8 Commits
1.0.0 ... 1.0.5

12 changed files with 63 additions and 25 deletions

3
.ansible-lint Normal file
View File

@@ -0,0 +1,3 @@
# .ansible-lint │
warn_list: # or 'skip_list' to silence them completely │
- '106' # Role name {} does not match ``^[a-z][a-z0-9_]+$`` pattern

View File

@@ -1,2 +1,3 @@
FROM docker.io/pycontribs/centos:7 FROM docker.io/pycontribs/centos:7
RUN yum install -y iproute RUN yum install -y iproute firewalld python-firewall net-tools && \
systemctl enable firewalld

7
Centos8-Dockerfile Normal file
View File

@@ -0,0 +1,7 @@
# Centos8-Dockerfile
FROM docker.io/pycontribs/centos:8
RUN yum install -y iproute firewalld net-tools && \
sed -i 's/FirewallBackend=nftables/FirewallBackend=iptables/' /etc/firewalld/firewalld.conf && \
sed -i 's/IPv6_rpfilter=yes/IPv6_rpfilter=no/' /etc/firewalld/firewalld.conf && \
systemctl enable firewalld

View File

@@ -1,14 +1,24 @@
--- ---
cmk_add_host: false # Should be true/false whether we should automatically add host for monitoring. cmk_add_host: false # Should be true/false whether we should automatically add host for monitoring.
cmk_omd_protocol: http # Should be http or https
cmk_omd_host: your-checkmk-hostname cmk_omd_host: your-checkmk-hostname
cmk_omd_site: your-checkmk-site # e.g the first piece after the / following your hostname cmk_omd_site: your-checkmk-site # e.g the first piece after the / following your hostname
# If you have created a folder in WATO already you want hosts to be put in when registered # If you have created a folder in WATO already you want hosts to be put in when registered
# uncomment cmk_folder below and specify the folder to use. Otherwise the role creates and # uncomment cmk_folder below and specify the folder to use. Otherwise the role creates and
# adds new hosts by default to Unsorted folder # adds new hosts by default to Unsorted folder
# cmk_folder: your_folder_in_WATO # cmk_folder: your_folder_in_WATO
# Copy paste the link address for rpm agent from CheckMK
cmk_rpm_agent: http://url-from-your-agent-bakery-in-checkmk.rpm cmk_rpm_agent: http://url-from-your-agent-bakery-in-checkmk.rpm
# Copy paste the link address for MSI (Windows) agent from CheckMK
cmk_msi_agent: http://url-from-your-agent-bakery-in-checkmk.msi cmk_msi_agent: http://url-from-your-agent-bakery-in-checkmk.msi
# Check_MK GPG Key
# Copy paste the link address from Signature Keys for Signing Agents page
cmk_gpg_key_id: 1
cmk_gpg_key_url: "{{ cmk_omd_protocol }}://{{ cmk_omd_host }}/{{ cmk_omd_site }}/check_mk/wato.py?key={{ cmk_gpg_key_id }}&mode=download_signature_key"
# Should be username of an automation user in checkmk # Should be username of an automation user in checkmk
cmk_username: some-username cmk_username: some-username
@@ -17,9 +27,15 @@ cmk_username: some-username
# I recommend encrypting this with ansible-vault. # I recommend encrypting this with ansible-vault.
# Example: ansible-vault encrypt_string somesecret_string --name cmk_secret # Example: ansible-vault encrypt_string somesecret_string --name cmk_secret
cmk_secret: some-secret cmk_secret: some-secret
# Combined string required for unattended actions # Combined string required for unattended actions
cmk_auth: "&_username={{ cmk_username }}&_secret={{ cmk_secret }}" cmk_auth: "&_username={{ cmk_username }}&_secret={{ cmk_secret }}"
# This variable is used to detect whether this is a fresh install # This variable is used to detect whether this is a fresh install
# Is changed to true if check-mk-agent gets installed # Is changed to true if check-mk-agent gets installed
cmk_fresh_install: false cmk_fresh_install: false
# This variable if set to true will force installation to run regardless of whether
# CheckMK is already installed.
# Breaks idempotence but allows role to be used to force upgrade agents.
cmk_force_install: false

View File

@@ -8,4 +8,14 @@
- name: cmk fresh install - name: cmk fresh install
set_fact: set_fact:
cmk_fresh_install: True cmk_fresh_install: True
- name: ensure firewall open
firewalld:
port: 6556/tcp
state: enabled
permanent: yes
- name: ensure firewall reloaded
command: firewall-cmd --reload
changed_when: false

View File

@@ -5,7 +5,7 @@ galaxy_info:
# If the issue tracker for your role is not on github, uncomment the # If the issue tracker for your role is not on github, uncomment the
# next line and provide a value # next line and provide a value
# issue_tracker_url: http://example.com/issue/tracker # issue_tracker_url: http://example.com/issue/tracker
license: MIT license: MIT
min_ansible_version: 2.9 min_ansible_version: 2.9
@@ -34,4 +34,3 @@ galaxy_info:
# Maximum 20 tags per role. # Maximum 20 tags per role.
dependencies: [] dependencies: []

View File

@@ -5,20 +5,21 @@ driver:
name: docker name: docker
platforms: platforms:
- name: rhel8 - name: rhel8
image: docker.io/pycontribs/centos:8 image: guisea/centos8-ansible:latest
#dockerfile: Centos8-Dockerfile
privileged: True privileged: True
volume_mounts: volume_mounts:
- "/sys/fs/cgroup:/sys/fs/cgroup:rw" - "/sys/fs/cgroup:/sys/fs/cgroup:rw"
command: "/usr/sbin/init" command: "/usr/sbin/init"
pre_build_image: true pre_build_image: true
- name: rhel7 - name: rhel7
image: docker.io/pycontribs/centos:7 image: guisea/centos7-ansible:latest
dockerfile: Centos7-Dockerfile # dockerfile: Centos7-Dockerfile
privileged: True privileged: True
volume_mounts: volume_mounts:
- "/sys/fs/cgroup:/sys/fs/cgroup:rw" - "/sys/fs/cgroup:/sys/fs/cgroup:rw"
command: "/usr/sbin/init" command: "/usr/sbin/init"
pre_build_image: false pre_build_image: true
provisioner: provisioner:
name: ansible name: ansible
verifier: verifier:

View File

@@ -2,3 +2,4 @@
shell: | shell: |
cmk-update-agent register -H $(hostname -s) --user {{ cmk_username }} \ cmk-update-agent register -H $(hostname -s) --user {{ cmk_username }} \
--secret {{ cmk_secret }} --secret {{ cmk_secret }}
changed_when: false

View File

@@ -16,19 +16,21 @@
get_url: get_url:
url: "{{ cmk_rpm_agent }}{{ cmk_auth }}" url: "{{ cmk_rpm_agent }}{{ cmk_auth }}"
dest: /tmp/check-mk-agent.rpm dest: /tmp/check-mk-agent.rpm
- name: Ensure check_mk_agent installed - name: Ensure check_mk_agent installed
yum: yum:
name: /tmp/check-mk-agent.rpm name: /tmp/check-mk-agent.rpm
state: installed state: installed
notify: disable_gpg_check: true
notify:
- restart xinetd - restart xinetd
- cmk fresh install - cmk fresh install
- ensure firewall open
- name: Remove agent Download - name: Remove agent Download
file: file:
path: /tmp/check-mk-agent.rpm path: /tmp/check-mk-agent.rpm
state: absent state: absent
when: "'check-mk-agent' not in ansible_facts.packages" when: "'check-mk-agent' not in ansible_facts.packages or cmk_force_install"
tags: tags:
- check_mk_agent - check_mk_agent

View File

@@ -1,5 +1,6 @@
- name: Register with CheckMK Update Server - name: Register with CheckMK Update Server
win_shell: | win_shell: |
C:\ProgramData\checkmk\agent\plugins\cmk-update-agent.exe register -H $env:computername ` C:\ProgramData\checkmk\agent\plugins\cmk-update-agent.exe register `
-H $env:computername `
--user {{ cmk_username }} ` --user {{ cmk_username }} `
--secret {{ cmk_secret }} --secret {{ cmk_secret }}

View File

@@ -3,13 +3,13 @@
win_file: win_file:
path: "c:/temp/" path: "c:/temp/"
state: directory state: directory
- name: Retrieve copy of agent - name: Retrieve copy of agent
win_get_url: win_get_url:
url: "{{ cmk_msi_agent }}{{ cmk_auth }}" url: "{{ cmk_msi_agent }}{{ cmk_auth }}"
dest: "c:/temp/check-mk-agent.msi" dest: "c:/temp/check-mk-agent.msi"
changed_when: false changed_when: false
- name: Ensure agent is installed - name: Ensure agent is installed
win_package: win_package:
path: "c:/temp/check-mk-agent.msi" path: "c:/temp/check-mk-agent.msi"

View File

@@ -2,7 +2,7 @@
- name: add host to omd - name: add host to omd
uri: uri:
method: POST method: POST
url: "http://{{ cmk_omd_host }}/{{ cmk_omd_site }}/check_mk/webapi.py?action=add_host{{ cmk_auth }}" url: "{{ cmk_omd_protocol }}://{{ cmk_omd_host }}/{{ cmk_omd_site }}/check_mk/webapi.py?action=add_host{{ cmk_auth }}"
body: | body: |
request={ request={
"attributes": { "attributes": {
@@ -11,7 +11,7 @@
"ipaddress": "{{ hostvars[inventory_hostname]['ansible_default_ipv4']['address'] }}" "ipaddress": "{{ hostvars[inventory_hostname]['ansible_default_ipv4']['address'] }}"
}, },
"folder": "{{ cmk_folder | default('Unsorted') }}", "folder": "{{ cmk_folder | default('Unsorted') }}",
"hostname": "{{inventory_hostname}}" "hostname": "{{ inventory_hostname }}"
} }
body_format: raw body_format: raw
return_content: yes return_content: yes
@@ -20,18 +20,15 @@
delegate_to: localhost delegate_to: localhost
when: cmk_add_host when: cmk_add_host
- set_fact: - name: Parse result
set_fact:
output: "{{ res.content | from_json }}" output: "{{ res.content | from_json }}"
when: cmk_add_host when: cmk_add_host
# - debug:
# msg: "{{ output }}"
# when: cmk_add_host
- name: cmk_discovery - name: cmk_discovery
uri: uri:
method: POST method: POST
url: http://{{ cmk_omd_host }}/{{ cmk_omd_site }}/check_mk/webapi.py?action=discover_services&mode=refresh{{ cmk_auth }} url: "{{ cmk_omd_protocol }}://{{ cmk_omd_host }}/{{ cmk_omd_site }}/check_mk/webapi.py?action=discover_services&mode=refresh{{ cmk_auth }}"
body: 'request={"hostname":"{{ inventory_hostname }}"}' body: 'request={"hostname":"{{ inventory_hostname }}"}'
body_format: raw body_format: raw
status_code: 200 status_code: 200
@@ -42,7 +39,7 @@
- name: cmk_apply - name: cmk_apply
uri: uri:
method: POST method: POST
url: http://{{ cmk_omd_host }}/{{ cmk_omd_site }}/check_mk/webapi.py?action=activate_changes&mode=specific{{ cmk_auth }} url: "{{ cmk_omd_protocol }}://{{ cmk_omd_host }}/{{ cmk_omd_site }}/check_mk/webapi.py?action=activate_changes&mode=specific{{ cmk_auth }}"
body: 'request={"sites":["{{ cmk_omd_site }}"]}' body: 'request={"sites":["{{ cmk_omd_site }}"]}'
body_format: raw body_format: raw
status_code: 200 status_code: 200