106 lines
6.7 KiB
Markdown
106 lines
6.7 KiB
Markdown
# AIM 3.3.0rc8 controller acceptance
|
|
|
|
Run on disposable/approved targets under the actual execution UID, groups, HOME and
|
|
service sandbox, using native ansible-core 2.19.11 and declared collections. Do not use
|
|
an ordinary root shell as evidence for another worker. Do not send raw Vaults/config
|
|
secrets in test feedback. Keep the staging exceptions from the accepted deployment.
|
|
|
|
## Installation and unchanged controls
|
|
|
|
Verify checksum, preview the deployer, confirm only named obsolete Core docs are removed,
|
|
quiesce jobs/writers and apply. Verify `aim --version`, `aimctl --version`, capabilities,
|
|
independent terminal startup, Vault wrong-then-correct retry and cancellation. Confirm
|
|
operator aim.yml/inventory/keys/add-on state are unchanged. `aimctl staging-check` must
|
|
pass inside the executor, including differing process and passwd homes when relevant.
|
|
|
|
## Discover the new contract without credentials
|
|
|
|
```bash
|
|
aimctl capabilities
|
|
printf '%s\n' '{"api_version":"1.0","operation":"list_playbooks","customer":"CUSTOMER"}' | aimctl request
|
|
printf '%s\n' '{"api_version":"1.0","operation":"prepare","request":{"customer":"CUSTOMER","playbook":"debug_detect_host_roles","hosts":["HOST"]}}' | aimctl request
|
|
```
|
|
|
|
Replace identifiers. Request JSON is one line. Expect operation_results capability and
|
|
prepared result_contract with host_capabilities_v1; unchanged explicit targets/revision.
|
|
Nonreporting `debug_test_connection` must advertise result:null. Unknown options/hosts
|
|
must still fail before launch. Schema changes must stale an earlier preparation.
|
|
|
|
## Fresh approved execution matrix
|
|
|
|
Supply credentials through the established one-run provider/private FD. Use summary
|
|
and detail on separate newly approved runs; compare reports rather than event ordering.
|
|
Do not cache the password or reuse a provider/revision after source changes.
|
|
|
|
| Operation | Evidence required |
|
|
|---|---|
|
|
| Detect roles | Eight booleans agree with authorized native report; no inventory mutation |
|
|
| Disk usage | Compare Windows/Linux observed byte counts; handle unavailable/empty mounts |
|
|
| Export event logs | Paths exist after apply; existing logs not cleared; check creates no export |
|
|
| Start services | Disposable services: one recoverable, one failing dependency/disabled/race case, one excluded; compare before/after states and fixed reasons |
|
|
| Patch OS | Disposable snapshots: verify Linux net package/version changes; Windows uses one native win_updates wave per approved patch stage; IDs/KBs/HRESULTs; user-visible reboot message/delay; default stops after reboot with continuation_required; explicit post-reboot continuation starts another wave |
|
|
| Checkmk cleanup | Preview removes nothing; approved deletion lists only managed files actually changed |
|
|
| Read Checkmk user config | Plugins/local/unknown sections preserved in report; dummy passphrase and MRPE command data redacted; reject other basenames; no timestamp/content write |
|
|
| Checkmk install | Installed version agrees with registry/package DB; services observed; idempotent rerun shows no package/config changes |
|
|
| Checkmk config update | One approved rule/file change reported; second run no change; unrelated local/MRPE/unknown files untouched |
|
|
|
|
New reporting tasks change task counts. Compare effects, failure states and payloads,
|
|
not historical exact ok/skipped totals. For patching, protect against concurrent package
|
|
management and record starting snapshot/selected categories. A partial update still
|
|
requires explicit recovery decisions; never repeat automatically.
|
|
|
|
### Windows patch-wave acceptance
|
|
|
|
Use a disposable Windows target with several applicable updates. Confirm the normal apply
|
|
path contains one `win_updates state=installed` task for the selected categories rather than
|
|
one task per update. Windows/collection-native sequencing inside that wave is expected; AIM
|
|
should not emit `accept_list` selectors for individual discovered updates.
|
|
|
|
Record the structured result and compare it to Windows Update history. Installed and failed
|
|
updates should retain bounded IDs/titles/KBs/HRESULT classifications. A mixed native result
|
|
must not lose successful updates merely because another update failed. Raw failure messages
|
|
or exception text must not enter the operation result.
|
|
|
|
With `os_patching_rescan_after_reboot: false` (catalog default), allow the current wave to
|
|
finish and require reboot. The user should receive the reviewed message/delay. After
|
|
reconnect the run must end without another install/search wave. Expect
|
|
`continuation_required: true` and `remaining_updates_known: false`; a new approved run owns
|
|
the next patch state.
|
|
|
|
Also test a host that begins with an already-pending reboot. With automatic reboot enabled
|
|
and post-reboot continuation false, AIM should reboot and stop before patch installation.
|
|
With continuation true, it may begin the first native update wave after reboot. With
|
|
automatic reboot disabled, it must fail preflight before new installs.
|
|
|
|
Repeat with `os_patching_rescan_after_reboot: true`. After a patch-triggered reboot AIM may
|
|
start another native update wave. Do not infer this opt-in from the reboot flag. Explicit
|
|
continuation remains bounded to 12 waves. A failed wave must stop and must never be replayed
|
|
automatically.
|
|
|
|
For a failed update, confirm `failed_updates` contains only bounded title/ID, unsigned/hex
|
|
HRESULT, reason and fixed message. If `0x80240016` can be reproduced, expect
|
|
`install_not_allowed`; do not expect `preexisting_reboot_required` unless the separate
|
|
preflight actually observed a pending reboot.
|
|
|
|
## Fail-closed fixtures (disposable catalog/playbook only)
|
|
|
|
After each fixture edit, prepare/review anew. Test missing required publisher; wrong
|
|
schema/type/extra fields; publisher under no_log; duplicate publication; >limit data;
|
|
and a supplied secret canary in an output string. Expect no rejected payload in public
|
|
JSON/logs. Native exit 0 with invalid/missing required data must fail at result_validation,
|
|
retain exit_code 0/native target facts and never replay. No declaration must export
|
|
nothing even if unrelated debug/custom stats contain a secret.
|
|
|
|
Test two targets with one unreachable and one completed report. Overall native failure
|
|
remains; one available report does not imply all-target success. Test Ctrl+C mid-run:
|
|
report must not claim earlier observations are completed output. Ensure no residual
|
|
credential/helper process and a subsequent fresh operation works. Test chunked output
|
|
beyond a single private frame; a torn stream must fail, never silently truncate.
|
|
|
|
## Sign-off
|
|
|
|
Record version, execution UID/group context, runtime/collection versions, platform and
|
|
which cases were tested, separately for native terminal and service. Do not mark global
|
|
transport, another OS, Server 2012 R2 or another service identity accepted from one Windows
|
|
11 test. Report final status/exit/target facts/report availability with credentials removed.
|