Files
2026-09-22 19:23:17 +02:00

1013 lines
29 KiB
YAML

# AIM playbook catalog, not an executable playbook. No credentials belong in this file.
# Only explicit run-time overrides are passed by AIM; inventory and role defaults remain authoritative.
schema_version: 1
release: 3.3.0rc8
categories:
- Checkmk
- Debug
- Maintenance
- Sophos XGS
- pfSense
playbooks:
- key: checkmk_install_agent
name: Install Checkmk agent
filename: checkmk_install_agent.yml
category: Checkmk
platforms:
- linux
- windows
description: Install staged agent packages, deploy selected checks, render
Windows settings and ensure the agent is running.
inputs:
- name: aim_debug
label: Safe diagnostics
type: bool
default_hint: 'false'
help: Only selected non-secret diagnostics; normal outcomes stay visible.
- name: checkmk_unifi_mode
label: UniFi application
type: choice
default_hint: auto
help: Automatic detection prefers UniFi OS when present; only one local
check/config is deployed.
platforms:
- linux
choices:
- auto
- network
- os
- disabled
- name: checkmk_unifi_username
label: UniFi monitoring username
type: text
default_hint: bf-monitoring
help: ''
platforms:
- linux
- name: checkmk_unifi_password
label: UniFi password variable
type: secret_ref
default_hint: vault_checkmk_unifi_password
help: Enter a Vault variable name, never its password. Required when a UniFi
check is selected.
platforms:
- linux
- name: checkmk_unifi_baseurl
label: UniFi controller URL
type: url
default_hint: 'network: https://127.0.0.1:8443; os: https://127.0.0.1:11443'
help: An explicit URL overrides the mode-specific default.
platforms:
- linux
- name: checkmk_unifi_curl_options
label: UniFi curl options
type: text
default_hint: ' --insecure --tlsv1.2'
help: Preserves the supplied TLS options. The shell configuration is safely
quoted.
platforms:
- linux
- name: want_linux_check_certificate
label: Certificate directory check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- linux
- name: want_windows_citrix
label: Citrix sessions check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: want_windows_surebackup
label: Veeam SureBackup check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: want_windows_backup
label: Windows Backup check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: want_windows_nsp_mailqueue
label: NSP mail queue check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: want_windows_certificate
label: Windows certificate check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: want_windows_veeam_cloud_connect
label: Veeam Cloud Connect check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: want_windows_veeam_backup
label: Repository Veeam backup plugin
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: checkmk_unifi_status_provisioning
label: 'UniFi status: provisioning'
type: int
default_hint: '1'
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
platforms:
- linux
minimum: 0
maximum: 3
- name: checkmk_unifi_status_upgrading
label: 'UniFi status: upgrading'
type: int
default_hint: '1'
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
platforms:
- linux
minimum: 0
maximum: 3
- name: checkmk_unifi_status_upgradable
label: 'UniFi status: upgradable'
type: int
default_hint: '0'
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
platforms:
- linux
minimum: 0
maximum: 3
- name: checkmk_unifi_status_heartbeat_missed
label: 'UniFi status: heartbeat_missed'
type: int
default_hint: '1'
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
platforms:
- linux
minimum: 0
maximum: 3
- name: checkmk_unifi_status_noautobackup
label: 'UniFi status: noautobackup'
type: int
default_hint: '0'
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
platforms:
- linux
minimum: 0
maximum: 3
- name: checkmk_windows_updates_timeout
label: Windows Updates timeout
type: int
default_hint: '3600'
help: Seconds. Unchanged options continue to inherit inventory/defaults.
platforms:
- windows
minimum: 0
- name: checkmk_windows_updates_cache
label: Windows Updates cache
type: int
default_hint: '43200'
help: Seconds. Unchanged options continue to inherit inventory/defaults.
platforms:
- windows
minimum: 0
- name: checkmk_mk_inventory_timeout
label: Inventory plugin timeout
type: int
default_hint: '120'
help: Seconds. Unchanged options continue to inherit inventory/defaults.
platforms:
- windows
minimum: 0
- name: checkmk_plugins_default_timeout
label: Plugin default timeout
type: int
default_hint: '120'
help: Seconds. Unchanged options continue to inherit inventory/defaults.
platforms:
- windows
minimum: 0
- name: checkmk_plugins_default_cache
label: Plugin default cache
type: int
default_hint: '600'
help: Seconds. Unchanged options continue to inherit inventory/defaults.
platforms:
- windows
minimum: 0
- name: checkmk_extra_plugin_patterns
label: Extra Windows plugin rules
type: sequence
default_hint: '[]'
help: YAML/JSON list of rule mappings; see role documentation.
platforms:
- windows
become_platforms:
- linux
warning: Installs packages and replaces AIM-managed script files. On Windows,
AIM replaces only the marked plugins section in check_mk.user.yml; other
user-config sections are preserved. UniFi deployment also removes the
alternative UniFi local check; no other cleanup is performed.
requirements:
- ansible.windows
result:
protocol: aim_output_v1
schema: checkmk_agent_state_v1
scope: per_host
required: true
sensitivity: safe
max_bytes_per_host: 1048576
schema_file: checkmk_agent_state_v1.yml
- key: checkmk_update_scripts_config
name: Update Checkmk scripts and configuration
filename: checkmk_update_scripts_config.yml
category: Checkmk
platforms:
- linux
- windows
description: Deploy selected checks and Windows configuration without
installing agent packages.
inputs:
- name: aim_debug
label: Safe diagnostics
type: bool
default_hint: 'false'
help: Only selected non-secret diagnostics; normal outcomes stay visible.
- name: checkmk_unifi_mode
label: UniFi application
type: choice
default_hint: auto
help: Automatic detection prefers UniFi OS when present; only one local
check/config is deployed.
platforms:
- linux
choices:
- auto
- network
- os
- disabled
- name: checkmk_unifi_username
label: UniFi monitoring username
type: text
default_hint: bf-monitoring
help: ''
platforms:
- linux
- name: checkmk_unifi_password
label: UniFi password variable
type: secret_ref
default_hint: vault_checkmk_unifi_password
help: Enter a Vault variable name, never its password. Required when a UniFi
check is selected.
platforms:
- linux
- name: checkmk_unifi_baseurl
label: UniFi controller URL
type: url
default_hint: 'network: https://127.0.0.1:8443; os: https://127.0.0.1:11443'
help: An explicit URL overrides the mode-specific default.
platforms:
- linux
- name: checkmk_unifi_curl_options
label: UniFi curl options
type: text
default_hint: ' --insecure --tlsv1.2'
help: Preserves the supplied TLS options. The shell configuration is safely
quoted.
platforms:
- linux
- name: want_linux_check_certificate
label: Certificate directory check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- linux
- name: want_windows_citrix
label: Citrix sessions check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: want_windows_surebackup
label: Veeam SureBackup check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: want_windows_backup
label: Windows Backup check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: want_windows_nsp_mailqueue
label: NSP mail queue check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: want_windows_certificate
label: Windows certificate check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: want_windows_veeam_cloud_connect
label: Veeam Cloud Connect check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: want_windows_veeam_backup
label: Repository Veeam backup plugin
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: checkmk_unifi_status_provisioning
label: 'UniFi status: provisioning'
type: int
default_hint: '1'
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
platforms:
- linux
minimum: 0
maximum: 3
- name: checkmk_unifi_status_upgrading
label: 'UniFi status: upgrading'
type: int
default_hint: '1'
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
platforms:
- linux
minimum: 0
maximum: 3
- name: checkmk_unifi_status_upgradable
label: 'UniFi status: upgradable'
type: int
default_hint: '0'
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
platforms:
- linux
minimum: 0
maximum: 3
- name: checkmk_unifi_status_heartbeat_missed
label: 'UniFi status: heartbeat_missed'
type: int
default_hint: '1'
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
platforms:
- linux
minimum: 0
maximum: 3
- name: checkmk_unifi_status_noautobackup
label: 'UniFi status: noautobackup'
type: int
default_hint: '0'
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
platforms:
- linux
minimum: 0
maximum: 3
- name: checkmk_windows_updates_timeout
label: Windows Updates timeout
type: int
default_hint: '3600'
help: Seconds. Unchanged options continue to inherit inventory/defaults.
platforms:
- windows
minimum: 0
- name: checkmk_windows_updates_cache
label: Windows Updates cache
type: int
default_hint: '43200'
help: Seconds. Unchanged options continue to inherit inventory/defaults.
platforms:
- windows
minimum: 0
- name: checkmk_mk_inventory_timeout
label: Inventory plugin timeout
type: int
default_hint: '120'
help: Seconds. Unchanged options continue to inherit inventory/defaults.
platforms:
- windows
minimum: 0
- name: checkmk_plugins_default_timeout
label: Plugin default timeout
type: int
default_hint: '120'
help: Seconds. Unchanged options continue to inherit inventory/defaults.
platforms:
- windows
minimum: 0
- name: checkmk_plugins_default_cache
label: Plugin default cache
type: int
default_hint: '600'
help: Seconds. Unchanged options continue to inherit inventory/defaults.
platforms:
- windows
minimum: 0
- name: checkmk_extra_plugin_patterns
label: Extra Windows plugin rules
type: sequence
default_hint: '[]'
help: YAML/JSON list of rule mappings; see role documentation.
platforms:
- windows
become_platforms:
- linux
warning: Deploys AIM-managed script files and, on Windows, replaces only the
marked plugins section in check_mk.user.yml. Other user-config sections are
preserved. Only the opposite UniFi check is removed during a UniFi mode
transition.
requirements:
- ansible.windows
result:
protocol: aim_output_v1
schema: checkmk_agent_config_v1
scope: per_host
required: true
sensitivity: safe
max_bytes_per_host: 1048576
schema_file: checkmk_agent_config_v1.yml
- key: checkmk_read_windows_config
name: Read Windows Checkmk config
filename: checkmk_read_windows_config.yml
category: Checkmk
platforms:
- windows
description: Display the current Windows check_mk.user.yml, including its path
and file metadata, without modifying the host.
inputs:
- name: aim_debug
label: Safe diagnostics
type: bool
default_hint: 'false'
help: Only selected non-secret diagnostics; normal outcomes stay visible.
- name: checkmk_windows_user_cfg
label: Checkmk user config path
type: text
default_hint: C:\ProgramData\checkmk\agent\check_mk.user.yml
help: Override only when the Windows agent uses a nonstandard
user-configuration path.
platforms:
- windows
requirements:
- ansible.windows
result:
protocol: aim_output_v1
schema: checkmk_user_config_v1
scope: per_host
required: true
sensitivity: safe
max_bytes_per_host: 1048576
schema_file: checkmk_user_config_v1.yml
- key: checkmk_cleanup_scripts
name: Preview / clean up Checkmk scripts
filename: checkmk_cleanup_scripts.yml
category: Checkmk
platforms:
- linux
- windows
description: List obsolete managed script paths; remove them only with
explicit deletion approval.
inputs:
- name: aim_debug
label: Safe diagnostics
type: bool
default_hint: 'false'
help: Only selected non-secret diagnostics; normal outcomes stay visible.
- name: checkmk_cleanup_enabled
label: Permit managed-script deletion
type: bool
default_hint: 'false'
help: Required for cleanup execution. False previews candidate paths without
deleting them.
- name: checkmk_unifi_mode
label: UniFi application
type: choice
default_hint: auto
help: Automatic detection prefers UniFi OS when present; only one local
check/config is deployed.
platforms:
- linux
choices:
- auto
- network
- os
- disabled
- name: want_linux_check_certificate
label: Certificate directory check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- linux
- name: want_windows_citrix
label: Citrix sessions check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: want_windows_surebackup
label: Veeam SureBackup check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: want_windows_backup
label: Windows Backup check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: want_windows_nsp_mailqueue
label: NSP mail queue check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: want_windows_certificate
label: Windows certificate check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: want_windows_veeam_cloud_connect
label: Veeam Cloud Connect check
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
- name: want_windows_veeam_backup
label: Repository Veeam backup plugin
type: bool
default_hint: 'false'
help: Optional check. Script-specific setup remains in the maintained script
repository.
platforms:
- windows
become_platforms:
- linux
warning: Cleanup only touches the documented managed filenames. Preview is the
default; enabling deletion requires another confirmation.
requirements:
- ansible.windows
result:
protocol: aim_output_v1
schema: managed_cleanup_preview_v1
scope: per_host
required: true
sensitivity: safe
max_bytes_per_host: 1048576
schema_file: managed_cleanup_preview_v1.yml
- key: debug_test_connection
name: Test Ansible connection
filename: debug_test_connection.yml
category: Debug
platforms:
- linux
- windows
description: Check Ansible manageability using ping or win_ping; this is not
an ICMP ping.
inputs:
- name: aim_debug
label: Safe diagnostics
type: bool
default_hint: 'false'
help: Only selected non-secret diagnostics; normal outcomes stay visible.
requirements:
- ansible.windows
- key: debug_show_disk_usage
name: Show disk usage
filename: debug_show_disk_usage.yml
category: Debug
platforms:
- linux
- windows
description: Report attached Windows storage volumes and common operational Linux mounts, including network/storage filesystems.
inputs:
- name: aim_debug
label: Safe diagnostics
type: bool
default_hint: 'false'
help: Only selected non-secret diagnostics; normal outcomes stay visible.
requirements:
- ansible.windows
- community.windows
result:
protocol: aim_output_v1
schema: filesystem_usage_v1
scope: per_host
required: true
sensitivity: safe
max_bytes_per_host: 1048576
schema_file: filesystem_usage_v1.yml
- key: debug_detect_host_roles
name: Detect host roles
filename: debug_detect_host_roles.yml
category: Debug
platforms:
- linux
- windows
description: Report detected AD, DHCP, Hyper-V, Veeam and UniFi capabilities
without changing inventory memberships.
inputs:
- name: aim_debug
label: Safe diagnostics
type: bool
default_hint: 'false'
help: Only selected non-secret diagnostics; normal outcomes stay visible.
requirements:
- ansible.windows
result:
protocol: aim_output_v1
schema: host_capabilities_v1
scope: per_host
required: true
sensitivity: safe
max_bytes_per_host: 1048576
schema_file: host_capabilities_v1.yml
- key: maintenance_export_event_logs
name: Export Windows event logs
filename: maintenance_export_event_logs.yml
category: Maintenance
platforms:
- windows
description: Export selected event channels to EVTX files on the target;
existing event logs are not cleared.
inputs:
- name: aim_debug
label: Safe diagnostics
type: bool
default_hint: 'false'
help: Only selected non-secret diagnostics; normal outcomes stay visible.
- name: event_age_days
label: Event age in days
type: int
default_hint: '45'
help: Export events from the last N days, without clearing the logs.
minimum: 1
maximum: 36500
- name: export_folder
label: Target export folder
type: text
default_hint: C:\Logs
help: Directory on each Windows target, not on the Ansible controller.
- name: event_log_channels
label: Event channels
type: list
default_hint: Application, Security, System, Setup
help: Event channels to export.
requirements:
- ansible.windows
result:
protocol: aim_output_v1
schema: event_log_export_v1
scope: per_host
required: true
sensitivity: safe
max_bytes_per_host: 1048576
schema_file: event_log_export_v1.yml
- key: maintenance_start_stopped_services
name: Start stopped automatic services
filename: maintenance_start_stopped_services.yml
category: Maintenance
platforms:
- windows
description: Start eligible stopped services, apply optional include/exclude
lists and report partial failures.
inputs:
- name: aim_debug
label: Safe diagnostics
type: bool
default_hint: 'false'
help: Only selected non-secret diagnostics; normal outcomes stay visible.
- name: maintenance_service_include
label: Service allowlist
type: list
default_hint: '[]'
help: Empty list selects all stopped automatic/delayed-start services; use
internal service names.
- name: maintenance_service_exclude
label: Service exclusions
type: list
default_hint: '[]'
help: Excluded internal service names are never started.
- name: maintenance_service_fail_on_error
label: Fail after partial failure
type: bool
default_hint: 'true'
help: Always reports individual failures; true makes the final task fail
when any start failed.
requirements:
- ansible.windows
result:
protocol: aim_output_v1
schema: service_start_summary_v1
scope: per_host
required: true
sensitivity: safe
max_bytes_per_host: 1048576
schema_file: service_start_summary_v1.yml
- key: maintenance_patch_os
name: Patch operating systems
filename: maintenance_patch_os.yml
category: Maintenance
platforms:
- linux
- windows
description: Apply updates on Windows, Debian and RedHat-family systems;
optionally notify users and reboot when required.
inputs:
- name: aim_debug
label: Safe diagnostics
type: bool
default_hint: 'false'
help: Only selected non-secret diagnostics; normal outcomes stay visible.
- name: os_patching_reboot
label: Reboot when required
type: bool
default_hint: 'true'
help: Patching may reboot each selected host. False installs without an
automatic reboot.
- name: os_patching_windows_categories
label: Windows update categories
type: list
default_hint: SecurityUpdates, CriticalUpdates, UpdateRollups,
DefinitionUpdates, Updates
help: Enter a YAML/JSON list or comma-separated category names.
platforms:
- windows
choices:
- SecurityUpdates
- CriticalUpdates
- UpdateRollups
- DefinitionUpdates
- Updates
- Drivers
- FeaturePacks
- ServicePacks
- Tools
- Upgrades
- '*'
- name: os_patching_serial
label: Batch size
type: serial
default_hint: 100%
help: Positive host count or percentage. Applies independently to each
platform play.
- name: os_patching_reboot_timeout
label: Reboot timeout
type: int
default_hint: '600'
help: Seconds to wait for a Windows/Linux host to reboot and become
manageable again.
minimum: 1
- name: os_patching_reboot_delay_minutes
label: Reboot delay (minutes)
type: int
default_hint: '0'
help: Delay before an AIM-initiated reboot. Linux scheduling is
minute-granular; 0 requests immediate/platform-minimum reboot.
minimum: 0
maximum: 1440
- name: os_patching_reboot_message
label: Reboot message
type: text
default_hint: 'AIM maintenance: operating system patching requires a reboot.'
help: Message shown to logged-in users before an AIM-initiated Windows/Linux
reboot.
- name: os_patching_rescan_after_reboot
label: Continue patching after reboot
type: bool
default_hint: 'false'
help: Windows only. False stops after the first patch-triggered reboot so the next
patch wave requires a new operator-approved run. True rediscovers applicable
updates after reboot and starts another native Windows Update wave.
platforms:
- windows
become_platforms:
- linux
warning: Updates production operating systems. Windows uses the native win_updates wave behavior with AIM-controlled reboots. A reboot boundary stops the run by default; continuing into a newly discovered post-reboot wave requires explicit opt-in. If automatic reboot is disabled, a newly required reboot is reported as deferred.
requirements:
- ansible.windows
result:
protocol: aim_output_v1
schema: patch_summary_v1
scope: per_host
required: true
sensitivity: safe
max_bytes_per_host: 1048576
schema_file: patch_summary_v1.yml
- key: maintenance_reboot_hosts
name: Reboot hosts
filename: maintenance_reboot_hosts.yml
category: Maintenance
platforms:
- linux
- windows
description: Reboot selected hosts in batches and wait for management
connectivity.
inputs:
- name: aim_debug
label: Safe diagnostics
type: bool
default_hint: 'false'
help: Only selected non-secret diagnostics; normal outcomes stay visible.
- name: maintenance_reboot_serial
label: Batch size
type: serial
default_hint: '10'
help: Positive host count or percentage.
- name: maintenance_reboot_timeout
label: Reboot timeout
type: int
default_hint: '1800'
help: Seconds.
minimum: 1
- name: maintenance_reboot_message
label: Reboot message
type: text
default_hint: Reboot initiated by debsansible01.bfmiglabor.lan (Ansible)
help: ''
- name: maintenance_reboot_pre_delay
label: Delay before reboot
type: int
default_hint: '0'
help: Seconds; Windows enforces a minimum of two seconds.
minimum: 0
- name: maintenance_reboot_post_delay
label: Delay after reboot
type: int
default_hint: '15'
help: Seconds.
minimum: 0
become_platforms:
- linux
warning: Every selected host will be rebooted. No reboot occurs before final
confirmation.
requirements:
- ansible.windows
- key: sophos_apply_baseline
name: Apply bitformer Sophos baseline
filename: sophos_apply_baseline.yml
category: Sophos XGS
platforms:
- sophosxgs
description: Apply the supplied bitformer firewall baseline. Existing policy
values and action order are preserved.
inputs:
- name: aim_debug
label: Safe diagnostics
type: bool
default_hint: 'false'
help: Only selected non-secret diagnostics; normal outcomes stay visible.
ask_pass: true
require_vault: true
warning: Changes firewall management access, objects and rules, including rule
removal and a final drop rule. Policy values have NOT been redesigned.
requirements:
- ansible.netcommon
- sophos.sophos_firewall
- key: sophos_apply_customer
name: Apply customer Sophos configuration
filename: sophos_apply_customer.yml
category: Sophos XGS
platforms:
- sophosxgs
description: Apply this customer profile using hostname, network_objects and
vlan_interfaces from inventory.
inputs:
- name: aim_debug
label: Safe diagnostics
type: bool
default_hint: 'false'
help: Only selected non-secret diagnostics; normal outcomes stay visible.
ask_pass: true
require_vault: true
customer_specific: true
warning: Changes customer firewall configuration. VLAN parent remains Port1 as
in the supplied playbooks. Only this customer profile is selected.
requirements:
- ansible.netcommon
- sophos.sophos_firewall
- key: pfsense_apply_baseline
name: Apply bitformer pfSense baseline
filename: pfsense_apply_baseline.yml
category: pfSense
platforms:
- pfsense
description: Apply the supplied pfSense baseline without changing its
firewall/VPN policy.
inputs:
- name: aim_debug
label: Safe diagnostics
type: bool
default_hint: 'false'
help: Only selected non-secret diagnostics; normal outcomes stay visible.
become_platforms:
- pfsense
warning: Contains the original any-source WAN management rule for ports
22/80/443. The original CA, VPN endpoint and client certificate reference
are unchanged; verify them before execution. Requires separately approved
pfsensible.core installation.
requirements:
- pfsensible.core
sophos_profiles:
bluuunit:
required_network_keys:
- derz_lan
- derz_sslvpn
- facility
- guest
- lan_old
- management
- office
- server
- voip
vlan_parent: Port1
formicon:
required_network_keys:
- azuregwc_lan
- lan_old
- management
- office
vlan_parent: Port1
gebhardt_stahl:
required_network_keys:
- drucker
- guest
- office
- wlan
vlan_parent: Port1
hungeling_und_toechter:
required_network_keys:
- facility
- guest
- management
- office
- voip
vlan_parent: Port1
koenig_holding_gmbh:
required_network_keys:
- facility
- guest
- management
- office
- server
- voip
vlan_parent: Port1