# PURPOSE: Install Checkmk agent # DESCRIPTION: Install staged agent packages, deploy selected checks, render Windows settings and ensure the agent is running. # TARGETS: linux, windows # INPUTS (omitted values inherit inventory / role defaults): # aim_debug [bool]: false # checkmk_unifi_mode [choice]: auto # checkmk_unifi_username [text]: bf-monitoring # checkmk_unifi_password [secret_ref]: vault_checkmk_unifi_password # checkmk_unifi_baseurl [url]: network: https://127.0.0.1:8443; os: https://127.0.0.1:11443 # checkmk_unifi_curl_options [text]: --insecure --tlsv1.2 # want_linux_check_certificate [bool]: false # want_windows_citrix [bool]: false # want_windows_surebackup [bool]: false # want_windows_backup [bool]: false # want_windows_nsp_mailqueue [bool]: false # want_windows_certificate [bool]: false # want_windows_veeam_cloud_connect [bool]: false # want_windows_veeam_backup [bool]: false # checkmk_unifi_status_provisioning [int]: 1 # checkmk_unifi_status_upgrading [int]: 1 # checkmk_unifi_status_upgradable [int]: 0 # checkmk_unifi_status_heartbeat_missed [int]: 1 # checkmk_unifi_status_noautobackup [int]: 0 # checkmk_windows_updates_timeout [int]: 3600 # checkmk_windows_updates_cache [int]: 43200 # checkmk_mk_inventory_timeout [int]: 120 # checkmk_plugins_default_timeout [int]: 120 # checkmk_plugins_default_cache [int]: 600 # checkmk_extra_plugin_patterns [sequence]: [] # AUTH: existing inventory / Vault credentials; no embedded passwords. # CHANGES: Installs packages and AIM-managed script files. On Windows only the marked plugins section in check_mk.user.yml is replaced; all other user-config sections are preserved. UniFi deployment also removes the alternative UniFi local check; no other cleanup is performed. # EXAMPLE: ansible-playbook -i inventories//hosts.yml # playbooks/checkmk_install_agent.yml --limit --vault-id @prompt - name: Checkmk | Install linux hosts: linux gather_facts: true pre_tasks: - name: AIM | Validate diagnostics option ansible.builtin.assert: that: - (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true', 'false'] fail_msg: aim_debug must be a YAML/JSON boolean. quiet: true - name: AIM | Reject mixed platform membership ansible.builtin.assert: that: - (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1 fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups. quiet: true - name: AIM | Execution context ansible.builtin.debug: msg: host: '{{ inventory_hostname }}' diagnostics: Enabled; secret values are never included by this task. when: aim_debug | default(false) | bool - name: Load system detect roles ansible.builtin.include_role: name: system_detect_roles - name: Load checkmk script plan ansible.builtin.include_role: name: checkmk_script_plan - name: Checkmk | Preflight scripts and credentials ansible.builtin.include_role: name: checkmk_deploy_scripts tasks_from: preflight become: true roles: - role: checkmk_agent - role: checkmk_deploy_scripts - role: checkmk_configure_agent - role: checkmk_manage_service post_tasks: - name: Checkmk | Observe installed agent ansible.builtin.include_role: name: checkmk_report - name: AIM | Publish operation result ansible.builtin.set_stats: per_host: true aggregate: false data: aim_output: protocol: aim_output_v1 schema: checkmk_agent_state_v1 data: '{{ _aim_checkmk_state }}' - name: Checkmk | Install windows hosts: windows gather_facts: true pre_tasks: - name: AIM | Validate diagnostics option ansible.builtin.assert: that: - (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true', 'false'] fail_msg: aim_debug must be a YAML/JSON boolean. quiet: true - name: AIM | Reject mixed platform membership ansible.builtin.assert: that: - (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1 fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups. quiet: true - name: AIM | Execution context ansible.builtin.debug: msg: host: '{{ inventory_hostname }}' diagnostics: Enabled; secret values are never included by this task. when: aim_debug | default(false) | bool - name: Load system detect roles ansible.builtin.include_role: name: system_detect_roles - name: Load checkmk script plan ansible.builtin.include_role: name: checkmk_script_plan - name: Checkmk | Preflight scripts and credentials ansible.builtin.include_role: name: checkmk_deploy_scripts tasks_from: preflight roles: - role: checkmk_agent - role: checkmk_deploy_scripts - role: checkmk_configure_agent - role: checkmk_manage_service post_tasks: - name: Checkmk | Observe installed agent ansible.builtin.include_role: name: checkmk_report - name: AIM | Publish operation result ansible.builtin.set_stats: per_host: true aggregate: false data: aim_output: protocol: aim_output_v1 schema: checkmk_agent_state_v1 data: '{{ _aim_checkmk_state }}'