5.9 KiB
AIM 3.3.0rc8 release notes
3.3.0rc8 is a focused Windows Checkmk ACL hardening release on top of the final rc7 script-placement baseline. AIM-managed persistent Checkmk files now remain readable/manageable by the standard local administrative principals even when created by a service account.
Windows Checkmk managed-file ACLs
After AIM creates or updates a persistent Windows Checkmk script or check_mk.user.yml, the reusable checkmk_windows_acl role enables parent ACL inheritance and guarantees these locale-independent well-known SID entries:
- SYSTEM (
S-1-5-18): FullControl - local Administrators (
S-1-5-32-544): FullControl - ALL APPLICATION PACKAGES (
S-1-15-2-1): ReadAndExecute - ALL RESTRICTED APPLICATION PACKAGES (
S-1-15-2-2): ReadAndExecute
AIM does not add a customer-specific administrator/user ACE such as the example bitformer account. ACL normalization is per exact AIM-managed file; it does not recurse through Checkmk directories or modify unknown/operator files. Existing intentional inherited/explicit ACEs are not blindly purged.
Final Windows Checkmk script placement
citrix_sessions_customized.ps1, veeam_o365_status.ps1, and veeam_backup_status.ps1 are now consistently deployed as Checkmk custom plugins under C:\ProgramData\checkmk\agent\plugins ($CUSTOM_PLUGINS_PATH$). Their managed execution rules use the custom-plugin path; AIM no longer needs to overwrite Checkmk's built-in plugin tree. veeam_backup_license_status.ps1 is added as a VBR-detected local check under $CUSTOM_LOCAL_PATH$. Selected plugin deployment removes only known historical AIM copies from the old local/built-in locations; unknown files remain untouched.
Windows disk facts
debug_show_disk_usagenow usescommunity.windows.win_disk_factsinstead of a customGet-PSDrivePowerShell collector.- Windows results represent attached local volumes. Mapped/network drives are intentionally outside this host-capacity report.
filesystem_usage_v1is unchanged, so existing add-on renderers do not need a schema migration. Baseline: complete AIM 3.3.0rc8 replacement bundle. Service/wire/event API remains 1.0 and canonical Ansible Core remains 2.19.11.
Native-module audit
This candidate reviews the complete bundled playbook/role tree with a native-module-first rule: if the supported Ansible runtime already exposes the required semantics, AIM delegates to that module instead of maintaining its own shell/PowerShell implementation.
Changes made:
- Windows pending-reboot detection now uses
ansible.windows.win_reboot_infoand publishes its bounded reboot sources instead of AIM-maintained registry heuristics. checkmk_read_windows_confignow usesansible.windows.win_statplusansible.windows.slurp; no PowerShell is used to stat/read the file.- Debian and RedHat package before/after snapshots use
ansible.builtin.package_factsinstead of directdpkg-query/rpm -qacommands. - Linux Checkmk installed-package reporting uses
package_facts; Linux Checkmk runtime state reporting usesservice_factsinstead ofdpkg-query/rpmandsystemctl showfor the final report. - Core/service and terminal dependency preflights now reject
ansible.windowsolder than 3.8.0 before a playbook can rely onwin_reboot_info.
Collection baseline change
ansible.windows.win_reboot_info was introduced in ansible.windows 3.8.0. The release requirements therefore declare:
- name: ansible.windows
version: ">=3.8.0,<4.0.0"
Existing controllers that still have ansible.windows 3.2.x must deliberately update the collection before accepting rc8. AIM still does not install or upgrade collections automatically.
Reboot-state behavior
The Windows preflight now trusts the collection's reboot detector, which covers Windows Update, Component Based Servicing, pending file rename, pending computer rename, domain join and Server Manager sources. The public patch report can include reboot_reasons_before entries containing bounded source and description fields.
Overall patch-wave/reboot policy is unchanged from rc4: one native win_updates wave, AIM-controlled reboot message/delay, and no post-reboot patch wave unless os_patching_rescan_after_reboot was explicitly enabled.
Reviewed custom operations intentionally retained
The audit did not replace custom code where a native module would lose required behavior:
- Windows disk reporting now uses
community.windows.win_disk_factsand reports attached local storage volumes. Mapped/network drives are intentionally excluded from Windows host-capacity reporting. - Windows event-log export keeps a bounded
win_powershellwrapper around the native Windows event export utility because the supported collection does not provide EVTX export with the required time filter. - Checkmk's Windows
plugins:section editor remains custom because AIM must preserve every unmanaged section/comment while replacing only its marked section. - Windows Checkmk installed-version discovery retains a bounded read-only uninstall-registry query because no supported module exposes arbitrary installed MSI/application inventory with the required product matching semantics.
- RedHat reboot-required checks retain
needs-restarting -r; no supported ansible-core module exposes that host state. - Linux Checkmk unit discovery retains
systemctl show LoadStatebecause AIM supports socket activation andservice_factsis service-oriented and is not a reliable replacement for arbitrary socket-unit existence discovery. - pfSense's two
raw sysctloperations remain intentionally bootstrap-safe and do not add a Python/runtime dependency merely to replace two appliance-native calls.
This is therefore a native-first policy, not a prohibition on all commands.
All AIM-owned Markdown/JSON documentation is centralized under scripts/docs/. The release no longer owns the installation-root README.md; an existing root README is preserved during update.