# PURPOSE: Read current Windows Checkmk user configuration # DESCRIPTION: Display the current check_mk.user.yml from Windows without modifying the host. # TARGETS: windows # INPUTS (omitted values inherit inventory / playbook defaults): # aim_debug [bool]: false # checkmk_windows_user_cfg [text]: C:\ProgramData\checkmk\agent\check_mk.user.yml # AUTH: existing inventory / Vault credentials; no embedded passwords. # CHANGES: none; this playbook is read-only. # EXAMPLE: ansible-playbook -i inventories//hosts.yml # playbooks/checkmk_read_windows_config.yml --limit --vault-id @prompt - name: Checkmk | Read Windows user configuration hosts: windows gather_facts: false tasks: - name: AIM | Validate diagnostics option ansible.builtin.assert: that: - (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true', 'false'] fail_msg: aim_debug must be a YAML/JSON boolean. quiet: true - name: AIM | Reject mixed platform membership ansible.builtin.assert: that: - (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1 fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups. quiet: true - name: AIM | Validate Checkmk configuration path ansible.builtin.assert: that: - (checkmk_windows_user_cfg | default('C:\\ProgramData\\checkmk\\agent\\check_mk.user.yml')) is string - (checkmk_windows_user_cfg | default('C:\\ProgramData\\checkmk\\agent\\check_mk.user.yml') | trim | length) > 0 fail_msg: checkmk_windows_user_cfg must be a non-empty Windows path. quiet: true - name: AIM | Execution context ansible.builtin.debug: msg: host: '{{ inventory_hostname }}' configuration: "{{ checkmk_windows_user_cfg | default('C:\\\\ProgramData\\\\checkmk\\\\agent\\\\check_mk.user.yml') }}" mode: Read-only; no Checkmk configuration is modified. when: aim_debug | default(false) | bool - name: Windows | Inspect current Checkmk user configuration ansible.windows.win_stat: path: "{{ checkmk_windows_user_cfg | default('C:\\ProgramData\\checkmk\\agent\\check_mk.user.yml') }}" get_checksum: false register: _checkmk_windows_user_config_stat changed_when: false - name: Windows | Require the approved Checkmk user filename ansible.builtin.assert: that: - not (_checkmk_windows_user_config_stat.stat.exists | default(false)) or (_checkmk_windows_user_config_stat.stat.filename | lower) == 'check_mk.user.yml' - not (_checkmk_windows_user_config_stat.stat.exists | default(false)) or (_checkmk_windows_user_config_stat.stat.isreg | default(false)) - (_checkmk_windows_user_config_stat.stat.size | default(0) | int) <= 524288 fail_msg: Only a regular check_mk.user.yml file up to 512 KiB may be read. quiet: true - name: Windows | Read current Checkmk user configuration ansible.windows.slurp: src: "{{ checkmk_windows_user_cfg | default('C:\\ProgramData\\checkmk\\agent\\check_mk.user.yml') }}" register: _checkmk_windows_user_config_slurp when: _checkmk_windows_user_config_stat.stat.exists | default(false) no_log: true - name: Windows | Build Checkmk user configuration result ansible.builtin.set_fact: _checkmk_windows_user_config: exists: '{{ _checkmk_windows_user_config_stat.stat.exists | default(false) | bool }}' path: "{{ _checkmk_windows_user_config_stat.stat.path | default(checkmk_windows_user_cfg | default('C:\\ProgramData\\checkmk\\agent\\check_mk.user.yml')) }}" size_bytes: '{{ _checkmk_windows_user_config_stat.stat.size | default(0) | int }}' last_write_time_utc: >- {{ (_checkmk_windows_user_config_stat.stat.lastwritetime | aim_epoch_iso_utc) if (_checkmk_windows_user_config_stat.stat.exists | default(false)) else none }} content: >- {{ (_checkmk_windows_user_config_slurp.content | b64decode) if (_checkmk_windows_user_config_stat.stat.exists | default(false)) else '' }} changed_when: false no_log: true - name: Windows | Report missing Checkmk user configuration ansible.builtin.debug: msg: |- {{ inventory_hostname }} Checkmk user configuration was not found. Path: {{ _checkmk_windows_user_config.path }} when: not (_checkmk_windows_user_config.exists | bool) - name: Windows | Print current Checkmk user configuration ansible.builtin.debug: msg: |- {{ inventory_hostname }} Path: {{ _checkmk_windows_user_config.path }} Size: {{ _checkmk_windows_user_config.size_bytes }} bytes Last write (UTC): {{ _checkmk_windows_user_config.last_write_time_utc }} ----- BEGIN check_mk.user.yml ----- {{ _checkmk_windows_user_config.content }} ----- END check_mk.user.yml ----- when: _checkmk_windows_user_config.exists | bool - name: AIM | Publish operation result ansible.builtin.set_stats: per_host: true aggregate: false data: aim_output: protocol: aim_output_v1 schema: checkmk_user_config_v1 data: '{{ _checkmk_windows_user_config | aim_report_checkmk_config }}'