136 lines
5.9 KiB
YAML
136 lines
5.9 KiB
YAML
# PURPOSE: Update Checkmk scripts and configuration
|
|
# DESCRIPTION: Deploy selected checks and Windows configuration without installing agent packages.
|
|
# TARGETS: linux, windows
|
|
# INPUTS (omitted values inherit inventory / role defaults):
|
|
# aim_debug [bool]: false
|
|
# checkmk_unifi_mode [choice]: auto
|
|
# checkmk_unifi_username [text]: bf-monitoring
|
|
# checkmk_unifi_password [secret_ref]: vault_checkmk_unifi_password
|
|
# checkmk_unifi_baseurl [url]: network: https://127.0.0.1:8443; os: https://127.0.0.1:11443
|
|
# checkmk_unifi_curl_options [text]: --insecure --tlsv1.2
|
|
# want_linux_check_certificate [bool]: false
|
|
# want_windows_citrix [bool]: false
|
|
# want_windows_surebackup [bool]: false
|
|
# want_windows_backup [bool]: false
|
|
# want_windows_nsp_mailqueue [bool]: false
|
|
# want_windows_certificate [bool]: false
|
|
# want_windows_veeam_cloud_connect [bool]: false
|
|
# want_windows_veeam_backup [bool]: false
|
|
# checkmk_unifi_status_provisioning [int]: 1
|
|
# checkmk_unifi_status_upgrading [int]: 1
|
|
# checkmk_unifi_status_upgradable [int]: 0
|
|
# checkmk_unifi_status_heartbeat_missed [int]: 1
|
|
# checkmk_unifi_status_noautobackup [int]: 0
|
|
# checkmk_windows_updates_timeout [int]: 3600
|
|
# checkmk_windows_updates_cache [int]: 43200
|
|
# checkmk_mk_inventory_timeout [int]: 120
|
|
# checkmk_plugins_default_timeout [int]: 120
|
|
# checkmk_plugins_default_cache [int]: 600
|
|
# checkmk_extra_plugin_patterns [sequence]: []
|
|
# AUTH: existing inventory / Vault credentials; no embedded passwords.
|
|
# CHANGES: AIM-managed script files are updated. On Windows only the marked plugins section in check_mk.user.yml is replaced; all other user-config sections are preserved. Only the opposite UniFi check is removed during a UniFi mode transition.
|
|
# EXAMPLE: ansible-playbook -i inventories/<customer>/hosts.yml
|
|
# playbooks/checkmk_update_scripts_config.yml --limit <host> --vault-id <customer>@prompt
|
|
- name: Checkmk | Update linux
|
|
hosts: linux
|
|
gather_facts: true
|
|
pre_tasks:
|
|
- name: AIM | Validate diagnostics option
|
|
ansible.builtin.assert:
|
|
that:
|
|
- (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in
|
|
['true', 'false']
|
|
fail_msg: aim_debug must be a YAML/JSON boolean.
|
|
quiet: true
|
|
- name: AIM | Reject mixed platform membership
|
|
ansible.builtin.assert:
|
|
that:
|
|
- (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1
|
|
fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups.
|
|
quiet: true
|
|
- name: AIM | Execution context
|
|
ansible.builtin.debug:
|
|
msg:
|
|
host: '{{ inventory_hostname }}'
|
|
diagnostics: Enabled; secret values are never included by this task.
|
|
when: aim_debug | default(false) | bool
|
|
- name: Load system detect roles
|
|
ansible.builtin.include_role:
|
|
name: system_detect_roles
|
|
- name: Load checkmk script plan
|
|
ansible.builtin.include_role:
|
|
name: checkmk_script_plan
|
|
- name: Checkmk | Preflight scripts and credentials
|
|
ansible.builtin.include_role:
|
|
name: checkmk_deploy_scripts
|
|
tasks_from: preflight
|
|
become: true
|
|
roles:
|
|
- role: checkmk_deploy_scripts
|
|
- role: checkmk_configure_agent
|
|
- role: checkmk_manage_service
|
|
post_tasks:
|
|
- &id001
|
|
name: Checkmk | Collect managed change summary
|
|
ansible.builtin.set_fact:
|
|
_aim_checkmk_changes: '{{ _aim_check_copies | default({}) | aim_report_checkmk_changes(_checkmk_selected_scripts,
|
|
_checkmk_plugins_update | default({}), _aim_unifi_write | default({}), _aim_opposite_remove | default({}),
|
|
_checkmk_unifi_effective, ansible_check_mode) }}'
|
|
- name: AIM | Publish operation result
|
|
ansible.builtin.set_stats:
|
|
per_host: true
|
|
aggregate: false
|
|
data:
|
|
aim_output:
|
|
protocol: aim_output_v1
|
|
schema: checkmk_agent_config_v1
|
|
data: '{{ _aim_checkmk_changes }}'
|
|
- name: Checkmk | Update windows
|
|
hosts: windows
|
|
gather_facts: true
|
|
pre_tasks:
|
|
- name: AIM | Validate diagnostics option
|
|
ansible.builtin.assert:
|
|
that:
|
|
- (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in
|
|
['true', 'false']
|
|
fail_msg: aim_debug must be a YAML/JSON boolean.
|
|
quiet: true
|
|
- name: AIM | Reject mixed platform membership
|
|
ansible.builtin.assert:
|
|
that:
|
|
- (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1
|
|
fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups.
|
|
quiet: true
|
|
- name: AIM | Execution context
|
|
ansible.builtin.debug:
|
|
msg:
|
|
host: '{{ inventory_hostname }}'
|
|
diagnostics: Enabled; secret values are never included by this task.
|
|
when: aim_debug | default(false) | bool
|
|
- name: Load system detect roles
|
|
ansible.builtin.include_role:
|
|
name: system_detect_roles
|
|
- name: Load checkmk script plan
|
|
ansible.builtin.include_role:
|
|
name: checkmk_script_plan
|
|
- name: Checkmk | Preflight scripts and credentials
|
|
ansible.builtin.include_role:
|
|
name: checkmk_deploy_scripts
|
|
tasks_from: preflight
|
|
roles:
|
|
- role: checkmk_deploy_scripts
|
|
- role: checkmk_configure_agent
|
|
- role: checkmk_manage_service
|
|
post_tasks:
|
|
- *id001
|
|
- name: AIM | Publish operation result
|
|
ansible.builtin.set_stats:
|
|
per_host: true
|
|
aggregate: false
|
|
data:
|
|
aim_output:
|
|
protocol: aim_output_v1
|
|
schema: checkmk_agent_config_v1
|
|
data: '{{ _aim_checkmk_changes }}'
|