checkmk_windows_acl
Normalizes access on AIM-managed persistent Windows Checkmk files without recursively changing Checkmk directories or unknown/operator files.
The role enables parent ACL inheritance and guarantees locale-independent well-known principals by SID:
- SYSTEM (
S-1-5-18): FullControl - local Administrators (
S-1-5-32-544): FullControl - ALL APPLICATION PACKAGES (
S-1-15-2-1): ReadAndExecute - ALL RESTRICTED APPLICATION PACKAGES (
S-1-15-2-2): ReadAndExecute
AIM does not add customer-specific administrator/user ACEs. Existing intentional parent
or explicit ACEs are not blindly purged. Pass persistent AIM-owned file paths through
checkmk_windows_acl_paths.