Files
Ansible/docs/OPERATIONS.md
T
2026-09-15 18:53:28 +02:00

2.9 KiB

AIM Operations Guide

Navigation

AIM is organized around a customer context:

Customer
├── Hosts Management
├── Access Management
├── Vault Management
├── Group Variables
├── Host Variables
├── Playbooks
└── Administration

For numbered navigation menus, Enter or 0 means Back/Cancel; at the main menu it means Exit. Single selectors use Enter/0 to cancel. Multi-select uses numbers to toggle, Enter to review, and 0 to cancel. Paginated views use p / n for Previous / Next.

Customer overview

Opening a customer should provide local information without unexpectedly contacting hosts, running Ansible or decrypting Vaults. The dashboard includes inventory YAML state, Vault presence, host/platform counts and available customer defaults.

Hosts

hosts.yml is the source of truth.

Creating a host also ensures:

host_vars/<fqdn>/main.yml

For ordinary non-Sophos hosts this file may be empty. Existing host variable files are not overwritten. Removing a host also removes its corresponding host-vars directory.

Routine add/update/remove operations perform local YAML validation and do not request the Vault password.

Access Management

Linux access manages SSH keys/service-user access.

Windows access includes temporary WinRM testing, local account creation, domain account creation/repair, member-server domain access, domain WinRM GPO rollout and configured-service-user testing.

See WINDOWS.md for the Windows model.

Vault Management

Vault operations include information, create, edit and delete.

A new Vault is populated as plaintext with mode 0600, YAML-validated, then encrypted using:

ansible-vault encrypt --vault-id <customer>@prompt vault.yml

A failed encryption must not leave populated plaintext secrets behind.

Variables

Group and host variable views are generally operator-readable without AIM rewriting arbitrary custom configuration. AIM only changes values in workflows explicitly designed to do so.

Template consolidation is explicit and non-destructive: missing AIM defaults/comments can be added, while existing non-empty values and custom keys are retained.

Playbooks

Curated categories include CheckMK, Debug, Maintenance and Sophos XGS. Compatible host/group selection is used to build the Ansible --limit.

Interactive playbooks and operations that require password/Vault prompts retain live terminal access.

Administration

Administration includes inventory validation, template consolidation, recovery and customer defaults.

Explicit inventory validation performs YAML parsing and ansible-inventory. When a customer Vault exists, validation uses the customer's Vault identity and may prompt for its password.

AIM maintains one pre-change inventory recovery backup per inventory per AIM process/session:

hosts.aim-session.bak.yml

Restores are explicit and YAML-validated.