--- # PURPOSE: Preview / clean up Checkmk scripts # DESCRIPTION: List obsolete managed script paths; remove them only with explicit deletion approval. # TARGETS: linux, windows # INPUTS (omitted values inherit inventory / role defaults): # aim_debug [bool]: false # checkmk_cleanup_enabled [bool]: false # checkmk_unifi_mode [choice]: auto # want_linux_check_certificate [bool]: false # want_windows_citrix [bool]: false # want_windows_surebackup [bool]: false # want_windows_backup [bool]: false # want_windows_nsp_mailqueue [bool]: false # want_windows_certificate [bool]: false # want_windows_veeam_cloud_connect [bool]: false # want_windows_veeam_backup [bool]: false # AUTH: existing inventory / Vault credentials; no embedded passwords. # CHANGES: Cleanup only touches the documented managed filenames. Preview is the default; enabling deletion requires another confirmation. # EXAMPLE: ansible-playbook -i inventories//hosts.yml # playbooks/checkmk_cleanup_scripts.yml --limit --vault-id @prompt - name: Checkmk | Preview or clean up linux hosts: linux gather_facts: true pre_tasks: - name: AIM | Validate diagnostics option ansible.builtin.assert: that: - (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true', 'false'] fail_msg: aim_debug must be a YAML/JSON boolean. quiet: true - name: AIM | Reject mixed platform membership ansible.builtin.assert: that: - (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1 fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups. quiet: true - name: AIM | Execution context ansible.builtin.debug: msg: host: '{{ inventory_hostname }}' diagnostics: Enabled; secret values are never included by this task. when: aim_debug | default(false) | bool become: true roles: - role: system_detect_roles - role: checkmk_script_plan - role: checkmk_cleanup_scripts - name: Checkmk | Preview or clean up windows hosts: windows gather_facts: true pre_tasks: - name: AIM | Validate diagnostics option ansible.builtin.assert: that: - (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true', 'false'] fail_msg: aim_debug must be a YAML/JSON boolean. quiet: true - name: AIM | Reject mixed platform membership ansible.builtin.assert: that: - (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1 fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups. quiet: true - name: AIM | Execution context ansible.builtin.debug: msg: host: '{{ inventory_hostname }}' diagnostics: Enabled; secret values are never included by this task. when: aim_debug | default(false) | bool roles: - role: system_detect_roles - role: checkmk_script_plan - role: checkmk_cleanup_scripts