aim-web2.1.0rc9

This commit is contained in:
admin_rb
2026-09-22 19:23:17 +02:00
parent d095887d2e
commit 3dfc80b782
438 changed files with 31613 additions and 1510 deletions
+72
View File
@@ -0,0 +1,72 @@
# AIM 3.3.0rc8 release notes
3.3.0rc8 is a focused Windows Checkmk ACL hardening release on top of the final rc7 script-placement baseline. AIM-managed persistent Checkmk files now remain readable/manageable by the standard local administrative principals even when created by a service account.
## Windows Checkmk managed-file ACLs
After AIM creates or updates a persistent Windows Checkmk script or `check_mk.user.yml`, the reusable `checkmk_windows_acl` role enables parent ACL inheritance and guarantees these locale-independent well-known SID entries:
- SYSTEM (`S-1-5-18`): FullControl
- local Administrators (`S-1-5-32-544`): FullControl
- ALL APPLICATION PACKAGES (`S-1-15-2-1`): ReadAndExecute
- ALL RESTRICTED APPLICATION PACKAGES (`S-1-15-2-2`): ReadAndExecute
AIM does not add a customer-specific administrator/user ACE such as the example `bitformer` account. ACL normalization is per exact AIM-managed file; it does not recurse through Checkmk directories or modify unknown/operator files. Existing intentional inherited/explicit ACEs are not blindly purged.
## Final Windows Checkmk script placement
`citrix_sessions_customized.ps1`, `veeam_o365_status.ps1`, and `veeam_backup_status.ps1` are now consistently deployed as Checkmk custom plugins under `C:\ProgramData\checkmk\agent\plugins` (`$CUSTOM_PLUGINS_PATH$`). Their managed execution rules use the custom-plugin path; AIM no longer needs to overwrite Checkmk's built-in plugin tree. `veeam_backup_license_status.ps1` is added as a VBR-detected local check under `$CUSTOM_LOCAL_PATH$`. Selected plugin deployment removes only known historical AIM copies from the old local/built-in locations; unknown files remain untouched.
## Windows disk facts
- `debug_show_disk_usage` now uses `community.windows.win_disk_facts` instead of a custom `Get-PSDrive` PowerShell collector.
- Windows results represent attached local volumes. Mapped/network drives are intentionally outside this host-capacity report.
- `filesystem_usage_v1` is unchanged, so existing add-on renderers do not need a schema migration.
Baseline: complete AIM 3.3.0rc8 replacement bundle. Service/wire/event API remains 1.0 and canonical Ansible Core remains 2.19.11.
## Native-module audit
This candidate reviews the complete bundled playbook/role tree with a native-module-first rule: if the supported Ansible runtime already exposes the required semantics, AIM delegates to that module instead of maintaining its own shell/PowerShell implementation.
Changes made:
- Windows pending-reboot detection now uses `ansible.windows.win_reboot_info` and publishes its bounded reboot sources instead of AIM-maintained registry heuristics.
- `checkmk_read_windows_config` now uses `ansible.windows.win_stat` plus `ansible.windows.slurp`; no PowerShell is used to stat/read the file.
- Debian and RedHat package before/after snapshots use `ansible.builtin.package_facts` instead of direct `dpkg-query`/`rpm -qa` commands.
- Linux Checkmk installed-package reporting uses `package_facts`; Linux Checkmk runtime state reporting uses `service_facts` instead of `dpkg-query`/`rpm` and `systemctl show` for the final report.
- Core/service and terminal dependency preflights now reject `ansible.windows` older than 3.8.0 before a playbook can rely on `win_reboot_info`.
## Collection baseline change
`ansible.windows.win_reboot_info` was introduced in ansible.windows 3.8.0. The release requirements therefore declare:
```yaml
- name: ansible.windows
version: ">=3.8.0,<4.0.0"
```
Existing controllers that still have ansible.windows 3.2.x must deliberately update the collection before accepting rc8. AIM still does not install or upgrade collections automatically.
## Reboot-state behavior
The Windows preflight now trusts the collection's reboot detector, which covers Windows Update, Component Based Servicing, pending file rename, pending computer rename, domain join and Server Manager sources. The public patch report can include `reboot_reasons_before` entries containing bounded `source` and `description` fields.
Overall patch-wave/reboot policy is unchanged from rc4: one native `win_updates` wave, AIM-controlled reboot message/delay, and no post-reboot patch wave unless `os_patching_rescan_after_reboot` was explicitly enabled.
## Reviewed custom operations intentionally retained
The audit did not replace custom code where a native module would lose required behavior:
- Windows disk reporting now uses `community.windows.win_disk_facts` and reports attached local storage volumes. Mapped/network drives are intentionally excluded from Windows host-capacity reporting.
- Windows event-log export keeps a bounded `win_powershell` wrapper around the native Windows event export utility because the supported collection does not provide EVTX export with the required time filter.
- Checkmk's Windows `plugins:` section editor remains custom because AIM must preserve every unmanaged section/comment while replacing only its marked section.
- Windows Checkmk installed-version discovery retains a bounded read-only uninstall-registry query because no supported module exposes arbitrary installed MSI/application inventory with the required product matching semantics.
- RedHat reboot-required checks retain `needs-restarting -r`; no supported ansible-core module exposes that host state.
- Linux Checkmk unit discovery retains `systemctl show LoadState` because AIM supports socket activation and `service_facts` is service-oriented and is not a reliable replacement for arbitrary socket-unit existence discovery.
- pfSense's two `raw sysctl` operations remain intentionally bootstrap-safe and do not add a Python/runtime dependency merely to replace two appliance-native calls.
This is therefore a native-first policy, not a prohibition on all commands.
All AIM-owned Markdown/JSON documentation is centralized under `scripts/docs/`. The release no longer owns the installation-root `README.md`; an existing root README is preserved during update.