1013 lines
29 KiB
YAML
1013 lines
29 KiB
YAML
# AIM playbook catalog, not an executable playbook. No credentials belong in this file.
|
|
# Only explicit run-time overrides are passed by AIM; inventory and role defaults remain authoritative.
|
|
schema_version: 1
|
|
release: 3.3.0rc8
|
|
categories:
|
|
- Checkmk
|
|
- Debug
|
|
- Maintenance
|
|
- Sophos XGS
|
|
- pfSense
|
|
playbooks:
|
|
- key: checkmk_install_agent
|
|
name: Install Checkmk agent
|
|
filename: checkmk_install_agent.yml
|
|
category: Checkmk
|
|
platforms:
|
|
- linux
|
|
- windows
|
|
description: Install staged agent packages, deploy selected checks, render
|
|
Windows settings and ensure the agent is running.
|
|
inputs:
|
|
- name: aim_debug
|
|
label: Safe diagnostics
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Only selected non-secret diagnostics; normal outcomes stay visible.
|
|
- name: checkmk_unifi_mode
|
|
label: UniFi application
|
|
type: choice
|
|
default_hint: auto
|
|
help: Automatic detection prefers UniFi OS when present; only one local
|
|
check/config is deployed.
|
|
platforms:
|
|
- linux
|
|
choices:
|
|
- auto
|
|
- network
|
|
- os
|
|
- disabled
|
|
- name: checkmk_unifi_username
|
|
label: UniFi monitoring username
|
|
type: text
|
|
default_hint: bf-monitoring
|
|
help: ''
|
|
platforms:
|
|
- linux
|
|
- name: checkmk_unifi_password
|
|
label: UniFi password variable
|
|
type: secret_ref
|
|
default_hint: vault_checkmk_unifi_password
|
|
help: Enter a Vault variable name, never its password. Required when a UniFi
|
|
check is selected.
|
|
platforms:
|
|
- linux
|
|
- name: checkmk_unifi_baseurl
|
|
label: UniFi controller URL
|
|
type: url
|
|
default_hint: 'network: https://127.0.0.1:8443; os: https://127.0.0.1:11443'
|
|
help: An explicit URL overrides the mode-specific default.
|
|
platforms:
|
|
- linux
|
|
- name: checkmk_unifi_curl_options
|
|
label: UniFi curl options
|
|
type: text
|
|
default_hint: ' --insecure --tlsv1.2'
|
|
help: Preserves the supplied TLS options. The shell configuration is safely
|
|
quoted.
|
|
platforms:
|
|
- linux
|
|
- name: want_linux_check_certificate
|
|
label: Certificate directory check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- linux
|
|
- name: want_windows_citrix
|
|
label: Citrix sessions check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: want_windows_surebackup
|
|
label: Veeam SureBackup check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: want_windows_backup
|
|
label: Windows Backup check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: want_windows_nsp_mailqueue
|
|
label: NSP mail queue check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: want_windows_certificate
|
|
label: Windows certificate check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: want_windows_veeam_cloud_connect
|
|
label: Veeam Cloud Connect check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: want_windows_veeam_backup
|
|
label: Repository Veeam backup plugin
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: checkmk_unifi_status_provisioning
|
|
label: 'UniFi status: provisioning'
|
|
type: int
|
|
default_hint: '1'
|
|
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
|
|
platforms:
|
|
- linux
|
|
minimum: 0
|
|
maximum: 3
|
|
- name: checkmk_unifi_status_upgrading
|
|
label: 'UniFi status: upgrading'
|
|
type: int
|
|
default_hint: '1'
|
|
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
|
|
platforms:
|
|
- linux
|
|
minimum: 0
|
|
maximum: 3
|
|
- name: checkmk_unifi_status_upgradable
|
|
label: 'UniFi status: upgradable'
|
|
type: int
|
|
default_hint: '0'
|
|
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
|
|
platforms:
|
|
- linux
|
|
minimum: 0
|
|
maximum: 3
|
|
- name: checkmk_unifi_status_heartbeat_missed
|
|
label: 'UniFi status: heartbeat_missed'
|
|
type: int
|
|
default_hint: '1'
|
|
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
|
|
platforms:
|
|
- linux
|
|
minimum: 0
|
|
maximum: 3
|
|
- name: checkmk_unifi_status_noautobackup
|
|
label: 'UniFi status: noautobackup'
|
|
type: int
|
|
default_hint: '0'
|
|
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
|
|
platforms:
|
|
- linux
|
|
minimum: 0
|
|
maximum: 3
|
|
- name: checkmk_windows_updates_timeout
|
|
label: Windows Updates timeout
|
|
type: int
|
|
default_hint: '3600'
|
|
help: Seconds. Unchanged options continue to inherit inventory/defaults.
|
|
platforms:
|
|
- windows
|
|
minimum: 0
|
|
- name: checkmk_windows_updates_cache
|
|
label: Windows Updates cache
|
|
type: int
|
|
default_hint: '43200'
|
|
help: Seconds. Unchanged options continue to inherit inventory/defaults.
|
|
platforms:
|
|
- windows
|
|
minimum: 0
|
|
- name: checkmk_mk_inventory_timeout
|
|
label: Inventory plugin timeout
|
|
type: int
|
|
default_hint: '120'
|
|
help: Seconds. Unchanged options continue to inherit inventory/defaults.
|
|
platforms:
|
|
- windows
|
|
minimum: 0
|
|
- name: checkmk_plugins_default_timeout
|
|
label: Plugin default timeout
|
|
type: int
|
|
default_hint: '120'
|
|
help: Seconds. Unchanged options continue to inherit inventory/defaults.
|
|
platforms:
|
|
- windows
|
|
minimum: 0
|
|
- name: checkmk_plugins_default_cache
|
|
label: Plugin default cache
|
|
type: int
|
|
default_hint: '600'
|
|
help: Seconds. Unchanged options continue to inherit inventory/defaults.
|
|
platforms:
|
|
- windows
|
|
minimum: 0
|
|
- name: checkmk_extra_plugin_patterns
|
|
label: Extra Windows plugin rules
|
|
type: sequence
|
|
default_hint: '[]'
|
|
help: YAML/JSON list of rule mappings; see role documentation.
|
|
platforms:
|
|
- windows
|
|
become_platforms:
|
|
- linux
|
|
warning: Installs packages and replaces AIM-managed script files. On Windows,
|
|
AIM replaces only the marked plugins section in check_mk.user.yml; other
|
|
user-config sections are preserved. UniFi deployment also removes the
|
|
alternative UniFi local check; no other cleanup is performed.
|
|
requirements:
|
|
- ansible.windows
|
|
result:
|
|
protocol: aim_output_v1
|
|
schema: checkmk_agent_state_v1
|
|
scope: per_host
|
|
required: true
|
|
sensitivity: safe
|
|
max_bytes_per_host: 1048576
|
|
schema_file: checkmk_agent_state_v1.yml
|
|
- key: checkmk_update_scripts_config
|
|
name: Update Checkmk scripts and configuration
|
|
filename: checkmk_update_scripts_config.yml
|
|
category: Checkmk
|
|
platforms:
|
|
- linux
|
|
- windows
|
|
description: Deploy selected checks and Windows configuration without
|
|
installing agent packages.
|
|
inputs:
|
|
- name: aim_debug
|
|
label: Safe diagnostics
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Only selected non-secret diagnostics; normal outcomes stay visible.
|
|
- name: checkmk_unifi_mode
|
|
label: UniFi application
|
|
type: choice
|
|
default_hint: auto
|
|
help: Automatic detection prefers UniFi OS when present; only one local
|
|
check/config is deployed.
|
|
platforms:
|
|
- linux
|
|
choices:
|
|
- auto
|
|
- network
|
|
- os
|
|
- disabled
|
|
- name: checkmk_unifi_username
|
|
label: UniFi monitoring username
|
|
type: text
|
|
default_hint: bf-monitoring
|
|
help: ''
|
|
platforms:
|
|
- linux
|
|
- name: checkmk_unifi_password
|
|
label: UniFi password variable
|
|
type: secret_ref
|
|
default_hint: vault_checkmk_unifi_password
|
|
help: Enter a Vault variable name, never its password. Required when a UniFi
|
|
check is selected.
|
|
platforms:
|
|
- linux
|
|
- name: checkmk_unifi_baseurl
|
|
label: UniFi controller URL
|
|
type: url
|
|
default_hint: 'network: https://127.0.0.1:8443; os: https://127.0.0.1:11443'
|
|
help: An explicit URL overrides the mode-specific default.
|
|
platforms:
|
|
- linux
|
|
- name: checkmk_unifi_curl_options
|
|
label: UniFi curl options
|
|
type: text
|
|
default_hint: ' --insecure --tlsv1.2'
|
|
help: Preserves the supplied TLS options. The shell configuration is safely
|
|
quoted.
|
|
platforms:
|
|
- linux
|
|
- name: want_linux_check_certificate
|
|
label: Certificate directory check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- linux
|
|
- name: want_windows_citrix
|
|
label: Citrix sessions check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: want_windows_surebackup
|
|
label: Veeam SureBackup check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: want_windows_backup
|
|
label: Windows Backup check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: want_windows_nsp_mailqueue
|
|
label: NSP mail queue check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: want_windows_certificate
|
|
label: Windows certificate check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: want_windows_veeam_cloud_connect
|
|
label: Veeam Cloud Connect check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: want_windows_veeam_backup
|
|
label: Repository Veeam backup plugin
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: checkmk_unifi_status_provisioning
|
|
label: 'UniFi status: provisioning'
|
|
type: int
|
|
default_hint: '1'
|
|
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
|
|
platforms:
|
|
- linux
|
|
minimum: 0
|
|
maximum: 3
|
|
- name: checkmk_unifi_status_upgrading
|
|
label: 'UniFi status: upgrading'
|
|
type: int
|
|
default_hint: '1'
|
|
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
|
|
platforms:
|
|
- linux
|
|
minimum: 0
|
|
maximum: 3
|
|
- name: checkmk_unifi_status_upgradable
|
|
label: 'UniFi status: upgradable'
|
|
type: int
|
|
default_hint: '0'
|
|
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
|
|
platforms:
|
|
- linux
|
|
minimum: 0
|
|
maximum: 3
|
|
- name: checkmk_unifi_status_heartbeat_missed
|
|
label: 'UniFi status: heartbeat_missed'
|
|
type: int
|
|
default_hint: '1'
|
|
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
|
|
platforms:
|
|
- linux
|
|
minimum: 0
|
|
maximum: 3
|
|
- name: checkmk_unifi_status_noautobackup
|
|
label: 'UniFi status: noautobackup'
|
|
type: int
|
|
default_hint: '0'
|
|
help: 0 OK, 1 WARN, 2 CRIT, 3 UNKNOWN.
|
|
platforms:
|
|
- linux
|
|
minimum: 0
|
|
maximum: 3
|
|
- name: checkmk_windows_updates_timeout
|
|
label: Windows Updates timeout
|
|
type: int
|
|
default_hint: '3600'
|
|
help: Seconds. Unchanged options continue to inherit inventory/defaults.
|
|
platforms:
|
|
- windows
|
|
minimum: 0
|
|
- name: checkmk_windows_updates_cache
|
|
label: Windows Updates cache
|
|
type: int
|
|
default_hint: '43200'
|
|
help: Seconds. Unchanged options continue to inherit inventory/defaults.
|
|
platforms:
|
|
- windows
|
|
minimum: 0
|
|
- name: checkmk_mk_inventory_timeout
|
|
label: Inventory plugin timeout
|
|
type: int
|
|
default_hint: '120'
|
|
help: Seconds. Unchanged options continue to inherit inventory/defaults.
|
|
platforms:
|
|
- windows
|
|
minimum: 0
|
|
- name: checkmk_plugins_default_timeout
|
|
label: Plugin default timeout
|
|
type: int
|
|
default_hint: '120'
|
|
help: Seconds. Unchanged options continue to inherit inventory/defaults.
|
|
platforms:
|
|
- windows
|
|
minimum: 0
|
|
- name: checkmk_plugins_default_cache
|
|
label: Plugin default cache
|
|
type: int
|
|
default_hint: '600'
|
|
help: Seconds. Unchanged options continue to inherit inventory/defaults.
|
|
platforms:
|
|
- windows
|
|
minimum: 0
|
|
- name: checkmk_extra_plugin_patterns
|
|
label: Extra Windows plugin rules
|
|
type: sequence
|
|
default_hint: '[]'
|
|
help: YAML/JSON list of rule mappings; see role documentation.
|
|
platforms:
|
|
- windows
|
|
become_platforms:
|
|
- linux
|
|
warning: Deploys AIM-managed script files and, on Windows, replaces only the
|
|
marked plugins section in check_mk.user.yml. Other user-config sections are
|
|
preserved. Only the opposite UniFi check is removed during a UniFi mode
|
|
transition.
|
|
requirements:
|
|
- ansible.windows
|
|
result:
|
|
protocol: aim_output_v1
|
|
schema: checkmk_agent_config_v1
|
|
scope: per_host
|
|
required: true
|
|
sensitivity: safe
|
|
max_bytes_per_host: 1048576
|
|
schema_file: checkmk_agent_config_v1.yml
|
|
- key: checkmk_read_windows_config
|
|
name: Read Windows Checkmk config
|
|
filename: checkmk_read_windows_config.yml
|
|
category: Checkmk
|
|
platforms:
|
|
- windows
|
|
description: Display the current Windows check_mk.user.yml, including its path
|
|
and file metadata, without modifying the host.
|
|
inputs:
|
|
- name: aim_debug
|
|
label: Safe diagnostics
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Only selected non-secret diagnostics; normal outcomes stay visible.
|
|
- name: checkmk_windows_user_cfg
|
|
label: Checkmk user config path
|
|
type: text
|
|
default_hint: C:\ProgramData\checkmk\agent\check_mk.user.yml
|
|
help: Override only when the Windows agent uses a nonstandard
|
|
user-configuration path.
|
|
platforms:
|
|
- windows
|
|
requirements:
|
|
- ansible.windows
|
|
result:
|
|
protocol: aim_output_v1
|
|
schema: checkmk_user_config_v1
|
|
scope: per_host
|
|
required: true
|
|
sensitivity: safe
|
|
max_bytes_per_host: 1048576
|
|
schema_file: checkmk_user_config_v1.yml
|
|
- key: checkmk_cleanup_scripts
|
|
name: Preview / clean up Checkmk scripts
|
|
filename: checkmk_cleanup_scripts.yml
|
|
category: Checkmk
|
|
platforms:
|
|
- linux
|
|
- windows
|
|
description: List obsolete managed script paths; remove them only with
|
|
explicit deletion approval.
|
|
inputs:
|
|
- name: aim_debug
|
|
label: Safe diagnostics
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Only selected non-secret diagnostics; normal outcomes stay visible.
|
|
- name: checkmk_cleanup_enabled
|
|
label: Permit managed-script deletion
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Required for cleanup execution. False previews candidate paths without
|
|
deleting them.
|
|
- name: checkmk_unifi_mode
|
|
label: UniFi application
|
|
type: choice
|
|
default_hint: auto
|
|
help: Automatic detection prefers UniFi OS when present; only one local
|
|
check/config is deployed.
|
|
platforms:
|
|
- linux
|
|
choices:
|
|
- auto
|
|
- network
|
|
- os
|
|
- disabled
|
|
- name: want_linux_check_certificate
|
|
label: Certificate directory check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- linux
|
|
- name: want_windows_citrix
|
|
label: Citrix sessions check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: want_windows_surebackup
|
|
label: Veeam SureBackup check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: want_windows_backup
|
|
label: Windows Backup check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: want_windows_nsp_mailqueue
|
|
label: NSP mail queue check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: want_windows_certificate
|
|
label: Windows certificate check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: want_windows_veeam_cloud_connect
|
|
label: Veeam Cloud Connect check
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
- name: want_windows_veeam_backup
|
|
label: Repository Veeam backup plugin
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Optional check. Script-specific setup remains in the maintained script
|
|
repository.
|
|
platforms:
|
|
- windows
|
|
become_platforms:
|
|
- linux
|
|
warning: Cleanup only touches the documented managed filenames. Preview is the
|
|
default; enabling deletion requires another confirmation.
|
|
requirements:
|
|
- ansible.windows
|
|
result:
|
|
protocol: aim_output_v1
|
|
schema: managed_cleanup_preview_v1
|
|
scope: per_host
|
|
required: true
|
|
sensitivity: safe
|
|
max_bytes_per_host: 1048576
|
|
schema_file: managed_cleanup_preview_v1.yml
|
|
- key: debug_test_connection
|
|
name: Test Ansible connection
|
|
filename: debug_test_connection.yml
|
|
category: Debug
|
|
platforms:
|
|
- linux
|
|
- windows
|
|
description: Check Ansible manageability using ping or win_ping; this is not
|
|
an ICMP ping.
|
|
inputs:
|
|
- name: aim_debug
|
|
label: Safe diagnostics
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Only selected non-secret diagnostics; normal outcomes stay visible.
|
|
requirements:
|
|
- ansible.windows
|
|
- key: debug_show_disk_usage
|
|
name: Show disk usage
|
|
filename: debug_show_disk_usage.yml
|
|
category: Debug
|
|
platforms:
|
|
- linux
|
|
- windows
|
|
description: Report attached Windows storage volumes and common operational Linux mounts, including network/storage filesystems.
|
|
inputs:
|
|
- name: aim_debug
|
|
label: Safe diagnostics
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Only selected non-secret diagnostics; normal outcomes stay visible.
|
|
requirements:
|
|
- ansible.windows
|
|
- community.windows
|
|
result:
|
|
protocol: aim_output_v1
|
|
schema: filesystem_usage_v1
|
|
scope: per_host
|
|
required: true
|
|
sensitivity: safe
|
|
max_bytes_per_host: 1048576
|
|
schema_file: filesystem_usage_v1.yml
|
|
- key: debug_detect_host_roles
|
|
name: Detect host roles
|
|
filename: debug_detect_host_roles.yml
|
|
category: Debug
|
|
platforms:
|
|
- linux
|
|
- windows
|
|
description: Report detected AD, DHCP, Hyper-V, Veeam and UniFi capabilities
|
|
without changing inventory memberships.
|
|
inputs:
|
|
- name: aim_debug
|
|
label: Safe diagnostics
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Only selected non-secret diagnostics; normal outcomes stay visible.
|
|
requirements:
|
|
- ansible.windows
|
|
result:
|
|
protocol: aim_output_v1
|
|
schema: host_capabilities_v1
|
|
scope: per_host
|
|
required: true
|
|
sensitivity: safe
|
|
max_bytes_per_host: 1048576
|
|
schema_file: host_capabilities_v1.yml
|
|
- key: maintenance_export_event_logs
|
|
name: Export Windows event logs
|
|
filename: maintenance_export_event_logs.yml
|
|
category: Maintenance
|
|
platforms:
|
|
- windows
|
|
description: Export selected event channels to EVTX files on the target;
|
|
existing event logs are not cleared.
|
|
inputs:
|
|
- name: aim_debug
|
|
label: Safe diagnostics
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Only selected non-secret diagnostics; normal outcomes stay visible.
|
|
- name: event_age_days
|
|
label: Event age in days
|
|
type: int
|
|
default_hint: '45'
|
|
help: Export events from the last N days, without clearing the logs.
|
|
minimum: 1
|
|
maximum: 36500
|
|
- name: export_folder
|
|
label: Target export folder
|
|
type: text
|
|
default_hint: C:\Logs
|
|
help: Directory on each Windows target, not on the Ansible controller.
|
|
- name: event_log_channels
|
|
label: Event channels
|
|
type: list
|
|
default_hint: Application, Security, System, Setup
|
|
help: Event channels to export.
|
|
requirements:
|
|
- ansible.windows
|
|
result:
|
|
protocol: aim_output_v1
|
|
schema: event_log_export_v1
|
|
scope: per_host
|
|
required: true
|
|
sensitivity: safe
|
|
max_bytes_per_host: 1048576
|
|
schema_file: event_log_export_v1.yml
|
|
- key: maintenance_start_stopped_services
|
|
name: Start stopped automatic services
|
|
filename: maintenance_start_stopped_services.yml
|
|
category: Maintenance
|
|
platforms:
|
|
- windows
|
|
description: Start eligible stopped services, apply optional include/exclude
|
|
lists and report partial failures.
|
|
inputs:
|
|
- name: aim_debug
|
|
label: Safe diagnostics
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Only selected non-secret diagnostics; normal outcomes stay visible.
|
|
- name: maintenance_service_include
|
|
label: Service allowlist
|
|
type: list
|
|
default_hint: '[]'
|
|
help: Empty list selects all stopped automatic/delayed-start services; use
|
|
internal service names.
|
|
- name: maintenance_service_exclude
|
|
label: Service exclusions
|
|
type: list
|
|
default_hint: '[]'
|
|
help: Excluded internal service names are never started.
|
|
- name: maintenance_service_fail_on_error
|
|
label: Fail after partial failure
|
|
type: bool
|
|
default_hint: 'true'
|
|
help: Always reports individual failures; true makes the final task fail
|
|
when any start failed.
|
|
requirements:
|
|
- ansible.windows
|
|
result:
|
|
protocol: aim_output_v1
|
|
schema: service_start_summary_v1
|
|
scope: per_host
|
|
required: true
|
|
sensitivity: safe
|
|
max_bytes_per_host: 1048576
|
|
schema_file: service_start_summary_v1.yml
|
|
- key: maintenance_patch_os
|
|
name: Patch operating systems
|
|
filename: maintenance_patch_os.yml
|
|
category: Maintenance
|
|
platforms:
|
|
- linux
|
|
- windows
|
|
description: Apply updates on Windows, Debian and RedHat-family systems;
|
|
optionally notify users and reboot when required.
|
|
inputs:
|
|
- name: aim_debug
|
|
label: Safe diagnostics
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Only selected non-secret diagnostics; normal outcomes stay visible.
|
|
- name: os_patching_reboot
|
|
label: Reboot when required
|
|
type: bool
|
|
default_hint: 'true'
|
|
help: Patching may reboot each selected host. False installs without an
|
|
automatic reboot.
|
|
- name: os_patching_windows_categories
|
|
label: Windows update categories
|
|
type: list
|
|
default_hint: SecurityUpdates, CriticalUpdates, UpdateRollups,
|
|
DefinitionUpdates, Updates
|
|
help: Enter a YAML/JSON list or comma-separated category names.
|
|
platforms:
|
|
- windows
|
|
choices:
|
|
- SecurityUpdates
|
|
- CriticalUpdates
|
|
- UpdateRollups
|
|
- DefinitionUpdates
|
|
- Updates
|
|
- Drivers
|
|
- FeaturePacks
|
|
- ServicePacks
|
|
- Tools
|
|
- Upgrades
|
|
- '*'
|
|
- name: os_patching_serial
|
|
label: Batch size
|
|
type: serial
|
|
default_hint: 100%
|
|
help: Positive host count or percentage. Applies independently to each
|
|
platform play.
|
|
- name: os_patching_reboot_timeout
|
|
label: Reboot timeout
|
|
type: int
|
|
default_hint: '600'
|
|
help: Seconds to wait for a Windows/Linux host to reboot and become
|
|
manageable again.
|
|
minimum: 1
|
|
- name: os_patching_reboot_delay_minutes
|
|
label: Reboot delay (minutes)
|
|
type: int
|
|
default_hint: '0'
|
|
help: Delay before an AIM-initiated reboot. Linux scheduling is
|
|
minute-granular; 0 requests immediate/platform-minimum reboot.
|
|
minimum: 0
|
|
maximum: 1440
|
|
- name: os_patching_reboot_message
|
|
label: Reboot message
|
|
type: text
|
|
default_hint: 'AIM maintenance: operating system patching requires a reboot.'
|
|
help: Message shown to logged-in users before an AIM-initiated Windows/Linux
|
|
reboot.
|
|
- name: os_patching_rescan_after_reboot
|
|
label: Continue patching after reboot
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Windows only. False stops after the first patch-triggered reboot so the next
|
|
patch wave requires a new operator-approved run. True rediscovers applicable
|
|
updates after reboot and starts another native Windows Update wave.
|
|
platforms:
|
|
- windows
|
|
become_platforms:
|
|
- linux
|
|
warning: Updates production operating systems. Windows uses the native win_updates wave behavior with AIM-controlled reboots. A reboot boundary stops the run by default; continuing into a newly discovered post-reboot wave requires explicit opt-in. If automatic reboot is disabled, a newly required reboot is reported as deferred.
|
|
requirements:
|
|
- ansible.windows
|
|
result:
|
|
protocol: aim_output_v1
|
|
schema: patch_summary_v1
|
|
scope: per_host
|
|
required: true
|
|
sensitivity: safe
|
|
max_bytes_per_host: 1048576
|
|
schema_file: patch_summary_v1.yml
|
|
- key: maintenance_reboot_hosts
|
|
name: Reboot hosts
|
|
filename: maintenance_reboot_hosts.yml
|
|
category: Maintenance
|
|
platforms:
|
|
- linux
|
|
- windows
|
|
description: Reboot selected hosts in batches and wait for management
|
|
connectivity.
|
|
inputs:
|
|
- name: aim_debug
|
|
label: Safe diagnostics
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Only selected non-secret diagnostics; normal outcomes stay visible.
|
|
- name: maintenance_reboot_serial
|
|
label: Batch size
|
|
type: serial
|
|
default_hint: '10'
|
|
help: Positive host count or percentage.
|
|
- name: maintenance_reboot_timeout
|
|
label: Reboot timeout
|
|
type: int
|
|
default_hint: '1800'
|
|
help: Seconds.
|
|
minimum: 1
|
|
- name: maintenance_reboot_message
|
|
label: Reboot message
|
|
type: text
|
|
default_hint: Reboot initiated by debsansible01.bfmiglabor.lan (Ansible)
|
|
help: ''
|
|
- name: maintenance_reboot_pre_delay
|
|
label: Delay before reboot
|
|
type: int
|
|
default_hint: '0'
|
|
help: Seconds; Windows enforces a minimum of two seconds.
|
|
minimum: 0
|
|
- name: maintenance_reboot_post_delay
|
|
label: Delay after reboot
|
|
type: int
|
|
default_hint: '15'
|
|
help: Seconds.
|
|
minimum: 0
|
|
become_platforms:
|
|
- linux
|
|
warning: Every selected host will be rebooted. No reboot occurs before final
|
|
confirmation.
|
|
requirements:
|
|
- ansible.windows
|
|
- key: sophos_apply_baseline
|
|
name: Apply bitformer Sophos baseline
|
|
filename: sophos_apply_baseline.yml
|
|
category: Sophos XGS
|
|
platforms:
|
|
- sophosxgs
|
|
description: Apply the supplied bitformer firewall baseline. Existing policy
|
|
values and action order are preserved.
|
|
inputs:
|
|
- name: aim_debug
|
|
label: Safe diagnostics
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Only selected non-secret diagnostics; normal outcomes stay visible.
|
|
ask_pass: true
|
|
require_vault: true
|
|
warning: Changes firewall management access, objects and rules, including rule
|
|
removal and a final drop rule. Policy values have NOT been redesigned.
|
|
requirements:
|
|
- ansible.netcommon
|
|
- sophos.sophos_firewall
|
|
- key: sophos_apply_customer
|
|
name: Apply customer Sophos configuration
|
|
filename: sophos_apply_customer.yml
|
|
category: Sophos XGS
|
|
platforms:
|
|
- sophosxgs
|
|
description: Apply this customer profile using hostname, network_objects and
|
|
vlan_interfaces from inventory.
|
|
inputs:
|
|
- name: aim_debug
|
|
label: Safe diagnostics
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Only selected non-secret diagnostics; normal outcomes stay visible.
|
|
ask_pass: true
|
|
require_vault: true
|
|
customer_specific: true
|
|
warning: Changes customer firewall configuration. VLAN parent remains Port1 as
|
|
in the supplied playbooks. Only this customer profile is selected.
|
|
requirements:
|
|
- ansible.netcommon
|
|
- sophos.sophos_firewall
|
|
- key: pfsense_apply_baseline
|
|
name: Apply bitformer pfSense baseline
|
|
filename: pfsense_apply_baseline.yml
|
|
category: pfSense
|
|
platforms:
|
|
- pfsense
|
|
description: Apply the supplied pfSense baseline without changing its
|
|
firewall/VPN policy.
|
|
inputs:
|
|
- name: aim_debug
|
|
label: Safe diagnostics
|
|
type: bool
|
|
default_hint: 'false'
|
|
help: Only selected non-secret diagnostics; normal outcomes stay visible.
|
|
become_platforms:
|
|
- pfsense
|
|
warning: Contains the original any-source WAN management rule for ports
|
|
22/80/443. The original CA, VPN endpoint and client certificate reference
|
|
are unchanged; verify them before execution. Requires separately approved
|
|
pfsensible.core installation.
|
|
requirements:
|
|
- pfsensible.core
|
|
sophos_profiles:
|
|
bluuunit:
|
|
required_network_keys:
|
|
- derz_lan
|
|
- derz_sslvpn
|
|
- facility
|
|
- guest
|
|
- lan_old
|
|
- management
|
|
- office
|
|
- server
|
|
- voip
|
|
vlan_parent: Port1
|
|
formicon:
|
|
required_network_keys:
|
|
- azuregwc_lan
|
|
- lan_old
|
|
- management
|
|
- office
|
|
vlan_parent: Port1
|
|
gebhardt_stahl:
|
|
required_network_keys:
|
|
- drucker
|
|
- guest
|
|
- office
|
|
- wlan
|
|
vlan_parent: Port1
|
|
hungeling_und_toechter:
|
|
required_network_keys:
|
|
- facility
|
|
- guest
|
|
- management
|
|
- office
|
|
- voip
|
|
vlan_parent: Port1
|
|
koenig_holding_gmbh:
|
|
required_network_keys:
|
|
- facility
|
|
- guest
|
|
- management
|
|
- office
|
|
- server
|
|
- voip
|
|
vlan_parent: Port1
|