Files
2026-09-15 18:53:28 +02:00

2.2 KiB

AIM Inventory Model

Source of truth

The authoritative inventory is:

/etc/ansible/inventories/<customer>/hosts.yml

AIM does not use .hosts.tsv as a secondary database and does not reverse-sync TSV data into YAML.

AIM uses round-trip YAML handling so valid manually maintained structures/comments can be preserved where possible.

Platform groups

Default top-level platform groups:

linux
windows
sophosxgs
pfsense

Platform remains top-level because it determines connection semantics such as SSH, WinRM or HTTPAPI.

Hosts may have multiple memberships and optional one-level functional subgroups.

Linux

Linux group variables normally include the SSH connection and service account. The customer SSH key directory is:

group_vars/linux/.ssh/

not:

group_vars/linux/files/.ssh/

ansible_ssh_pass may remain configured as a legacy remote-login-password fallback. A private-key passphrase is a separate secret.

Windows

Domain-joined Windows hosts normally inherit the group-level service identity/password.

A local-account host can override credentials in:

host_vars/<fqdn>/main.yml

Shared local example:

ansible_user: svc_bf-ansible
ansible_password: "{{ vault_windows_local_ansible_password }}"

Host-specific example:

ansible_user: svc_bf-ansible
ansible_password: "{{ vault_ansible_password_server01_example_lan }}"

Host vars

Every newly managed host has:

host_vars/<fqdn>/main.yml

Existing host-vars content is not blindly overwritten.

Customer defaults

AIM customer defaults live in:

/etc/ansible/inventories/<customer>/.aim.yml

Example:

domain_suffix: bfmiglabor.lan
network_address: 10.20.30.0
netmask: 255.255.255.0
ad_dns_domain: intra.company.de
ad_netbios_domain: COMPANY

The AD DNS domain is used for service-account UPNs. NetBIOS remains metadata/legacy naming information.

Safe writes

Inventory mutations use the conceptual sequence:

candidate temp file
→ local YAML validation
→ compare
→ session backup
→ atomic replace

AIM also protects against stale/concurrent writes and uses an inventory lock.