# AIM playbook catalog, not an executable playbook. No credentials belong in this file. # Only explicit run-time overrides are passed by AIM; inventory and role defaults remain authoritative. schema_version: 1 release: 3.3.0rc8 categories: - Checkmk - Debug - Maintenance - Sophos XGS - pfSense playbooks: - key: checkmk_install_agent name: Install Checkmk agent filename: checkmk_install_agent.yml category: Checkmk platforms: - linux - windows description: Install staged agent packages, deploy selected checks, render Windows settings and ensure the agent is running. inputs: - name: aim_debug label: Safe diagnostics type: bool default_hint: 'false' help: Only selected non-secret diagnostics; normal outcomes stay visible. - name: checkmk_unifi_mode label: UniFi application type: choice default_hint: auto help: Automatic detection prefers UniFi OS when present; only one local check/config is deployed. platforms: - linux choices: - auto - network - os - disabled - name: checkmk_unifi_username label: UniFi monitoring username type: text default_hint: bf-monitoring help: '' platforms: - linux - name: checkmk_unifi_password label: UniFi password variable type: secret_ref default_hint: vault_checkmk_unifi_password help: Enter a Vault variable name, never its password. Required when a UniFi check is selected. platforms: - linux - name: checkmk_unifi_baseurl label: UniFi controller URL type: url default_hint: 'network: https://127.0.0.1:8443; os: https://127.0.0.1:11443' help: An explicit URL overrides the mode-specific default. platforms: - linux - name: checkmk_unifi_curl_options label: UniFi curl options type: text default_hint: ' --insecure --tlsv1.2' help: Preserves the supplied TLS options. The shell configuration is safely quoted. platforms: - linux - name: want_linux_check_certificate label: Certificate directory check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - linux - name: want_windows_citrix label: Citrix sessions check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: want_windows_surebackup label: Veeam SureBackup check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: want_windows_backup label: Windows Backup check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: want_windows_nsp_mailqueue label: NSP mail queue check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: want_windows_certificate label: Windows certificate check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: want_windows_veeam_cloud_connect label: Veeam Cloud Connect check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: want_windows_veeam_backup label: Repository Veeam backup plugin type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: checkmk_unifi_status_provisioning label: 'UniFi status: provisioning' type: int default_hint: '1' help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN. platforms: - linux minimum: 0 maximum: 3 - name: checkmk_unifi_status_upgrading label: 'UniFi status: upgrading' type: int default_hint: '1' help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN. platforms: - linux minimum: 0 maximum: 3 - name: checkmk_unifi_status_upgradable label: 'UniFi status: upgradable' type: int default_hint: '0' help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN. platforms: - linux minimum: 0 maximum: 3 - name: checkmk_unifi_status_heartbeat_missed label: 'UniFi status: heartbeat_missed' type: int default_hint: '1' help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN. platforms: - linux minimum: 0 maximum: 3 - name: checkmk_unifi_status_noautobackup label: 'UniFi status: noautobackup' type: int default_hint: '0' help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN. platforms: - linux minimum: 0 maximum: 3 - name: checkmk_windows_updates_timeout label: Windows Updates timeout type: int default_hint: '3600' help: Seconds. Unchanged options continue to inherit inventory/defaults. platforms: - windows minimum: 0 - name: checkmk_windows_updates_cache label: Windows Updates cache type: int default_hint: '43200' help: Seconds. Unchanged options continue to inherit inventory/defaults. platforms: - windows minimum: 0 - name: checkmk_mk_inventory_timeout label: Inventory plugin timeout type: int default_hint: '120' help: Seconds. Unchanged options continue to inherit inventory/defaults. platforms: - windows minimum: 0 - name: checkmk_plugins_default_timeout label: Plugin default timeout type: int default_hint: '120' help: Seconds. Unchanged options continue to inherit inventory/defaults. platforms: - windows minimum: 0 - name: checkmk_plugins_default_cache label: Plugin default cache type: int default_hint: '600' help: Seconds. Unchanged options continue to inherit inventory/defaults. platforms: - windows minimum: 0 - name: checkmk_extra_plugin_patterns label: Extra Windows plugin rules type: sequence default_hint: '[]' help: YAML/JSON list of rule mappings; see role documentation. platforms: - windows become_platforms: - linux warning: Installs packages and replaces AIM-managed script files. On Windows, AIM replaces only the marked plugins section in check_mk.user.yml; other user-config sections are preserved. UniFi deployment also removes the alternative UniFi local check; no other cleanup is performed. requirements: - ansible.windows result: protocol: aim_output_v1 schema: checkmk_agent_state_v1 scope: per_host required: true sensitivity: safe max_bytes_per_host: 1048576 schema_file: checkmk_agent_state_v1.yml - key: checkmk_update_scripts_config name: Update Checkmk scripts and configuration filename: checkmk_update_scripts_config.yml category: Checkmk platforms: - linux - windows description: Deploy selected checks and Windows configuration without installing agent packages. inputs: - name: aim_debug label: Safe diagnostics type: bool default_hint: 'false' help: Only selected non-secret diagnostics; normal outcomes stay visible. - name: checkmk_unifi_mode label: UniFi application type: choice default_hint: auto help: Automatic detection prefers UniFi OS when present; only one local check/config is deployed. platforms: - linux choices: - auto - network - os - disabled - name: checkmk_unifi_username label: UniFi monitoring username type: text default_hint: bf-monitoring help: '' platforms: - linux - name: checkmk_unifi_password label: UniFi password variable type: secret_ref default_hint: vault_checkmk_unifi_password help: Enter a Vault variable name, never its password. Required when a UniFi check is selected. platforms: - linux - name: checkmk_unifi_baseurl label: UniFi controller URL type: url default_hint: 'network: https://127.0.0.1:8443; os: https://127.0.0.1:11443' help: An explicit URL overrides the mode-specific default. platforms: - linux - name: checkmk_unifi_curl_options label: UniFi curl options type: text default_hint: ' --insecure --tlsv1.2' help: Preserves the supplied TLS options. The shell configuration is safely quoted. platforms: - linux - name: want_linux_check_certificate label: Certificate directory check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - linux - name: want_windows_citrix label: Citrix sessions check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: want_windows_surebackup label: Veeam SureBackup check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: want_windows_backup label: Windows Backup check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: want_windows_nsp_mailqueue label: NSP mail queue check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: want_windows_certificate label: Windows certificate check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: want_windows_veeam_cloud_connect label: Veeam Cloud Connect check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: want_windows_veeam_backup label: Repository Veeam backup plugin type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: checkmk_unifi_status_provisioning label: 'UniFi status: provisioning' type: int default_hint: '1' help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN. platforms: - linux minimum: 0 maximum: 3 - name: checkmk_unifi_status_upgrading label: 'UniFi status: upgrading' type: int default_hint: '1' help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN. platforms: - linux minimum: 0 maximum: 3 - name: checkmk_unifi_status_upgradable label: 'UniFi status: upgradable' type: int default_hint: '0' help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN. platforms: - linux minimum: 0 maximum: 3 - name: checkmk_unifi_status_heartbeat_missed label: 'UniFi status: heartbeat_missed' type: int default_hint: '1' help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN. platforms: - linux minimum: 0 maximum: 3 - name: checkmk_unifi_status_noautobackup label: 'UniFi status: noautobackup' type: int default_hint: '0' help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN. platforms: - linux minimum: 0 maximum: 3 - name: checkmk_windows_updates_timeout label: Windows Updates timeout type: int default_hint: '3600' help: Seconds. Unchanged options continue to inherit inventory/defaults. platforms: - windows minimum: 0 - name: checkmk_windows_updates_cache label: Windows Updates cache type: int default_hint: '43200' help: Seconds. Unchanged options continue to inherit inventory/defaults. platforms: - windows minimum: 0 - name: checkmk_mk_inventory_timeout label: Inventory plugin timeout type: int default_hint: '120' help: Seconds. Unchanged options continue to inherit inventory/defaults. platforms: - windows minimum: 0 - name: checkmk_plugins_default_timeout label: Plugin default timeout type: int default_hint: '120' help: Seconds. Unchanged options continue to inherit inventory/defaults. platforms: - windows minimum: 0 - name: checkmk_plugins_default_cache label: Plugin default cache type: int default_hint: '600' help: Seconds. Unchanged options continue to inherit inventory/defaults. platforms: - windows minimum: 0 - name: checkmk_extra_plugin_patterns label: Extra Windows plugin rules type: sequence default_hint: '[]' help: YAML/JSON list of rule mappings; see role documentation. platforms: - windows become_platforms: - linux warning: Deploys AIM-managed script files and, on Windows, replaces only the marked plugins section in check_mk.user.yml. Other user-config sections are preserved. Only the opposite UniFi check is removed during a UniFi mode transition. requirements: - ansible.windows result: protocol: aim_output_v1 schema: checkmk_agent_config_v1 scope: per_host required: true sensitivity: safe max_bytes_per_host: 1048576 schema_file: checkmk_agent_config_v1.yml - key: checkmk_read_windows_config name: Read Windows Checkmk config filename: checkmk_read_windows_config.yml category: Checkmk platforms: - windows description: Display the current Windows check_mk.user.yml, including its path and file metadata, without modifying the host. inputs: - name: aim_debug label: Safe diagnostics type: bool default_hint: 'false' help: Only selected non-secret diagnostics; normal outcomes stay visible. - name: checkmk_windows_user_cfg label: Checkmk user config path type: text default_hint: C:\ProgramData\checkmk\agent\check_mk.user.yml help: Override only when the Windows agent uses a nonstandard user-configuration path. platforms: - windows requirements: - ansible.windows result: protocol: aim_output_v1 schema: checkmk_user_config_v1 scope: per_host required: true sensitivity: safe max_bytes_per_host: 1048576 schema_file: checkmk_user_config_v1.yml - key: checkmk_cleanup_scripts name: Preview / clean up Checkmk scripts filename: checkmk_cleanup_scripts.yml category: Checkmk platforms: - linux - windows description: List obsolete managed script paths; remove them only with explicit deletion approval. inputs: - name: aim_debug label: Safe diagnostics type: bool default_hint: 'false' help: Only selected non-secret diagnostics; normal outcomes stay visible. - name: checkmk_cleanup_enabled label: Permit managed-script deletion type: bool default_hint: 'false' help: Required for cleanup execution. False previews candidate paths without deleting them. - name: checkmk_unifi_mode label: UniFi application type: choice default_hint: auto help: Automatic detection prefers UniFi OS when present; only one local check/config is deployed. platforms: - linux choices: - auto - network - os - disabled - name: want_linux_check_certificate label: Certificate directory check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - linux - name: want_windows_citrix label: Citrix sessions check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: want_windows_surebackup label: Veeam SureBackup check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: want_windows_backup label: Windows Backup check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: want_windows_nsp_mailqueue label: NSP mail queue check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: want_windows_certificate label: Windows certificate check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: want_windows_veeam_cloud_connect label: Veeam Cloud Connect check type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows - name: want_windows_veeam_backup label: Repository Veeam backup plugin type: bool default_hint: 'false' help: Optional check. Script-specific setup remains in the maintained script repository. platforms: - windows become_platforms: - linux warning: Cleanup only touches the documented managed filenames. Preview is the default; enabling deletion requires another confirmation. requirements: - ansible.windows result: protocol: aim_output_v1 schema: managed_cleanup_preview_v1 scope: per_host required: true sensitivity: safe max_bytes_per_host: 1048576 schema_file: managed_cleanup_preview_v1.yml - key: debug_test_connection name: Test Ansible connection filename: debug_test_connection.yml category: Debug platforms: - linux - windows description: Check Ansible manageability using ping or win_ping; this is not an ICMP ping. inputs: - name: aim_debug label: Safe diagnostics type: bool default_hint: 'false' help: Only selected non-secret diagnostics; normal outcomes stay visible. requirements: - ansible.windows - key: debug_show_disk_usage name: Show disk usage filename: debug_show_disk_usage.yml category: Debug platforms: - linux - windows description: Report attached Windows storage volumes and common operational Linux mounts, including network/storage filesystems. inputs: - name: aim_debug label: Safe diagnostics type: bool default_hint: 'false' help: Only selected non-secret diagnostics; normal outcomes stay visible. requirements: - ansible.windows - community.windows result: protocol: aim_output_v1 schema: filesystem_usage_v1 scope: per_host required: true sensitivity: safe max_bytes_per_host: 1048576 schema_file: filesystem_usage_v1.yml - key: debug_detect_host_roles name: Detect host roles filename: debug_detect_host_roles.yml category: Debug platforms: - linux - windows description: Report detected AD, DHCP, Hyper-V, Veeam and UniFi capabilities without changing inventory memberships. inputs: - name: aim_debug label: Safe diagnostics type: bool default_hint: 'false' help: Only selected non-secret diagnostics; normal outcomes stay visible. requirements: - ansible.windows result: protocol: aim_output_v1 schema: host_capabilities_v1 scope: per_host required: true sensitivity: safe max_bytes_per_host: 1048576 schema_file: host_capabilities_v1.yml - key: maintenance_export_event_logs name: Export Windows event logs filename: maintenance_export_event_logs.yml category: Maintenance platforms: - windows description: Export selected event channels to EVTX files on the target; existing event logs are not cleared. inputs: - name: aim_debug label: Safe diagnostics type: bool default_hint: 'false' help: Only selected non-secret diagnostics; normal outcomes stay visible. - name: event_age_days label: Event age in days type: int default_hint: '45' help: Export events from the last N days, without clearing the logs. minimum: 1 maximum: 36500 - name: export_folder label: Target export folder type: text default_hint: C:\Logs help: Directory on each Windows target, not on the Ansible controller. - name: event_log_channels label: Event channels type: list default_hint: Application, Security, System, Setup help: Event channels to export. requirements: - ansible.windows result: protocol: aim_output_v1 schema: event_log_export_v1 scope: per_host required: true sensitivity: safe max_bytes_per_host: 1048576 schema_file: event_log_export_v1.yml - key: maintenance_start_stopped_services name: Start stopped automatic services filename: maintenance_start_stopped_services.yml category: Maintenance platforms: - windows description: Start eligible stopped services, apply optional include/exclude lists and report partial failures. inputs: - name: aim_debug label: Safe diagnostics type: bool default_hint: 'false' help: Only selected non-secret diagnostics; normal outcomes stay visible. - name: maintenance_service_include label: Service allowlist type: list default_hint: '[]' help: Empty list selects all stopped automatic/delayed-start services; use internal service names. - name: maintenance_service_exclude label: Service exclusions type: list default_hint: '[]' help: Excluded internal service names are never started. - name: maintenance_service_fail_on_error label: Fail after partial failure type: bool default_hint: 'true' help: Always reports individual failures; true makes the final task fail when any start failed. requirements: - ansible.windows result: protocol: aim_output_v1 schema: service_start_summary_v1 scope: per_host required: true sensitivity: safe max_bytes_per_host: 1048576 schema_file: service_start_summary_v1.yml - key: maintenance_patch_os name: Patch operating systems filename: maintenance_patch_os.yml category: Maintenance platforms: - linux - windows description: Apply updates on Windows, Debian and RedHat-family systems; optionally notify users and reboot when required. inputs: - name: aim_debug label: Safe diagnostics type: bool default_hint: 'false' help: Only selected non-secret diagnostics; normal outcomes stay visible. - name: os_patching_reboot label: Reboot when required type: bool default_hint: 'true' help: Patching may reboot each selected host. False installs without an automatic reboot. - name: os_patching_windows_categories label: Windows update categories type: list default_hint: SecurityUpdates, CriticalUpdates, UpdateRollups, DefinitionUpdates, Updates help: Enter a YAML/JSON list or comma-separated category names. platforms: - windows choices: - SecurityUpdates - CriticalUpdates - UpdateRollups - DefinitionUpdates - Updates - Drivers - FeaturePacks - ServicePacks - Tools - Upgrades - '*' - name: os_patching_serial label: Batch size type: serial default_hint: 100% help: Positive host count or percentage. Applies independently to each platform play. - name: os_patching_reboot_timeout label: Reboot timeout type: int default_hint: '600' help: Seconds to wait for a Windows/Linux host to reboot and become manageable again. minimum: 1 - name: os_patching_reboot_delay_minutes label: Reboot delay (minutes) type: int default_hint: '0' help: Delay before an AIM-initiated reboot. Linux scheduling is minute-granular; 0 requests immediate/platform-minimum reboot. minimum: 0 maximum: 1440 - name: os_patching_reboot_message label: Reboot message type: text default_hint: 'AIM maintenance: operating system patching requires a reboot.' help: Message shown to logged-in users before an AIM-initiated Windows/Linux reboot. - name: os_patching_rescan_after_reboot label: Continue patching after reboot type: bool default_hint: 'false' help: Windows only. False stops after the first patch-triggered reboot so the next patch wave requires a new operator-approved run. True rediscovers applicable updates after reboot and starts another native Windows Update wave. platforms: - windows become_platforms: - linux warning: Updates production operating systems. Windows uses the native win_updates wave behavior with AIM-controlled reboots. A reboot boundary stops the run by default; continuing into a newly discovered post-reboot wave requires explicit opt-in. If automatic reboot is disabled, a newly required reboot is reported as deferred. requirements: - ansible.windows result: protocol: aim_output_v1 schema: patch_summary_v1 scope: per_host required: true sensitivity: safe max_bytes_per_host: 1048576 schema_file: patch_summary_v1.yml - key: maintenance_reboot_hosts name: Reboot hosts filename: maintenance_reboot_hosts.yml category: Maintenance platforms: - linux - windows description: Reboot selected hosts in batches and wait for management connectivity. inputs: - name: aim_debug label: Safe diagnostics type: bool default_hint: 'false' help: Only selected non-secret diagnostics; normal outcomes stay visible. - name: maintenance_reboot_serial label: Batch size type: serial default_hint: '10' help: Positive host count or percentage. - name: maintenance_reboot_timeout label: Reboot timeout type: int default_hint: '1800' help: Seconds. minimum: 1 - name: maintenance_reboot_message label: Reboot message type: text default_hint: Reboot initiated by debsansible01.bfmiglabor.lan (Ansible) help: '' - name: maintenance_reboot_pre_delay label: Delay before reboot type: int default_hint: '0' help: Seconds; Windows enforces a minimum of two seconds. minimum: 0 - name: maintenance_reboot_post_delay label: Delay after reboot type: int default_hint: '15' help: Seconds. minimum: 0 become_platforms: - linux warning: Every selected host will be rebooted. No reboot occurs before final confirmation. requirements: - ansible.windows - key: sophos_apply_baseline name: Apply bitformer Sophos baseline filename: sophos_apply_baseline.yml category: Sophos XGS platforms: - sophosxgs description: Apply the supplied bitformer firewall baseline. Existing policy values and action order are preserved. inputs: - name: aim_debug label: Safe diagnostics type: bool default_hint: 'false' help: Only selected non-secret diagnostics; normal outcomes stay visible. ask_pass: true require_vault: true warning: Changes firewall management access, objects and rules, including rule removal and a final drop rule. Policy values have NOT been redesigned. requirements: - ansible.netcommon - sophos.sophos_firewall - key: sophos_apply_customer name: Apply customer Sophos configuration filename: sophos_apply_customer.yml category: Sophos XGS platforms: - sophosxgs description: Apply this customer profile using hostname, network_objects and vlan_interfaces from inventory. inputs: - name: aim_debug label: Safe diagnostics type: bool default_hint: 'false' help: Only selected non-secret diagnostics; normal outcomes stay visible. ask_pass: true require_vault: true customer_specific: true warning: Changes customer firewall configuration. VLAN parent remains Port1 as in the supplied playbooks. Only this customer profile is selected. requirements: - ansible.netcommon - sophos.sophos_firewall - key: pfsense_apply_baseline name: Apply bitformer pfSense baseline filename: pfsense_apply_baseline.yml category: pfSense platforms: - pfsense description: Apply the supplied pfSense baseline without changing its firewall/VPN policy. inputs: - name: aim_debug label: Safe diagnostics type: bool default_hint: 'false' help: Only selected non-secret diagnostics; normal outcomes stay visible. become_platforms: - pfsense warning: Contains the original any-source WAN management rule for ports 22/80/443. The original CA, VPN endpoint and client certificate reference are unchanged; verify them before execution. Requires separately approved pfsensible.core installation. requirements: - pfsensible.core sophos_profiles: bluuunit: required_network_keys: - derz_lan - derz_sslvpn - facility - guest - lan_old - management - office - server - voip vlan_parent: Port1 formicon: required_network_keys: - azuregwc_lan - lan_old - management - office vlan_parent: Port1 gebhardt_stahl: required_network_keys: - drucker - guest - office - wlan vlan_parent: Port1 hungeling_und_toechter: required_network_keys: - facility - guest - management - office - voip vlan_parent: Port1 koenig_holding_gmbh: required_network_keys: - facility - guest - management - office - server - voip vlan_parent: Port1