116 lines
5.6 KiB
YAML
116 lines
5.6 KiB
YAML
# PURPOSE: Read current Windows Checkmk user configuration
|
|
# DESCRIPTION: Display the current check_mk.user.yml from Windows without modifying the host.
|
|
# TARGETS: windows
|
|
# INPUTS (omitted values inherit inventory / playbook defaults):
|
|
# aim_debug [bool]: false
|
|
# checkmk_windows_user_cfg [text]: C:\ProgramData\checkmk\agent\check_mk.user.yml
|
|
# AUTH: existing inventory / Vault credentials; no embedded passwords.
|
|
# CHANGES: none; this playbook is read-only.
|
|
# EXAMPLE: ansible-playbook -i inventories/<customer>/hosts.yml
|
|
# playbooks/checkmk_read_windows_config.yml --limit <host> --vault-id <customer>@prompt
|
|
|
|
- name: Checkmk | Read Windows user configuration
|
|
hosts: windows
|
|
gather_facts: false
|
|
tasks:
|
|
- name: AIM | Validate diagnostics option
|
|
ansible.builtin.assert:
|
|
that:
|
|
- (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in
|
|
['true', 'false']
|
|
fail_msg: aim_debug must be a YAML/JSON boolean.
|
|
quiet: true
|
|
|
|
- name: AIM | Reject mixed platform membership
|
|
ansible.builtin.assert:
|
|
that:
|
|
- (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1
|
|
fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups.
|
|
quiet: true
|
|
|
|
- name: AIM | Validate Checkmk configuration path
|
|
ansible.builtin.assert:
|
|
that:
|
|
- (checkmk_windows_user_cfg | default('C:\\ProgramData\\checkmk\\agent\\check_mk.user.yml')) is
|
|
string
|
|
- (checkmk_windows_user_cfg | default('C:\\ProgramData\\checkmk\\agent\\check_mk.user.yml') | trim
|
|
| length) > 0
|
|
fail_msg: checkmk_windows_user_cfg must be a non-empty Windows path.
|
|
quiet: true
|
|
|
|
- name: AIM | Execution context
|
|
ansible.builtin.debug:
|
|
msg:
|
|
host: '{{ inventory_hostname }}'
|
|
configuration: "{{ checkmk_windows_user_cfg | default('C:\\\\ProgramData\\\\checkmk\\\\agent\\\\check_mk.user.yml')
|
|
}}"
|
|
mode: Read-only; no Checkmk configuration is modified.
|
|
when: aim_debug | default(false) | bool
|
|
|
|
- name: Windows | Inspect current Checkmk user configuration
|
|
ansible.windows.win_stat:
|
|
path: "{{ checkmk_windows_user_cfg | default('C:\\ProgramData\\checkmk\\agent\\check_mk.user.yml') }}"
|
|
get_checksum: false
|
|
register: _checkmk_windows_user_config_stat
|
|
changed_when: false
|
|
|
|
- name: Windows | Require the approved Checkmk user filename
|
|
ansible.builtin.assert:
|
|
that:
|
|
- not (_checkmk_windows_user_config_stat.stat.exists | default(false)) or (_checkmk_windows_user_config_stat.stat.filename | lower) == 'check_mk.user.yml'
|
|
- not (_checkmk_windows_user_config_stat.stat.exists | default(false)) or (_checkmk_windows_user_config_stat.stat.isreg | default(false))
|
|
- (_checkmk_windows_user_config_stat.stat.size | default(0) | int) <= 524288
|
|
fail_msg: Only a regular check_mk.user.yml file up to 512 KiB may be read.
|
|
quiet: true
|
|
|
|
- name: Windows | Read current Checkmk user configuration
|
|
ansible.windows.slurp:
|
|
src: "{{ checkmk_windows_user_cfg | default('C:\\ProgramData\\checkmk\\agent\\check_mk.user.yml') }}"
|
|
register: _checkmk_windows_user_config_slurp
|
|
when: _checkmk_windows_user_config_stat.stat.exists | default(false)
|
|
no_log: true
|
|
|
|
- name: Windows | Build Checkmk user configuration result
|
|
ansible.builtin.set_fact:
|
|
_checkmk_windows_user_config:
|
|
exists: '{{ _checkmk_windows_user_config_stat.stat.exists | default(false) | bool }}'
|
|
path: "{{ _checkmk_windows_user_config_stat.stat.path | default(checkmk_windows_user_cfg | default('C:\\ProgramData\\checkmk\\agent\\check_mk.user.yml')) }}"
|
|
size_bytes: '{{ _checkmk_windows_user_config_stat.stat.size | default(0) | int }}'
|
|
last_write_time_utc: >-
|
|
{{ (_checkmk_windows_user_config_stat.stat.lastwritetime | aim_epoch_iso_utc)
|
|
if (_checkmk_windows_user_config_stat.stat.exists | default(false)) else none }}
|
|
content: >-
|
|
{{ (_checkmk_windows_user_config_slurp.content | b64decode)
|
|
if (_checkmk_windows_user_config_stat.stat.exists | default(false)) else '' }}
|
|
changed_when: false
|
|
no_log: true
|
|
|
|
- name: Windows | Report missing Checkmk user configuration
|
|
ansible.builtin.debug:
|
|
msg: |-
|
|
{{ inventory_hostname }}
|
|
Checkmk user configuration was not found.
|
|
Path: {{ _checkmk_windows_user_config.path }}
|
|
when: not (_checkmk_windows_user_config.exists | bool)
|
|
|
|
- name: Windows | Print current Checkmk user configuration
|
|
ansible.builtin.debug:
|
|
msg: |-
|
|
{{ inventory_hostname }}
|
|
Path: {{ _checkmk_windows_user_config.path }}
|
|
Size: {{ _checkmk_windows_user_config.size_bytes }} bytes
|
|
Last write (UTC): {{ _checkmk_windows_user_config.last_write_time_utc }}
|
|
----- BEGIN check_mk.user.yml -----
|
|
{{ _checkmk_windows_user_config.content }}
|
|
----- END check_mk.user.yml -----
|
|
when: _checkmk_windows_user_config.exists | bool
|
|
- name: AIM | Publish operation result
|
|
ansible.builtin.set_stats:
|
|
per_host: true
|
|
aggregate: false
|
|
data:
|
|
aim_output:
|
|
protocol: aim_output_v1
|
|
schema: checkmk_user_config_v1
|
|
data: '{{ _checkmk_windows_user_config | aim_report_checkmk_config }}'
|