--- - name: Checkmk | Inspect selected controller script sources ansible.builtin.stat: path: '{{ item.source }}' delegate_to: localhost become: false loop: '{{ _checkmk_selected_scripts }}' loop_control: label: '{{ item.filename }}' register: _checkmk_sources - name: Checkmk | Require selected controller files ansible.builtin.assert: that: - item.stat.exists | default(false) - item.stat.isreg | default(false) fail_msg: A selected monitoring script is missing on the controller. Sync the monitoring repository first. quiet: true loop: '{{ _checkmk_sources.results }}' loop_control: label: '{{ item.item.filename }}' - name: Checkmk | Validate UniFi public settings ansible.builtin.assert: that: - checkmk_unifi_username is string - checkmk_unifi_username | length > 0 - checkmk_unifi_baseurl is match('^https?://[^\s]+$') - checkmk_unifi_curl_options is string - checkmk_unifi_status_provisioning | int in [0,1,2,3] - checkmk_unifi_status_upgrading | int in [0,1,2,3] - checkmk_unifi_status_upgradable | int in [0,1,2,3] - checkmk_unifi_status_heartbeat_missed | int in [0,1,2,3] - checkmk_unifi_status_noautobackup | int in [0,1,2,3] fail_msg: Invalid UniFi username, base URL, curl options or status mapping. quiet: true when: - ansible_facts.os_family != 'Windows' - _checkmk_unifi_effective in ['network','os'] - name: Checkmk | Require a real UniFi monitoring password when: - ansible_facts.os_family != 'Windows' - _checkmk_unifi_effective in ['network','os'] block: - name: Checkmk | Validate secret ansible.builtin.assert: that: - checkmk_unifi_password is string - checkmk_unifi_password | length > 0 - checkmk_unifi_password != 'CHANGEME' fail_msg: A real UniFi password is required. quiet: true no_log: true rescue: - name: Checkmk | Explain missing UniFi secret ansible.builtin.fail: msg: Set vault_checkmk_unifi_password in the customer Vault, or override checkmk_unifi_password with a host-specific Vault reference. Empty values and CHANGEME are refused. No secret was logged.