This commit is contained in:
admin_rb
2026-09-15 21:33:10 +02:00
parent 7c24c7ba7f
commit d095887d2e
118 changed files with 1655 additions and 21 deletions
+64
View File
@@ -0,0 +1,64 @@
---
- name: "Checkmk | Cleanup agent"
hosts: all
gather_facts: true
tasks:
- name: "Windows | Remove installed Checkmk agent"
when: ansible_facts['os_family'] == 'Windows'
ansible.windows.win_powershell:
script: |
$Ansible.Changed = $false
$uninstallRoots = @(
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall'
)
$products = foreach ($root in $uninstallRoots) {
if (Test-Path -LiteralPath $root) {
Get-ChildItem -LiteralPath $root -ErrorAction SilentlyContinue |
ForEach-Object {
$product = Get-ItemProperty -LiteralPath $_.PSPath -ErrorAction SilentlyContinue
if ($product.DisplayName -like 'Check MK Agent*' -or
$product.DisplayName -like 'Checkmk Agent*') {
[PSCustomObject]@{
ProductCode = $_.PSChildName
DisplayName = $product.DisplayName
}
}
}
}
}
foreach ($product in $products) {
if ($product.ProductCode -match '^\{[0-9A-Fa-f-]+\}$') {
$process = Start-Process -FilePath 'msiexec.exe' `
-ArgumentList "/x $($product.ProductCode) /qn /norestart" `
-Wait -PassThru
if ($process.ExitCode -notin @(0, 1605, 1614, 3010)) {
throw "Failed to uninstall $($product.DisplayName). MSI exit code: $($process.ExitCode)"
}
if ($process.ExitCode -in @(0, 3010)) {
$Ansible.Changed = $true
}
}
}
$Ansible.Result = @{
removed_products = @($products.DisplayName)
}
- name: "Debian | Remove Checkmk agent"
when: ansible_facts['os_family'] == 'Debian'
ansible.builtin.apt:
name: check-mk-agent
state: absent
purge: true
- name: "RedHat | Remove Checkmk agent"
when: ansible_facts['os_family'] == 'RedHat'
ansible.builtin.dnf:
name: check-mk-agent
state: absent
+10
View File
@@ -0,0 +1,10 @@
---
- name: "Checkmk | Deploy agent, scripts and configuration"
hosts: all
gather_facts: true
roles:
- checkmk_agent
- server_role_selection
- checkmk_scripts
- checkmk_agent_config
+8
View File
@@ -0,0 +1,8 @@
---
- name: "Checkmk | Update agent configuration"
hosts: all
gather_facts: true
roles:
- server_role_selection
- checkmk_agent_config
+8
View File
@@ -0,0 +1,8 @@
---
- name: "Checkmk | Update monitoring scripts"
hosts: all
gather_facts: true
roles:
- server_role_selection
- checkmk_scripts
+38
View File
@@ -0,0 +1,38 @@
---
- name: "Debug | Disk usage"
hosts: all
gather_facts: true
tasks:
- name: "Linux | Collect filesystem usage"
when: ansible_facts['os_family'] != 'Windows'
ansible.builtin.command:
cmd: df -hP -x tmpfs -x devtmpfs
register: disk_usage_linux
changed_when: false
- name: "Linux | Show filesystem usage"
when: ansible_facts['os_family'] != 'Windows'
ansible.builtin.debug:
var: disk_usage_linux.stdout_lines
- name: "Windows | Collect filesystem drive usage"
when: ansible_facts['os_family'] == 'Windows'
ansible.windows.win_powershell:
script: |
Get-CimInstance Win32_LogicalDisk -Filter "DriveType=3" |
Select-Object DeviceID,
@{Name='SizeGB';Expression={[math]::Round($_.Size / 1GB, 2)}},
@{Name='FreeGB';Expression={[math]::Round($_.FreeSpace / 1GB, 2)}},
@{Name='UsedPercent';Expression={
if ($_.Size -gt 0) {
[math]::Round((($_.Size - $_.FreeSpace) / $_.Size) * 100, 1)
} else { 0 }
}}
register: disk_usage_windows
changed_when: false
- name: "Windows | Show filesystem drive usage"
when: ansible_facts['os_family'] == 'Windows'
ansible.builtin.debug:
var: disk_usage_windows.output
+13
View File
@@ -0,0 +1,13 @@
---
- name: "Debug | Ping hosts"
hosts: all
gather_facts: false
tasks:
- name: "Windows | WinRM ping"
when: ansible_connection | default('') == 'winrm'
ansible.windows.win_ping:
- name: "Linux | Ansible ping"
when: ansible_connection | default('ssh') != 'winrm'
ansible.builtin.ping:
+87
View File
@@ -0,0 +1,87 @@
---
- name: "Debug | Server Role Selection"
hosts: all
gather_facts: true
roles:
- server_role_selection
tasks:
- name: "Debug | Display detected server roles"
ansible.builtin.debug:
msg:
host: "{{ inventory_hostname }}"
os_family: "{{ ansible_facts['os_family'] | default('unknown') }}"
windows_roles:
domain_controller: "{{ is_dc | default(false) | bool }}"
dhcp_server: "{{ is_dhcp_server | default(false) | bool }}"
hyperv_host: "{{ is_hyperv_host | default(false) | bool }}"
veeam:
vbr: "{{ has_veeam_vbr | default(false) | bool }}"
vbo: "{{ has_veeam_vbo | default(false) | bool }}"
enterprise_manager: "{{ has_veeam_em | default(false) | bool }}"
linux_roles:
unifi_controller: "{{ is_unifi_controller | default(false) | bool }}"
optional_features:
linux_certificate_check: "{{ want_linux_check_certificate | default(false) | bool }}"
windows_citrix: "{{ want_windows_citrix | default(false) | bool }}"
windows_surebackup: "{{ want_windows_surebackup | default(false) | bool }}"
windows_backup: "{{ want_windows_backup | default(false) | bool }}"
- name: "Debug | Display Checkmk script deployment decisions"
ansible.builtin.debug:
msg:
linux:
unifi_controller:
deploy: "{{ is_unifi_controller | default(false) | bool }}"
reason: "UniFi Controller detected"
scripts:
- "check_unifi-controller.sh"
- "unifi.cfg"
certificate_directory:
deploy: "{{ want_linux_check_certificate | default(false) | bool }}"
reason: "Certificate directory monitoring explicitly enabled"
scripts:
- "check_certificate_directory.sh"
windows:
check_ping:
deploy: "{{ is_dc | default(false) | bool }}"
reason: "Domain Controller"
scripts:
- "check-ping.ps1"
veeam_config_backup:
deploy: "{{ has_veeam_vbr | default(false) | bool }}"
reason: "Veeam Backup & Replication detected"
scripts:
- "veeam_config_backup_status.ps1"
veeam_o365:
deploy: "{{ has_veeam_vbo | default(false) | bool }}"
reason: "Veeam Backup for Microsoft 365 detected"
scripts:
- "veeam_o365_status.ps1"
citrix_sessions:
deploy: "{{ want_windows_citrix | default(false) | bool }}"
reason: "Citrix monitoring explicitly enabled"
scripts:
- "citrix_sessions_customized.ps1"
veeam_surebackup:
deploy: "{{ want_windows_surebackup | default(false) | bool }}"
reason: "Veeam SureBackup monitoring explicitly enabled"
scripts:
- "veeam_surebackup_status.ps1"
windows_backup:
deploy: "{{ want_windows_backup | default(false) | bool }}"
reason: "Windows Backup monitoring explicitly enabled"
scripts:
- "windows-backup.ps1"
@@ -0,0 +1,74 @@
---
- name: "Maintenance | Backup system logs"
hosts: all
gather_facts: true
vars:
windows_event_log_backup_dir: 'C:\\Windows\\Temp\\EventLogBackup'
windows_event_logs_to_backup:
- Application
- System
- Security
linux_log_backup_dir: /var/backups/system-logs
linux_journal_since: "-24h"
tasks:
- name: "Windows | Ensure event log backup directory exists"
when: ansible_facts['os_family'] == 'Windows'
ansible.windows.win_file:
path: "{{ windows_event_log_backup_dir }}"
state: directory
- name: "Windows | Export event logs"
when: ansible_facts['os_family'] == 'Windows'
ansible.windows.win_command: >-
wevtutil epl {{ item }} "{{ windows_event_log_backup_dir }}\\{{ item }}.evtx" /ow:true
loop: "{{ windows_event_logs_to_backup }}"
changed_when: true
- name: "Linux | Ensure system log backup directory exists"
when: ansible_facts['os_family'] != 'Windows'
become: true
ansible.builtin.file:
path: "{{ linux_log_backup_dir }}"
state: directory
owner: root
group: root
mode: "0750"
- name: "Linux | Check whether systemd journal is available"
when: ansible_facts['os_family'] != 'Windows'
ansible.builtin.command:
cmd: journalctl --version
register: journalctl_available
changed_when: false
failed_when: false
- name: "Linux | Export systemd journal"
when:
- ansible_facts['os_family'] != 'Windows'
- journalctl_available.rc == 0
become: true
ansible.builtin.shell: >-
journalctl --since {{ linux_journal_since | quote }} --no-pager
> {{ (linux_log_backup_dir ~ '/journal.log') | quote }}
args:
executable: /bin/sh
changed_when: true
- name: "Linux | Backup traditional system logs"
when:
- ansible_facts['os_family'] != 'Windows'
- journalctl_available.rc != 0
become: true
ansible.builtin.shell: |
set -e
for file in /var/log/syslog /var/log/messages /var/log/auth.log /var/log/secure; do
if [ -f "$file" ]; then
cp -p "$file" "{{ linux_log_backup_dir }}/$(basename "$file")"
fi
done
args:
executable: /bin/sh
changed_when: true
+35
View File
@@ -0,0 +1,35 @@
---
- name: "Maintenance | Patch operating system"
hosts: all
gather_facts: true
tasks:
- name: "Debian | Update package cache and upgrade packages"
when: ansible_facts['os_family'] == 'Debian'
ansible.builtin.apt:
update_cache: true
upgrade: dist
- name: "RedHat | Upgrade installed packages"
when: ansible_facts['os_family'] == 'RedHat'
ansible.builtin.dnf:
name: '*'
state: latest
- name: "Windows | Install available updates"
when: ansible_facts['os_family'] == 'Windows'
ansible.windows.win_updates:
category_names:
- CriticalUpdates
- SecurityUpdates
- UpdateRollups
- Updates
reboot: false
register: windows_updates
- name: "Windows | Report reboot requirement"
when:
- ansible_facts['os_family'] == 'Windows'
- windows_updates.reboot_required | default(false)
ansible.builtin.debug:
msg: "Windows updates were installed and a reboot is required. No reboot was performed."
+15
View File
@@ -0,0 +1,15 @@
---
- name: "Maintenance | Reboot systems"
hosts: all
gather_facts: true
tasks:
- name: "Windows | Reboot system"
when: ansible_facts['os_family'] == 'Windows'
ansible.windows.win_reboot:
reboot_timeout: 1800
- name: "Linux | Reboot system"
when: ansible_facts['os_family'] != 'Windows'
ansible.builtin.reboot:
reboot_timeout: 1800
@@ -0,0 +1,82 @@
---
- name: "Maintenance | Start stopped automatic services"
hosts: all
gather_facts: true
tasks:
- name: "Windows | Start stopped automatic services"
when: ansible_facts['os_family'] == 'Windows'
ansible.windows.win_powershell:
script: |
$Ansible.Changed = $false
$started = @()
Get-CimInstance Win32_Service |
Where-Object {
$_.StartMode -eq 'Auto' -and
$_.State -ne 'Running'
} |
ForEach-Object {
try {
Start-Service -Name $_.Name -ErrorAction Stop
$started += $_.Name
$Ansible.Changed = $true
}
catch {
Write-Warning "Could not start service $($_.Name): $($_.Exception.Message)"
}
}
$Ansible.Result = @{
started_services = $started
}
register: started_services_windows
- name: "Windows | Show started services"
when: ansible_facts['os_family'] == 'Windows'
ansible.builtin.debug:
var: started_services_windows.result.started_services
- name: "Linux | Collect service facts"
when: ansible_facts['os_family'] != 'Windows'
ansible.builtin.service_facts:
- name: "Linux | Start stopped enabled systemd services"
when:
- ansible_facts['os_family'] != 'Windows'
- ansible_facts['service_mgr'] == 'systemd'
- item.value.status | default('') == 'enabled'
- item.value.state | default('') != 'running'
become: true
ansible.builtin.systemd:
name: "{{ item.key }}"
state: started
loop: "{{ ansible_facts.services | dict2items }}"
loop_control:
label: "{{ item.key }}"
register: started_services_linux
failed_when: false
- name: "Linux | Show services that were started"
when:
- ansible_facts['os_family'] != 'Windows'
- ansible_facts['service_mgr'] == 'systemd'
ansible.builtin.debug:
msg: >-
{{
started_services_linux.results
| default([])
| selectattr('changed', 'defined')
| selectattr('changed')
| map(attribute='item.key')
| list
}}
- name: "Linux | Report unsupported service manager"
when:
- ansible_facts['os_family'] != 'Windows'
- ansible_facts['service_mgr'] != 'systemd'
ansible.builtin.debug:
msg: >-
Automatic stopped-service recovery currently supports systemd hosts only.
Detected service manager: {{ ansible_facts['service_mgr'] }}