Files
Ansible/scripts/docs/CHANGELOG.md
T
2026-09-22 19:23:17 +02:00

32 KiB

Changelog

3.3.0rc8

  • Normalize ACLs on persistent AIM-managed Windows Checkmk scripts and check_mk.user.yml after creation/update.
  • Re-enable parent ACL inheritance per managed file and guarantee locale-independent well-known principals by SID: SYSTEM and local Administrators with FullControl; ALL APPLICATION PACKAGES and ALL RESTRICTED APPLICATION PACKAGES with ReadAndExecute.
  • Do not add customer-specific administrator/user ACEs and do not recursively rewrite Checkmk directories or unknown/operator files. Existing intentional parent/explicit ACEs are not blindly purged.
  • Add the reusable checkmk_windows_acl role and apply it only to the exact AIM-managed persistent file paths.
  • Keep Checkmk script placement, structured-result contracts, service/wire/event API 1.0, and Ansible Core 2.19.11 unchanged.

3.3.0rc7

  • Move veeam_o365_status.ps1 from the Windows Checkmk local-check directory to C:\ProgramData\checkmk\agent\plugins.

  • If an earlier rc7 build placed that file under the Checkmk built-in plugin directory, selected deployment removes that known stale copy after the custom plugin is staged.

  • Add the exact $CUSTOM_PLUGINS_PATH$\veeam_o365_status.ps1 execution rule when Veeam VBO is detected, ahead of the built-in plugin deny catch-all.

  • Remove the legacy AIM-managed local copy after selected deployment and teach explicit cleanup to remove the current custom-plugin path plus both known legacy locations without touching unknown files.

  • Keep Checkmk public structured-result schemas and service/wire/event API 1.0 unchanged.

  • Replaced the Windows disk-usage PowerShell/Get-PSDrive collector with community.windows.win_disk_facts; Windows capacity reports now describe attached local volumes and intentionally exclude mapped/network drives.

  • Kept the public filesystem_usage_v1 result schema stable while normalizing native disk/partition/volume facts into the existing fields.

  • Audited the complete playbook/role tree for native Ansible module coverage.

  • Replaced custom Windows pending-reboot registry probing with ansible.windows.win_reboot_info and added bounded reboot-source reporting.

  • Raised the supported ansible.windows baseline to >=3.8.0,<4.0.0 and added explicit readiness/terminal version checks.

  • Replaced Checkmk Windows config file shell reads with win_stat + slurp.

  • Replaced Linux package snapshot/version commands with package_facts and Linux Checkmk final service-state command reporting with service_facts.

  • Documented reviewed custom command/PowerShell/raw call sites that remain because native modules do not preserve the required behavior.

3.3.0rc3

  • Change Windows OS patching from one broad win_updates install request to an explicit discovery queue with one update installed per invocation. The queue is deterministic and places drivers last.
  • Add Windows-only catalog option os_patching_rescan_after_reboot (false by default). A patch-triggered reboot ends the run by default; post-reboot discovery/install continuation requires explicit operator opt-in.
  • Preserve one operator-approved patch wave per run by default. A completed reboot boundary reports continuation_required: true and does not perform a post-reboot search unless continuation was enabled.
  • After a wave completes without reboot, perform one read-only final discovery for reporting only; do not append newly applicable updates to the already-approved install queue.
  • Expand patch_summary_v1 with Windows patch-cycle/continuation facts and bounded per-update HRESULT classification. 0x80240016 is reported as install_not_allowed, not treated as proof of a reboot.
  • Stop the Windows wave on an individual update failure, publish already completed updates plus the bounded failure, and never replay the update/job automatically.
  • Keep reboot notification/delay, Linux patching, service/wire/event API 1.0, Ansible Core 2.19.11 and the generic operation-result transport unchanged.
  • Native Windows controller acceptance of the sequential queue and post-reboot continuation remains required before stable promotion.

3.3.0rc2

  • Improve OS patch reboot handling without changing Core API/wire/event 1.0: expose a cross-platform reboot delay (minutes) and reboot notification message through catalog metadata.
  • Windows patching now disables win_updates implicit reboot and uses an explicit win_reboot so the configured message/delay is honored; Linux uses the corresponding reboot module message/delay semantics.
  • Detect a pre-existing pending reboot before starting new patch work where the platform provides a supported signal. If automatic reboot is disabled, publish a structured blocked patch result and fail with an explicit reboot-required message instead of a generic later fatal.
  • When a patch run newly requires reboot and automatic reboot is disabled, keep the successful update run successful but report reboot_required/reboot_deferred in patch_summary_v1. A later run remains blocked until the host is rebooted.
  • Extend patch_summary_v1 with pre/post/deferred reboot facts, configured delay and a typed preexisting_reboot_required block reason; package/update reporting remains unchanged.
  • Add the current fresh-install INSTALLATION.md to the consolidated documentation set.
  • Native Windows/Linux controller acceptance for these rc2 patching changes remains pending; see VALIDATION.md and SANITY.md.

3.2.1rc2 - inventory hierarchy, split-home staging and per-target outcomes

  • Adds read-only inventory_hierarchy discovery with nested parent/subgroup relationships and direct host membership. The public tree exposes group names/paths and host names only; variables remain private and execution still requires explicit reviewed host names.
  • Corrects controller staging preflight for hardened executors whose process $HOME differs from the execution account passwd home. Core now probes controller local_tmp using the process/config home and the default delegated connection: local POSIX temp path using the passwd/NSS account home. No home, permission or service-unit mutation is performed.
  • Adds additive target_outcome_summary_v1 data to every execution RunResult. Overall Core status/exit semantics remain unchanged; consumers receive requested-target accounting plus per-target successful, failed, unreachable, not_started or indeterminate outcomes derived from native final host stats.
  • Target summaries are available in both summary and detail progress modes and do not require consumers to reconstruct task events. Incomplete/cancelled execution without final stats never fabricates target success.
  • Keeps service/wire/event API 1.0, canonical Ansible Core 2.19.11, credentials, playbooks, roles, WinRM and remote execution semantics unchanged. This is an additive discovery/readiness/result candidate.

3.2.1rc1 - controller staging preflight and hardened-executor default

  • Makes a writable, private controller staging directory an always-checked service requirement. Readiness and execution validate staging before credentials/native runtime inspection, with a second check before playbook launch. Failures return fixed readiness errors rather than late delegated-task unreachable results.
  • Adds protected staging_check / AimService.staging_check() and aimctl staging-check, plus additive capability/readiness fields. No credentials, customer inventory or native Ansible command is needed for the local probe.
  • Performs real create/write/flush/read/remove operations under the current UID and sandbox, bounded to ten seconds. Missing directories are privately created; existing permissions, owners and contents are never repaired or purged.
  • Preserves native controller temporary configuration and remote-host settings. Checks the default POSIX local-connection staging path; explicitly warns when global remote_tmp overrides or inventory-specific settings are outside probe coverage.
  • Establishes the generic add-on deployment default: provision private staging, append a directory-specific ReadWritePaths exception and an in-sandbox startup check while retaining ProtectHome/ProtectSystem/PrivateTmp/NoNewPrivileges. Core never edits independent service units or add-on code.
  • Records operator confirmation that the narrow staging exception allowed the Checkmk service job to install successfully on a Windows 11 client. New candidate acceptance and detailed-progress/other-target qualification remain separate.
  • Keeps API/wire/event 1.0, Ansible Core 2.19.11, existing roles/playbooks, WinRM, credentials, terminal behavior and deployment logic unchanged. Full replacement ZIP plus checksum; no patches or bundled validators.

3.2.0 - safe detailed execution progress

  • Adds optional progress_mode: detail to the stable service/wire/event 1.0 contract. The default summary mode retains anonymous progress and existing consumers. Capabilities advertise play_task_host_v1; clients opt in before requesting it.
  • Detailed events expose plays, no-host skips, tasks/handlers, per-host outcomes, retry/poll notices and recaps, with run/play/task correlation. Native first-party terminal output remains unchanged.
  • Uses bounded unexpanded source labels, explicit reviewed host names and fixed diagnostic hints. Suppresses unsafe/template/no_log labels and protected result details; never forwards raw stdout/stderr, module arguments, variable/config dumps, exception fields or loop-item payloads.
  • Revalidates native frames, sequences and recap totals before public emission. Missing, incomplete, malformed or over-limit detailed progress cannot silently become a successful result. No automatic replay or rollback of remote work is introduced.
  • Keeps Ansible Core 2.19.11 canonical, external execution disabled by default, and existing credential/ownership/deployment policies. No playbook, role, WinRM helper, inventory, key, add-on or deployment behavior is changed.
  • Updates release notes, additive API contract, support metadata, renderer guidance and the controller acceptance checklist. Local tests use simulated Ansible callbacks/CLIs; new detailed execution still requires native controller/target acceptance.

3.1.0 - accepted service-v1 baseline

  • Promotes the controller-accepted 3.0.0rc21 candidate to the stable 3.1.0 minor release without changing playbook, role, credential, WinRM, Checkmk, deployment, or service behavior.
  • Freezes AIM service/wire/event API 1.0 for additive 1.x evolution. AIM continues to ship the built-in terminal plus aimctl; add-ons consume only the documented service boundary.
  • Records real-controller acceptance of Windows 11 terminal management, Vault retry behavior, group/subgroup select-all, launcher deployment, aimctl discovery/preparation, and native Ansible Core 2.19.11 readiness.
  • External non-interactive execution remains disabled by default and requires separate acceptance by the chosen add-on/runtime identity. Unsupported boundaries remain unchanged: cross-UID execution, forced Custom password override, private-key export, API inventory/Vault mutation, raw sensitive task output, and automatic replay after remote work may have started.
  • Release delivery remains a complete replacement ZIP plus SHA-256 sidecar; no Git, .patch, release manifest, or bundled development validator is used.
  • Fixes the rc20 ZIP deployer rejecting an existing /usr/local/bin/aim symlink before it could refresh the installed aim and aimctl launchers.
  • Allows only recognized existing AIM launcher symlinks at the final launcher path; symlinked parent directories, broken links, non-regular targets, and unrecognized launcher contents remain rejected.
  • Deployment now backs up the symlink itself, atomically replaces it with the managed launcher, verifies aim and aimctl, and restores the original symlink target during rollback.
  • No service API, terminal workflow, playbook, role, WinRM, Checkmk, credential, or remote-execution behavior changes from rc20. Service API / wire / event remain 1.0 and Ansible Core 2.19.11 remains canonical.
  • Records the operator-observed rc20 deployment failure as the regression target. Local disposable testing passed dry-run, symlink replacement, installed command verification, and rollback restoration.

3.0.0rc20 - terminal stabilization and stable services v1 handoff

  • Adds interface-supplied, operation-scoped Vault unlock/retry before terminal Vault edits, reads and normal catalog playbook launches. A rejected password keeps the selected workflow. Empty/invalid input re-prompts; Ctrl+C cancels. Only the native Vault decryption rejection from a bounded local ansible-vault view preflight is retried, never an editor or launched playbook.
  • Reuses the private same-UID password-client channel for the validated operation: no password in argv/environment/helper contents and no second Vault prompt after successful prevalidation. Terminal Vault-password input preserves literal whitespace. Legacy internal manager callers without terminal interaction retain native prompts. Additional/inline Vault files are not exhaustively prevalidated; late failures are never automatically replayed. Vault create/new-encryption prompts remain native.
  • Adds "Select all hosts in this group/subgroup" versus individual selection after group selection. Parent scopes include descendant subgroups; overlapping memberships are deduplicated. Execution still uses explicit host names and the existing final run review/confirmation.
  • ZIP deployment now installs/refreshes and smoke-tests both aim and aimctl launchers with the existing AIM Python, without pip, dependency installation or changes to the Ansible environment. Adds --aim-python and --bin-dir, conservative interpreter discovery, previewed launcher changes and launcher recovery alongside source recovery. Unknown commands/symlinks are refused. A separate target requires its own explicit command directory.
  • Returns safe invalid_target and invalid_options service errors for known validation failures; actual inaccessible/invalid source remains source_invalid. Error-code fallback remains required for v1 clients.
  • Adds optional credential_requirement_reasons to prepared results and advertises credential_requirements_policy. A present conventional customer Vault remains conservatively required even with require_vault: false; this is not a claim of full effective-variable credential analysis.
  • Freezes the documented service/wire/event 1.0 contract as the supported additive 1.x boundary. AIM keeps its built-in terminal and machine client; internal managers remain private. No add-on source or interface framework is required.
  • Records operator-reported rc19 Windows 11 terminal onboarding/service-account authentication, targeting, interruption, metadata/prepare and native 2.19.11 readiness results separately from rc20 local regression evidence and pending controller re-tests. External execution remains opt-in/disabled by default; neither readiness nor CLI success proves the non-interactive execution path.
  • Updates add-on guidelines, API/support contract, deployment instructions, RC20_SANITY_TESTS.md and RC20_HANDOFF.md. No WinRM/Checkmk/other remote playbook or role behavior is changed. No Git/patches/release manifest/development validators are shipped.

3.0.0rc19 - independent add-on service foundation and ZIP deployment

  • Adds aim.services.v1, aimctl and a source-tree machine wrapper. Generic API/wire/event version 1.0; no add-on/web-framework imports or need to inspect an add-on codebase.
  • Adds capabilities, authorized metadata reads, typed explicit-host/catalog preparation, bounded known-source revisions, local readiness and opt-in same-UID native Ansible execution. Shared target validation now protects direct CLI manager calls as well as the UI.
  • Establishes ansible-core 2.19.11 as the canonical supported runtime, separately from the AIM/add-on Python environments. Native sibling CLI identity and required collections are checked without installation side effects.
  • Adds private one-run credential providers, inherited credential-FD support, native executable password sources and safe progress/results. Keeps native inventory/Vault precedence: supplied connection/become passwords are defaults, not a forced Custom override. Existing terminal @prompt behavior is retained; --ask-vault-pass is also interactive and does not solve unattended input.
  • Adds bounded Vault preflight, owned per-run SSH agents/process groups, cancellation and conservative remote-work reporting. Unencrypted keys no longer require a Vault passphrase. CLI agent probing rejects stale sockets and no longer transports key passphrases through environment values.
  • Preserves owner/group/mode/attributes before atomic replacements, including inventory/configuration/Vault publication and restore paths. Existing non-root shared-group writers retain their legacy owner-transfer exception with a warning; full managed single-writer ownership is not claimed.
  • Makes cooperative customer locks persistent and reentrant instead of unlinking their inode. Extends locking across key/Vault/config mutations and playbook execution. Direct shell edits and arbitrary external writers remain outside advisory-lock guarantees.
  • Adds optional runtime.private_key_owner for new keys only, with exclusive staged keypair publication. Does not rename keys, change remote service_user, re-own existing keys, switch UIDs or migrate permissions automatically.
  • Adds the operator-approved standard-library deploy/deploy.py, dry-run-first source replacement, explicit quiescence and protected source recovery. Delivers a ZIP plus SHA-256 sidecar without Git, patches, release manifests or bundled development validators. Existing aim.yml, add-ons/runtime state, inventories/Vaults/keys, environments and unknown customer files are preserved.
  • Publishes ADDON_AGENTS.md, ADDON_API.md, ADDON_SUPPORT.md, addon-support-v1.json, and RC19_HANDOFF.md. Exposes unsupported capabilities explicitly: Custom overrides, cross-UID launchers, key export, API mutations and raw sensitive task results.
  • External execution defaults to disabled. Development validation includes real Python/Unix IPC/filesystem/process tests and simulated native CLI contract fixtures, not live Ansible 2.19.11, SSH or WinRM acceptance. See the handoff for evidence and controller gates.
  • No Checkmk task/template, WinRM bootstrap or remote configuration behavior was changed. The earlier question about a remote Checkmk configuration backup remains separate and unimplemented.

3.0.0rc18 - Checkmk Windows config parser hotfix

  • Fixes the checkmk_configure_agent Windows plugins-section update task failing during Ansible argument parsing before reaching the managed host.
  • Removes an unmatched apostrophe from an embedded win_shell PowerShell comment; Ansible free-form shell argument parsing still scans quote characters inside the script text, including comments.
  • Does not change Checkmk configuration behavior: AIM still replaces only the marked top-level plugins: section and preserves all other check_mk.user.yml content.

3.0.0rc17 - read-only Windows Checkmk configuration inspection

  • Adds checkmk_read_windows_config.yml, a read-only Windows playbook that displays the current check_mk.user.yml without changing the host.
  • Reports the resolved configuration path, file size, UTC last-write timestamp, and complete current file contents; a missing file is reported without failing or creating it.
  • Adds an optional checkmk_windows_user_cfg path override for nonstandard agent layouts while retaining C:\ProgramData\checkmk\agent\check_mk.user.yml as the default.
  • Exposes the operation in the AIM Checkmk catalog and documents it as a safe pre/post-rollout inspection tool.
  • Uses the standard Windows shell path rather than win_powershell, keeping this inspection operation usable on legacy PowerShell 4 hosts such as Windows Server 2012 R2.

3.0.0rc16 - section-scoped Checkmk user configuration

  • Changes Windows check_mk.user.yml handling from full-file rendering to section-scoped editing. AIM now replaces or appends only the top-level plugins: section.
  • Preserves existing global, winperf, fileinfo, logwatch, local, mrpe, unknown top-level sections, and unrelated comments instead of resetting them to AIM defaults.
  • Keeps an AIM ownership notice on the first line and adds a dedicated ownership comment immediately before the AIM-managed plugins: section so the management boundary is explicit.
  • Removes the rc15 checkmk_manage_local_execution / checkmk_extra_local_patterns rollout controls: local-check execution is no longer managed by this role at all. Existing local execution policy is preserved.
  • Preserves existing MRPE configuration instead of writing mrpe.config: [].
  • Retains the existing AIM plugin execution ordering and role-based plugin rules; unknown local/plugin files remain untouched.
  • Existing hosts already overwritten by an earlier full-file rollout cannot have lost settings reconstructed automatically; restore those settings from the host's previous configuration/backup if needed, then rc16 will preserve them on subsequent runs.

3.0.0rc15 - Checkmk local execution inheritance hotfix

  • Fixes Windows Checkmk user configuration generation so checkmk_manage_local_execution: false omits the local section instead of writing local: {}.
  • This preserves the effective local-check execution policy inherited from Checkmk default/bakery configuration and prevents custom files in C:\ProgramData\checkmk\agent\local from becoming non-executable merely because AIM rendered the user configuration.
  • When checkmk_manage_local_execution: true, AIM now explicitly writes local.enabled: true together with the managed local.execution rules.
  • Does not change Checkmk script-file ownership: unknown local/plugin files remain untouched, while known AIM-managed filenames may still be replaced.
  • The Checkmk user configuration file remains fully rendered by AIM in this hotfix; merge-preserving ownership of arbitrary pre-existing user-config keys is a separate design change.

3.0.0rc14 - clean replacement bundle layout

  • Changed release packaging to a complete replacement/fresh-install model instead of shipping patch/merge deployment mechanics.
  • Removed release-manifest.json, release updater/deployer tooling, bundled release-validation tooling, historical migration guides, .patch artifacts, and generated Python caches from the distributable archive.
  • Moved the controller-wide AIM configuration from /etc/ansible/aim.yml to /etc/ansible/scripts/aim.yml and included a clean default scripts/aim.yml in the bundle.
  • Moved the maintained one-time WinRM bootstrap helper to scripts/AIM-WinRM-OneTime.ps1.
  • Retained operational documentation, changelog, playbooks, roles, collection requirements, and the complete AIM application source required for a new installation.

3.0.0rc13 - forgiving WinRM password prompts

  • Temporary/bootstrap WinRM credentials are validated before the requested Windows access operation begins.
  • A failed WinRM credential probe now re-prompts for the password instead of consuming/skipping the host operation. Ctrl+C still cancels normally.
  • Empty temporary passwords are re-prompted instead of failing the workflow.
  • Service-account password entry now loops on empty values or confirmation mismatches instead of aborting back to the menu.
  • Introduces a dedicated WinRMConnectionFailed error so only an actual WinRM probe failure triggers credential re-entry; missing commands and unrelated controller errors still fail normally.

3.0.0rc12 - Windows Server 2012 R2 WinRM certificate hotfix

  • Fixes New-SelfSignedCertificate on Windows Server 2012 R2 / PowerShell 4 systems that expose -CertStoreLocation but reject Cert:\LocalMachine\My with InvalidStorePathException.
  • Certificate creation now retries only that specific failure from inside Cert:\LocalMachine\My, preserving normal behavior and error reporting on newer Windows versions.
  • Keeps capability detection for optional -FriendlyName and -TextExtension parameters and applies the friendly name after creation when required.
  • Adds scripts/tools/AIM-WinRM-OneTime.ps1 as the maintained standalone one-time WinRM HTTPS bootstrap script using the same compatibility logic.
  • Adds top-level AGENTS.md as the authoritative development/release/compatibility guideline for continued AIM development.

3.0.0rc11 - Windows local host_vars credential-model repair hotfix

  • Prepare local account now inspects every selected host's host_vars/<fqdn>/main.yml before prompting for credentials.
  • Empty legacy host-vars files and partial overrides are explicitly identified as incomplete when ansible_user or ansible_password is missing/blank.
  • The operator chooses the desired local credential model: shared-local, host-specific local, or retain complete existing overrides.
  • Retain existing is rejected while any selected host has incomplete credential overrides, preventing a successful account bootstrap from leaving an unusable empty/partial host-vars file behind.
  • After the local account bootstrap and independent WinRM verification succeed, AIM reapplies the selected shared-local or host-specific model to host_vars, preserving unrelated custom variables/comments.

3.0.0rc10 - legacy inventory consolidation/template comments hotfix

  • Template consolidation now creates missing platform group_vars/<platform>/ directories and main.yml files, matching the existing preview message instead of silently skipping absent parent directories.
  • Existing group-vars values/custom variables remain non-destructively preserved; malformed YAML continues to be skipped rather than repaired implicitly.
  • Windows shared-local and host-specific credential overrides now write a clear AIM ownership/context comment as the first line of host_vars/<host>/main.yml.
  • Template validation/consolidation also detects older AIM local-credential host_vars/<host>/main.yml files that lack that header and adds it without changing existing credential values or custom variables.
  • Switching a host back to the domain credential model removes only AIM's known local-credential header while preserving unrelated custom comments/keys.

3.0.0rc9 - Standalone Windows WinRM local-admin hotfix

  • Prepare local account now idempotently sets LocalAccountTokenFilterPolicy=1 before the service-account WinRM verification.
  • Keeps the existing bare svc_bf-ansible username behavior because that is known to work once remote UAC token filtering is disabled.
  • Domain-account and domain-GPO behavior are unchanged.
  • The GPO WinRM payload retains direct Get-NetIPAddress discovery and optional additional SANs for Hyper-V/complex networking cases.

3.0.0rc8 - Consolidation permission handling hotfix

  • Treat existing shared inventory mode 0660 as already correct and avoid redundant chmod attempts.
  • Template consolidation uses best-effort permission normalization after a successful content update.
  • EPERM/EACCES during consolidation permission normalization is reported as a warning instead of failing the operation.
  • Security-sensitive permission operations outside template consolidation remain strict.

3.0.0rc7 - WinRM certificate compatibility hotfix

  • Makes the generated AIM-WinRM-Setup.ps1 compatible with PKI cmdlet implementations that do not expose New-SelfSignedCertificate -TextExtension and/or -FriendlyName.
  • Builds the certificate call from the parameters actually supported by the target host. The base -DnsName + CertStoreLocation path remains an SSL server certificate; the explicit Server Authentication EKU extension is added when TextExtension is available.
  • Applies the WinRM friendly name after creation when it could not be supplied as a cmdlet parameter, preserving AIM's existing certificate-reuse behavior.
  • Does not change listener, firewall, GPO link, scheduled-task timing, service-account or access-policy behavior.

3.0.0rc6 - coordinated playbook/role migration candidate

  • Adds top-level Multi-customer operations next to Open customer; it is never launched from inside a customer context.
  • Adds multi-customer catalog playbook execution with per-customer hosts.yml target selection, shared typed run options and one isolated Ansible invocation per customer.
  • Runs selected customers sequentially, keeps native Ansible/Vault/password prompts live, continues with the next customer after an ordinary playbook failure, and stops the remaining batch when the operator interrupts the current command.
  • Adds clear per-customer live-output separators and a final summary with target counts, result and duration, plus failure/skip details.
  • Keeps customer-specific inventories, Vault IDs, SSH preparation and target limits isolated; inventories are never merged.
  • Changes multi-select a into a filter-aware toggle: when all currently matching items are selected it clears them; otherwise it selects all currently matching items. Selections outside the active filter are unchanged.

3.0.0rc5 - coordinated playbook/role migration candidate

  • Stores the controller-wide Checkmk agent source as structured settings in /etc/ansible/aim.yml: protocol, base URL/host, site name, version, patchlevel and revision. AIM always appends /check_mk/agents and builds the package version as <version>p<patchlevel>-<revision>. Legacy complete URL/version settings are migrated in memory and normalized on the next save.
  • Moves Save settings to the bottom of the Settings menu.
  • Adds a to every multi-select selector to select all items matching the current filter (across all filtered pages).

3.0.0rc4 - coordinated playbook/role migration candidate

  • Expanded debug_show_disk_usage to Windows and Linux. Windows reports all filesystem drives visible to the WinRM session; Linux reports common operational mounts and network/storage filesystems while excluding pseudo/system mounts.

Breaking source layout / entrypoint changes from AIM 2.2.2. AIM and its catalog, playbooks and roles must be installed together. No legacy wrappers are shipped.

  • Introduces playbooks/aim_catalog.yml with descriptions, targets, dependencies, risk notices and typed, opt-in run parameters. Unchanged inputs remain inherited.
  • Standardizes runnable names as <category>_<verb>_<purpose>.yml; retains standard role entrypoints such as tasks/main.yml and defaults/main.yml.
  • Removes the deprecated gebhardt customer playbook and empty _sample role.
  • Preserves firewall task arguments/order and per-customer policy identities; extracts reusable role entrypoints and adds preflight validation.
  • Adds aim_debug for selected diagnostics without enabling ANSIBLE_DEBUG or disabling secret protections. Normal reports remain visible.
  • Routes AlmaLinux/Rocky through RedHat-family patching; does not install an alternate Python interpreter automatically.
  • Repairs optional Windows Checkmk YAML generation, configurable variable precedence, and installed-but-stopped agent service handling.
  • Adds known monitoring-script selections and a single managed UniFi configuration with Vault-backed password references, safe shell quoting and mode-specific URLs.
  • Keeps removal of the opposite UniFi check during mode replacement; other cleanup is a separately approved preview/delete operation.
  • Preserves existing controller maintenance, GPO/WinRM provisioning, UI styling, pagination and inventory/SSH/Vault paths.
  • Adds guarded source-only migration and controller-side validation tools.
  • Updates the migration guard so operator-approved differences in scripts/ and requirements.yml are backed up and replaced instead of blocking deployment; playbook/role mismatch protection remains strict.
  • Adopts the operator-provided unpinned collection baseline and includes pfsensible.core.
  • Uses staged-role isolation for syntax checks so refactored playbooks cannot accidentally validate against old live roles.

See the migration document for intentionally changed behavior and verification limits.

Final rc7 Checkmk/script classification hotfix

  • Classify citrix_sessions_customized.ps1, veeam_o365_status.ps1, and veeam_backup_status.ps1 as AIM-managed Checkmk custom plugins under $CUSTOM_PLUGINS_PATH$ (C:\ProgramData\checkmk\agent\plugins).
  • Add veeam_backup_license_status.ps1 as a VBR-detected Windows local check under $CUSTOM_LOCAL_PATH$.
  • Stop enabling the Veeam backup status file from $BUILTIN_PLUGINS_PATH$; its exact managed rule now targets $CUSTOM_PLUGINS_PATH$ and follows want_windows_veeam_backup.
  • Selected custom-plugin deployment removes only known legacy AIM copies from the local directory, plus known historic built-in copies for Veeam O365/backup status.
  • Centralize AIM documentation under scripts/docs/. The deployment source no longer owns or replaces the installation-root README.md.