checkmk_deploy_scripts
Operator defaults are intentionally low-precedence; inventory and explicit run options may override them.
---
# unifi.cfg is role-managed and replaced, mode 0600. Password comes from Vault.
# An absent/CHANGEME password fails before deployment; no credentials are logged.
checkmk_linux_plugin_dir: /usr/lib/check_mk_agent/plugins
checkmk_linux_local_dir: /usr/lib/check_mk_agent/local
checkmk_linux_config_dir: /etc/check_mk
checkmk_windows_plugin_dir: C:\ProgramData\checkmk\agent\plugins
checkmk_windows_builtin_plugin_dir: C:\Program Files (x86)\checkmk\service\plugins
checkmk_windows_local_dir: C:\ProgramData\checkmk\agent\local
checkmk_monitoring_scripts_dir: '{{ lookup(''ansible.builtin.env'', ''AIM_CHECKMK_MONITORING_SCRIPTS_DIR'')
| default(''/etc/checkmk_monitoring_scripts'', true) }}'
checkmk_windows_scripts_dir: '{{ checkmk_monitoring_scripts_dir }}/Scripts Windows'
checkmk_linux_scripts_dir: '{{ checkmk_monitoring_scripts_dir }}/Scripts Linux'
checkmk_unifi_mode: auto
want_linux_check_certificate: false
want_windows_citrix: false
want_windows_surebackup: false
want_windows_backup: false
want_windows_nsp_mailqueue: false
want_windows_certificate: false
want_windows_veeam_cloud_connect: false
want_windows_veeam_backup: false
checkmk_unifi_username: bf-monitoring
checkmk_unifi_password: '{{ vault_checkmk_unifi_password | default('''') }}'
checkmk_unifi_baseurl: '{{ ''https://127.0.0.1:11443'' if _checkmk_unifi_effective == ''os'' else ''https://127.0.0.1:8443''
}}'
checkmk_unifi_curl_options: ' --insecure --tlsv1.2'
checkmk_unifi_status_provisioning: 1
checkmk_unifi_status_upgrading: 1
checkmk_unifi_status_upgradable: 0
checkmk_unifi_status_heartbeat_missed: 1
checkmk_unifi_status_noautobackup: 0
unifi.cfg is generated from the supplied schema, POSIX-shell quoted, mode 0600, and protected with no_log and diff: false. Use a Vault reference for the password. CHANGEME and empty passwords fail before deployment. The active UniFi mode replaces the alternative local check. Other obsolete scripts are removed only by explicit cleanup.
Structured result integration
Current reporting behavior and field semantics are specified in scripts/docs/OPERATION_RESULTS.md. The calling catalog playbook owns publication; helper roles do not implicitly export arbitrary facts, module results or debug data. Existing defaults above retain their precedence. See the current validation/sanity documents before using the new candidate.