31 lines
1.0 KiB
YAML
31 lines
1.0 KiB
YAML
---
|
|
- name: Windows ACL | Validate managed paths
|
|
ansible.builtin.assert:
|
|
that:
|
|
- checkmk_windows_acl_paths is defined
|
|
- checkmk_windows_acl_paths is sequence
|
|
- checkmk_windows_acl_paths is not string
|
|
- checkmk_windows_acl_paths | length > 0
|
|
fail_msg: checkmk_windows_acl_paths must contain one or more AIM-managed Windows files.
|
|
quiet: true
|
|
|
|
- name: Windows ACL | Ensure managed files inherit parent permissions
|
|
ansible.windows.win_acl_inheritance:
|
|
path: '{{ item }}'
|
|
state: present
|
|
reorganize: true
|
|
loop: '{{ checkmk_windows_acl_paths }}'
|
|
loop_control:
|
|
label: '{{ item }}'
|
|
|
|
- name: Windows ACL | Ensure Checkmk-style administrative and application access
|
|
ansible.windows.win_acl:
|
|
path: '{{ item.0 }}'
|
|
user: '{{ item.1.sid }}'
|
|
rights: '{{ item.1.rights }}'
|
|
type: allow
|
|
state: present
|
|
loop: '{{ checkmk_windows_acl_paths | product(checkmk_windows_managed_acl_entries) | list }}'
|
|
loop_control:
|
|
label: '{{ item.0 }} | {{ item.1.description }}'
|