This commit is contained in:
admin_rb
2026-09-15 21:33:10 +02:00
parent 7c24c7ba7f
commit d095887d2e
118 changed files with 1655 additions and 21 deletions
+9
View File
@@ -0,0 +1,9 @@
---
checkmk_linux_tmp_path: "/tmp"
checkmk_windows_tmp_path: "C:\\Windows\\Temp"
checkmk_deb_filename: "check-mk-agent.deb"
checkmk_rpm_filename: "check-mk-agent.rpm"
checkmk_msi_filename: "check_mk_agent.msi"
checkmk_linux_socket_name: "check-mk-agent.socket"
checkmk_linux_service_name: "check-mk-agent"
checkmk_windows_service_name: "CheckMkService"
+5
View File
@@ -0,0 +1,5 @@
Place the Checkmk agent packages here:
- `check-mk-agent.deb`
- `check-mk-agent.rpm`
- `check_mk_agent.msi`
Binary file not shown.
Binary file not shown.
Binary file not shown.
+55
View File
@@ -0,0 +1,55 @@
---
- name: "Enable & start Checkmk socket (if present)"
listen: "checkmk | linux | agent-ensure-running"
when: ansible_facts['os_family'] != "Windows"
ansible.builtin.systemd:
name: "{{ checkmk_linux_socket_name }}"
enabled: true
state: started
daemon_reload: true
failed_when: false
- name: "Enable & start Checkmk service (fallback/if present)"
listen: "checkmk | linux | agent-ensure-running"
when: ansible_facts['os_family'] != "Windows"
ansible.builtin.systemd:
name: "{{ checkmk_linux_service_name }}"
enabled: true
state: started
daemon_reload: true
failed_when: false
- name: "Windows | Detect Checkmk service name"
listen: "checkmk | windows | agent-ensure-running"
when: ansible_facts['os_family'] == "Windows"
ansible.windows.win_powershell:
script: |
$candidates = @('CheckMkService','Check_MK_Agent')
foreach ($n in $candidates) {
$svc = Get-Service -Name $n -ErrorAction SilentlyContinue
if ($svc) { $svc.Name; break }
}
register: cmk_detect
failed_when: false
- name: "Windows | Set detected service name"
listen: "checkmk | windows | agent-ensure-running"
when: ansible_facts['os_family'] == "Windows"
ansible.builtin.set_fact:
cmk_service_name: >-
{{
(cmk_detect.output[0] | default('') | trim)
if (cmk_detect.output | default([]) | length > 0)
else (checkmk_windows_service_name | default('CheckMkService'))
}}
- name: "Windows | Ensure Checkmk agent service running"
listen: "checkmk | windows | agent-ensure-running"
when:
- ansible_facts['os_family'] == "Windows"
- (cmk_service_name | default('')) | length > 0
ansible.windows.win_service:
name: "{{ cmk_service_name }}"
start_mode: auto
state: started
failed_when: false
+6
View File
@@ -0,0 +1,6 @@
---
galaxy_info:
role_name: checkmk_agent
description: Install Checkmk agent from local packages
min_ansible_version: "2.18"
dependencies: []
+11
View File
@@ -0,0 +1,11 @@
---
- name: "Debian | Copy Checkmk agent package"
ansible.builtin.copy:
src: "{{ checkmk_deb_filename }}"
dest: "{{ checkmk_linux_tmp_path }}/{{ checkmk_deb_filename }}"
mode: "0644"
- name: "Debian | Install Checkmk agent"
ansible.builtin.apt:
deb: "{{ checkmk_linux_tmp_path }}/{{ checkmk_deb_filename }}"
notify: "checkmk | linux | agent-ensure-running"
+12
View File
@@ -0,0 +1,12 @@
---
- name: Include Debian installation
ansible.builtin.include_tasks: debian.yml
when: ansible_facts['os_family'] == 'Debian'
- name: Include RedHat installation
ansible.builtin.include_tasks: redhat.yml
when: ansible_facts['os_family'] == 'RedHat'
- name: Include Windows installation
ansible.builtin.include_tasks: windows.yml
when: ansible_facts['os_family'] == 'Windows'
+12
View File
@@ -0,0 +1,12 @@
---
- name: "RedHat | Copy Checkmk agent package"
ansible.builtin.copy:
src: "{{ checkmk_rpm_filename }}"
dest: "{{ checkmk_linux_tmp_path }}/{{ checkmk_rpm_filename }}"
mode: "0644"
- name: "RedHat | Install Checkmk agent"
ansible.builtin.package:
name: "{{ checkmk_linux_tmp_path }}/{{ checkmk_rpm_filename }}"
state: present
notify: "checkmk | linux | agent-ensure-running"
+11
View File
@@ -0,0 +1,11 @@
---
- name: "Windows | Copy Checkmk agent MSI"
ansible.windows.win_copy:
src: "{{ checkmk_msi_filename }}"
dest: "{{ checkmk_windows_tmp_path }}\\{{ checkmk_msi_filename }}"
- name: "Windows | Install Checkmk agent from local MSI"
ansible.windows.win_package:
path: "{{ checkmk_windows_tmp_path }}\\{{ checkmk_msi_filename }}"
state: present
notify: "checkmk | windows | agent-ensure-running"
@@ -0,0 +1,9 @@
---
checkmk_windows_user_cfg: "C:\\ProgramData\\checkmk\\agent\\check_mk.user.yml"
checkmk_windows_updates_timeout: 3600
checkmk_windows_updates_cache: 43200
checkmk_mk_inventory_timeout: 120
checkmk_plugins_default_timeout: 120
checkmk_plugins_default_cache: 600
checkmk_extra_plugin_patterns: []
checkmk_extra_local_patterns: []
+6
View File
@@ -0,0 +1,6 @@
---
galaxy_info:
role_name: checkmk_agent_config
description: Render Windows Checkmk agent configuration from detected server roles
min_ansible_version: "2.18"
dependencies: []
+20
View File
@@ -0,0 +1,20 @@
---
- name: "Debug detected role flags"
when: ansible_facts['os_family'] == "Windows"
ansible.builtin.debug:
msg:
dc: "{{ is_dc | default(false) }}"
dhcp: "{{ is_dhcp_server | default(false) }}"
vbr: "{{ has_veeam_vbr | default(false) }}"
vbo: "{{ has_veeam_vbo | default(false) }}"
em: "{{ has_veeam_em | default(false) }}"
hv: "{{ is_hyperv_host | default(false) }}"
timeout_updates: "{{ checkmk_windows_updates_timeout }}"
- name: "Windows | Render check_mk.user.yml"
when: ansible_facts['os_family'] == "Windows"
ansible.windows.win_template:
src: "windows_check_mk.user.yml.j2"
dest: "{{ checkmk_windows_user_cfg }}"
backup: true
notify: "checkmk | windows | agent-ensure-running"
@@ -0,0 +1,130 @@
# Managed by Ansible (checkmk_agent_config)
# Windows Checkmk Agent user configuration built from detected roles.
# $CUSTOM_PLUGINS_PATH$ -> ProgramData\checkmk\agent\plugins
# $BUILTIN_PLUGINS_PATH$ -> Program Files (x86)\checkmk\service\plugins
# $CUSTOM_AGENT_PATH$ -> ProgramData\checkmk\agent
# $CUSTOM_LOCAL_PATH$ -> ProgramData\checkmk\agent\local
global:
_only_from:
_realtime:
enabled: yes
timeout: 90
port: 6559
encrypted: no
passphrase: this is my password
run:
- mem
- df
- winperf_processor
winperf:
counters:
- MSExchangeTransport Queues: msx_queues
_logfiles:
enabled: no
fileinfo:
path: []
logwatch:
logfile: []
plugins:
execution:
# --- Built-in defaults ---
- pattern: '$BUILTIN_PLUGINS_PATH$\windows_updates.vbs'
run: yes
async: yes
timeout: {{ checkmk_windows_updates_timeout }}
cache_age: {{ checkmk_windows_updates_cache }}
retry_count: 0
- pattern: '$BUILTIN_PLUGINS_PATH$\mk_inventory.vbs'
run: yes
async: yes
timeout: {{ checkmk_mk_inventory_timeout }}
cache_age: 3600
- pattern: '$BUILTIN_PLUGINS_PATH$\mssql.vbs'
run: yes
timeout: {{ checkmk_plugins_default_timeout }}
{% if has_veeam_vbr | default(false) %}
# --- Veeam Backup & Replication ---
- pattern: '$BUILTIN_PLUGINS_PATH$\veeam_backup_status.ps1'
run: yes
async: yes
timeout: {{ checkmk_plugins_default_timeout }}
cache_age: {{ checkmk_plugins_default_cache }}
{% endif %}
{% if is_dc | default(false) %}
# --- Domain Controller ---
- pattern: '$BUILTIN_PLUGINS_PATH$\ad_replication.bat'
run: yes
timeout: {{ checkmk_plugins_default_timeout }}
{% endif %}
{% if is_dhcp_server | default(false) %}
# --- DHCP Server ---
- pattern: '$BUILTIN_PLUGINS_PATH$\win_dhcp_pools.bat'
run: yes
timeout: {{ checkmk_plugins_default_timeout }}
{% endif %}
# --- Generic patterns / precedence ---
- pattern: '$CUSTOM_PLUGINS_PATH$\*.ps1'
run: yes
async: yes
timeout: {{ checkmk_plugins_default_timeout }}
cache_age: {{ checkmk_plugins_default_cache }}
- pattern: '$CUSTOM_PLUGINS_PATH$\*.*'
run: yes
timeout: {{ checkmk_plugins_default_timeout }}
- pattern: '$BUILTIN_PLUGINS_PATH$\*.*'
run: no
timeout: {{ checkmk_plugins_default_timeout }}
- pattern: '*'
run: no
{% for p in (checkmk_extra_plugin_patterns | default([])) %}
- pattern: '{{ p.pattern }}'
{% if p.run is defined %}
run: {{ p.run | bool }}
{% endif %}
{% if p.async is defined %}
async: {{ p.async | bool }}
{% endif %}
{% if p.timeout is defined %}
timeout: {{ p.timeout }}
{% endif %}
{% if p.cache_age is defined %}
cache_age: {{ p.cache_age }}
{% endif %}
{% endfor %}
local:
_execution:
- pattern: '*.*'
run: yes
{% for l in (checkmk_extra_local_patterns | default([])) %}
- pattern: '{{ l.pattern }}'
{% if l.run is defined %}
run: {{ l.run | bool }}
{% endif %}
{% if l.async is defined %}
async: {{ l.async | bool }}
{% endif %}
{% if l.timeout is defined %}
timeout: {{ l.timeout }}
{% endif %}
{% endfor %}
mrpe:
config: []
+12
View File
@@ -0,0 +1,12 @@
---
checkmk_linux_local_dir: "/usr/lib/check_mk_agent/local"
checkmk_linux_config_dir: "/etc/check_mk"
checkmk_windows_local_dir: "C:\\ProgramData\\checkmk\\agent\\local"
checkmk_linux_scripts_dir: "Linux/local"
checkmk_windows_scripts_dir: "Windows/local"
# Optional checks, disabled until explicitly requested
want_linux_check_certificate: false
want_windows_citrix: false
want_windows_surebackup: false
want_windows_backup: false
+16
View File
@@ -0,0 +1,16 @@
Place the actual monitoring scripts in these directories.
Linux/local/
- check_certificate_directory.sh
- check_unifi-controller.sh
- unifi.cfg
Windows/local/
- check-ping.ps1
- citrix_sessions_customized.ps1
- veeam_config_backup_status.ps1
- veeam_o365_status.ps1
- veeam_surebackup_status.ps1
- windows-backup.ps1
The ZIP intentionally does not invent script contents that were not provided.
+6
View File
@@ -0,0 +1,6 @@
---
galaxy_info:
role_name: checkmk_scripts
description: Deploy role-specific Checkmk local monitoring scripts
min_ansible_version: "2.18"
dependencies: []
+36
View File
@@ -0,0 +1,36 @@
---
- name: "Linux | Ensure local dir exists"
ansible.builtin.file:
path: "{{ checkmk_linux_local_dir }}"
state: directory
mode: "0755"
- name: "Linux | Ensure config dir exists"
ansible.builtin.file:
path: "{{ checkmk_linux_config_dir }}"
state: directory
mode: "0755"
- name: "Linux | Deploy UniFi local check"
when: is_unifi_controller | default(false) | bool
ansible.builtin.copy:
src: "{{ checkmk_linux_scripts_dir }}/check_unifi-controller.sh"
dest: "{{ checkmk_linux_local_dir }}/check_unifi-controller.sh"
mode: "0755"
notify: "checkmk | linux | agent-ensure-running"
- name: "Linux | Deploy unifi.cfg"
when: is_unifi_controller | default(false) | bool
ansible.builtin.copy:
src: "{{ checkmk_linux_scripts_dir }}/unifi.cfg"
dest: "{{ checkmk_linux_config_dir }}/unifi.cfg"
mode: "0644"
notify: "checkmk | linux | agent-ensure-running"
- name: "Linux | Deploy certificate directory check"
when: want_linux_check_certificate | default(false) | bool
ansible.builtin.copy:
src: "{{ checkmk_linux_scripts_dir }}/check_certificate_directory.sh"
dest: "{{ checkmk_linux_local_dir }}/check_certificate_directory.sh"
mode: "0755"
notify: "checkmk | linux | agent-ensure-running"
+8
View File
@@ -0,0 +1,8 @@
---
- name: Include Linux monitoring scripts
ansible.builtin.include_tasks: linux.yml
when: ansible_facts['os_family'] != 'Windows'
- name: Include Windows monitoring scripts
ansible.builtin.include_tasks: windows.yml
when: ansible_facts['os_family'] == 'Windows'
+47
View File
@@ -0,0 +1,47 @@
---
- name: "Windows | Ensure local dir exists"
ansible.windows.win_file:
path: "{{ checkmk_windows_local_dir }}"
state: directory
- name: "Windows | Deploy check-ping.ps1 (DC only)"
when: is_dc | default(false) | bool
ansible.windows.win_copy:
src: "{{ checkmk_windows_scripts_dir }}/check-ping.ps1"
dest: "{{ checkmk_windows_local_dir }}\\check-ping.ps1"
notify: "checkmk | windows | agent-ensure-running"
- name: "Windows | Deploy Veeam configuration backup status check (VBR only)"
when: has_veeam_vbr | default(false) | bool
ansible.windows.win_copy:
src: "{{ checkmk_windows_scripts_dir }}/veeam_config_backup_status.ps1"
dest: "{{ checkmk_windows_local_dir }}\\veeam_config_backup_status.ps1"
notify: "checkmk | windows | agent-ensure-running"
- name: "Windows | Deploy veeam_o365_status.ps1 (VBO only)"
when: has_veeam_vbo | default(false) | bool
ansible.windows.win_copy:
src: "{{ checkmk_windows_scripts_dir }}/veeam_o365_status.ps1"
dest: "{{ checkmk_windows_local_dir }}\\veeam_o365_status.ps1"
notify: "checkmk | windows | agent-ensure-running"
- name: "Windows | Deploy Citrix sessions check"
when: want_windows_citrix | default(false) | bool
ansible.windows.win_copy:
src: "{{ checkmk_windows_scripts_dir }}/citrix_sessions_customized.ps1"
dest: "{{ checkmk_windows_local_dir }}\\citrix_sessions_customized.ps1"
notify: "checkmk | windows | agent-ensure-running"
- name: "Windows | Deploy Veeam SureBackup check"
when: want_windows_surebackup | default(false) | bool
ansible.windows.win_copy:
src: "{{ checkmk_windows_scripts_dir }}/veeam_surebackup_status.ps1"
dest: "{{ checkmk_windows_local_dir }}\\veeam_surebackup_status.ps1"
notify: "checkmk | windows | agent-ensure-running"
- name: "Windows | Deploy Windows Backup check"
when: want_windows_backup | default(false) | bool
ansible.windows.win_copy:
src: "{{ checkmk_windows_scripts_dir }}/windows-backup.ps1"
dest: "{{ checkmk_windows_local_dir }}\\windows-backup.ps1"
notify: "checkmk | windows | agent-ensure-running"
@@ -0,0 +1,12 @@
---
ad_ds_feature_name: "AD-Domain-Services"
dhcp_windows_service_name: "DHCPServer"
veeam_services:
vbr: "VeeamBackupSvc"
vbo: "Veeam.Archiver.Service"
em: "VeeamEnterpriseManagerSvc"
unifi_linux_services:
- unifi
- unifi.service
unifi_linux_packages:
- unifi
@@ -0,0 +1,6 @@
---
galaxy_info:
role_name: server_role_selection
description: Detect server roles used for Checkmk deployment decisions
min_ansible_version: "2.18"
dependencies: []
+111
View File
@@ -0,0 +1,111 @@
---
# ==========================
# WINDOWS DETECTION
# ==========================
- name: "Windows | Detect AD DS feature (DC)"
when: ansible_facts['os_family'] == "Windows"
ansible.windows.win_feature_info:
name: "{{ ad_ds_feature_name }}"
register: _win_dc_feature
failed_when: false
- name: "Windows | Fallback: check NTDS service (DC)"
when: ansible_facts['os_family'] == "Windows"
ansible.windows.win_service_info:
name: "NTDS"
register: _win_ntds_svc
failed_when: false
- name: "Windows | Check DHCP service"
when: ansible_facts['os_family'] == "Windows"
ansible.windows.win_service_info:
name: "{{ dhcp_windows_service_name }}"
register: _win_dhcp_svc
failed_when: false
- name: "Windows | Check Veeam VBR service"
when: ansible_facts['os_family'] == "Windows"
ansible.windows.win_service_info:
name: "{{ veeam_services.vbr }}"
register: _veeam_vbr
failed_when: false
- name: "Windows | Check Veeam VBO service"
when: ansible_facts['os_family'] == "Windows"
ansible.windows.win_service_info:
name: "{{ veeam_services.vbo }}"
register: _veeam_vbo
failed_when: false
- name: "Windows | Check Veeam Enterprise Manager service"
when: ansible_facts['os_family'] == "Windows"
ansible.windows.win_service_info:
name: "{{ veeam_services.em }}"
register: _veeam_em
failed_when: false
- name: "Windows | Check Hyper-V service"
when: ansible_facts['os_family'] == "Windows"
ansible.windows.win_service_info:
name: "vmms"
register: _win_hyperv_svc
failed_when: false
- name: "Windows | Set detection booleans"
when: ansible_facts['os_family'] == "Windows"
ansible.builtin.set_fact:
is_dc: >-
{{
(((_win_dc_feature.features | default([])) | selectattr('installed') | list | length) > 0)
or (_win_ntds_svc.exists | default(false))
}}
is_dhcp_server: "{{ _win_dhcp_svc.exists | default(false) }}"
has_veeam_vbr: "{{ _veeam_vbr.exists | default(false) }}"
has_veeam_vbo: "{{ _veeam_vbo.exists | default(false) }}"
has_veeam_em: "{{ _veeam_em.exists | default(false) }}"
is_hyperv_host: "{{ _win_hyperv_svc.exists | default(false) }}"
- name: "Windows | Debug summary"
when: ansible_facts['os_family'] == "Windows"
ansible.builtin.debug:
msg:
is_dc: "{{ is_dc }}"
is_dhcp_server: "{{ is_dhcp_server }}"
has_veeam_vbr: "{{ has_veeam_vbr }}"
has_veeam_vbo: "{{ has_veeam_vbo }}"
has_veeam_em: "{{ has_veeam_em }}"
is_hyperv_host: "{{ is_hyperv_host }}"
# ==========================
# LINUX DETECTION
# ==========================
- name: "Linux | Collect service facts"
when: ansible_facts['os_family'] != "Windows"
ansible.builtin.service_facts:
- name: "Linux | Collect package facts"
when: ansible_facts['os_family'] != "Windows"
ansible.builtin.package_facts:
manager: auto
- name: "Linux | Set UniFi flag"
when: ansible_facts['os_family'] != "Windows"
vars:
svcs: "{{ ansible_facts.services | default({}) }}"
pkgs: "{{ ansible_facts.packages | default({}) | list }}"
ansible.builtin.set_fact:
is_unifi_controller: >-
{{
(unifi_linux_services | select('in', svcs.keys()) | list | length > 0)
or (pkgs | intersect(unifi_linux_packages) | length > 0)
}}
- name: "Normalize detection booleans"
ansible.builtin.set_fact:
is_dc: "{{ is_dc | default(false) }}"
is_dhcp_server: "{{ is_dhcp_server | default(false) }}"
has_veeam_vbr: "{{ has_veeam_vbr | default(false) }}"
has_veeam_vbo: "{{ has_veeam_vbo | default(false) }}"
has_veeam_em: "{{ has_veeam_em | default(false) }}"
is_hyperv_host: "{{ is_hyperv_host | default(false) }}"
is_unifi_controller: "{{ is_unifi_controller | default(false) }}"