adds clear per-customer live-output separators and a final summary with target counts, result and duration, plus failure/skip details.
|
||||
- Keeps customer-specific inventories, Vault IDs, SSH preparation and target limits isolated; inventories are never merged.
|
||||
- Changes multi-select `a` into a filter-aware toggle: when all currently matching items are selected it clears them; otherwise it selects all currently matching items. Selections outside the active filter are unchanged.
|
||||
|
||||
## 3.0.0rc5 - coordinated playbook/role migration candidate
|
||||
|
||||
- Stores the controller-wide Checkmk agent source as structured settings in `/etc/ansible/aim.yml`: protocol, base URL/host, site name, version, patchlevel and revision. AIM always appends `/check_mk/agents` and builds the package version as `<version>p<patchlevel>-<revision>`. Legacy complete URL/version settings are migrated in memory and normalized on the next save.
|
||||
- Moves `Save settings` to the bottom of the Settings menu.
|
||||
- Adds `a` to every multi-select selector to select all items matching the current filter (across all filtered pages).
|
||||
|
||||
## 3.0.0rc4 - coordinated playbook/role migration candidate
|
||||
|
||||
- Expanded `debug_show_disk_usage` to Windows and Linux. Windows reports all filesystem drives visible to the WinRM session; Linux reports common operational mounts and network/storage filesystems while excluding pseudo/system mounts.
|
||||
|
||||
Breaking source layout / entrypoint changes from AIM 2.2.2. AIM and its catalog,
|
||||
playbooks and roles must be installed together. No legacy wrappers are shipped.
|
||||
|
||||
- Introduces `playbooks/aim_catalog.yml` with descriptions, targets, dependencies,
|
||||
risk notices and typed, opt-in run parameters. Unchanged inputs remain inherited.
|
||||
- Standardizes runnable names as `<category>_<verb>_<purpose>.yml`; retains standard
|
||||
role entrypoints such as `tasks/main.yml` and `defaults/main.yml`.
|
||||
- Removes the deprecated `gebhardt` customer playbook and empty `_sample` role.
|
||||
- Preserves firewall task arguments/order and per-customer policy identities;
|
||||
extracts reusable role entrypoints and adds preflight validation.
|
||||
- Adds `aim_debug` for selected diagnostics without enabling `ANSIBLE_DEBUG` or
|
||||
disabling secret protections. Normal reports remain visible.
|
||||
- Routes AlmaLinux/Rocky through RedHat-family patching; does not install an
|
||||
alternate Python interpreter automatically.
|
||||
- Repairs optional Windows Checkmk YAML generation, configurable variable
|
||||
precedence, and installed-but-stopped agent service handling.
|
||||
- Adds known monitoring-script selections and a single managed UniFi configuration
|
||||
with Vault-backed password references, safe shell quoting and mode-specific URLs.
|
||||
- Keeps removal of the opposite UniFi check during mode replacement; other cleanup
|
||||
is a separately approved preview/delete operation.
|
||||
- Preserves existing controller maintenance, GPO/WinRM provisioning, UI styling,
|
||||
pagination and inventory/SSH/Vault paths.
|
||||
- Adds guarded source-only migration and controller-side validation tools.
|
||||
- Updates the migration guard so operator-approved differences in `scripts/` and `requirements.yml` are backed up and replaced instead of blocking deployment; playbook/role mismatch protection remains strict.
|
||||
- Adopts the operator-provided unpinned collection baseline and includes `pfsensible.core`.
|
||||
- Uses staged-role isolation for syntax checks so refactored playbooks cannot accidentally validate against old live roles.
|
||||
|
||||
See the migration document for intentionally changed behavior and verification limits.
|
||||
|
||||
### Final rc7 Checkmk/script classification hotfix
|
||||
- Classify `citrix_sessions_customized.ps1`, `veeam_o365_status.ps1`, and `veeam_backup_status.ps1` as AIM-managed Checkmk custom plugins under `$CUSTOM_PLUGINS_PATH$` (`C:\ProgramData\checkmk\agent\plugins`).
|
||||
- Add `veeam_backup_license_status.ps1` as a VBR-detected Windows local check under `$CUSTOM_LOCAL_PATH$`.
|
||||
- Stop enabling the Veeam backup status file from `$BUILTIN_PLUGINS_PATH$`; its exact managed rule now targets `$CUSTOM_PLUGINS_PATH$` and follows `want_windows_veeam_backup`.
|
||||
- Selected custom-plugin deployment removes only known legacy AIM copies from the local directory, plus known historic built-in copies for Veeam O365/backup status.
|
||||
- Centralize AIM documentation under `scripts/docs/`. The deployment source no longer owns or replaces the installation-root `README.md`.
|
||||
Reference in New Issue
Block a user