Ansible Role linuxfabrik.lfops.icinga2_agent¶
This role installs Icinga2, configures it to act as an agent, and tries to registers the host in the Icinga Director.
Currently, this role only works if the host can reach the Icinga2 master API.
Available since LFOps 2.0.0.
How the Role Behaves¶
- The agent certificate is signed by the Icinga2 master. The role requests a ticket for the agent's CN from the master API (
icinga2_agent__icinga2_api_user_login) and passes it toicinga2 node setup, so the master signs the certificate right away (CSR auto-signing). icinga2 node setup(tagsicinga2_agentandicinga2_agent:node_setup) creates a new key and certificate for the agent each time it runs, so the role only runs it, requests a ticket for it and restarts the agent when one of these applies: the agent certificate is missing, expired or not signed by the CA of the master, the master presents a different certificate than before (for example after it was rebuilt), or one of theicinga2_agent__*settings passed toicinga2 node setupchanged. A hash of these settings is kept in/var/lib/icinga2/linuxfabrik-node-setup.sha256; delete the file to force a new node setup.- If the role cannot get a ticket, the run aborts before
icinga2 node setupand says why, since without one the agent would be left with an unsigned certificate, even if it was connected before. - If the master does not accept a connection on
icinga2_agent__icinga2_master_hostandicinga2_agent__icinga2_master_portfrom this host within 10 seconds, the run aborts before the node setup and names the address it tried. - With
icinga2_agent__skip_pki_ticket: true, the role requests no ticket and sets the agent up without one. Its certificate request then has to be signed on the master by hand (on-demand CSR signing). Until it is signed, every run creates a new request.
Dependent Roles¶
Any LFOps playbook that installs this role runs these for you. Optional ones can be disabled via the playbook's skip variables.
- The Icinga Package Repository must be enabled (role: linuxfabrik.lfops.repo_icinga).
Requirements¶
Manual steps:
- Deploy a configured Icinga2 Master, reachable from this host, by running the setup_icinga2_master playbook (role: linuxfabrik.lfops.icinga2_master). The master runs on a separate host and is not set up by this role's playbook.
Tags¶
icinga2_agent
- Installs and configures icinga2 as an agent.
- Triggers: icinga2.service restart.
icinga2_agent:logrotate
- Deploys the Icinga2 logrotate config. Serves as a hotfix for the following issue RLIMIT permission warnings.
- Triggers: none.
icinga2_agent:node_setup
- Runs the
icinga2 node setupif the agent needs it (see "How the Role Behaves") and registers the host in the Director. - Triggers: icinga2.service restart, if the node setup ran.
icinga2_agent:state
- Manages the state of the Icinga2 service.
- Triggers: none.
icinga2_agent:systemd_override
- Deploys:
/etc/systemd/system/icinga2.service.d/z00-after-sssd.conf. - Triggers: none.
icinga2_agent:update
- Updates the Icinga2 package and restarts the service.
- Triggers: icinga2.service restart.
Mandatory Role Variables¶
icinga2_agent__icinga2_api_user_login
- The account for generating a ticket for this agent using the Icinga2 API (API of Icinga Core). The account needs to have the
actions/generate-ticketpermission on the Icinga2 Master. Not used ificinga2_agent__skip_pki_ticketistrue. - Type: Dictionary.
icinga2_agent__icinga2_master_cn
- The common name of the Icinga2 Master.
- Type: String.
icinga2_agent__windows_version
- Mandatory for Windows. The version of the Icinga2 Agent to install. Possible options: https://packages.icinga.com/windows/?C=N;O=D.
- Type: String.
Example:
icinga2_agent__icinga2_api_user_login:
password: 'password'
username: 'enrolment-user'
icinga2_agent__icinga2_master_cn: 'master.example.com'
icinga2_agent__windows_version: 'v2.12.8'
Optional Role Variables¶
icinga2_agent__additional_icinga2_master_endpoints
- A list of dictionaries with additional Icinga2 master endpoints.
- Type: List of dictionaries.
-
Default:
[] -
Subkeys:
-
host:- Mandatory. Host of the master endpoint.
- Type: String.
-
port:- Optional. The Icinga2 port of the endpoint.
- Type: Number.
- Default:
5665
-
icinga2_agent__bind_host
- The bind host. This allows restricting on which IP addresses the Agent is listening.
- Type: String.
- Default: unset
icinga2_agent__cn
- The common name of the Icinga2 Agent. Tries to default to the FQDN of the server.
- Type: String.
- Default:
'{{ ansible_facts["nodename"] }}'
icinga2_agent__director_host_object_address
- The host address of the Icinga Director host object. Tries to default to the IPv4 address of the server.
- Type: String.
- Default:
'{{ ansible_facts["ip_addresses"][0] }}'for Windows, else'{{ ansible_facts["default_ipv4"]["address"] }}'
icinga2_agent__director_host_object_display_name
- The host display name of the Icinga Director host object. Tries to default to the hostname.
- Type: String.
- Default:
'{{ ansible_facts["hostname"] }}'
icinga2_agent__director_host_object_import
- A list of Icinga Director host templates which should be imported for this server.
- Type: List of strings.
- Default:
['tpl-host-windows']for Windows, else['tpl-host-linux']
icinga2_agent__icinga2_api_url
- The URL to the Icinga2 API. Will be used to generate the ticket for the agent certificate.
- Type: String.
- Default:
'https://{{ icinga2_agent__icinga2_master_host }}:{{ icinga2_agent__icinga2_master_port }}'
icinga2_agent__icinga2_master_host
- The host where the Icinga2 Master is running. Has to be reachable from the Agent.
- Type: String.
- Default:
'{{ icinga2_agent__icinga2_master_cn }}'
icinga2_agent__icinga2_master_port
- The port on which the Icinga2 master is reachable.
- Type: Number.
- Default:
5665
icinga2_agent__icingaweb2_url
- The URL where the IcingaWeb2 (the API) is reachable. This will be used to register the host in the Icinga Director (otherwise the host is registered in Icinga Core, but not visible in Icinga Director).
- Type: String.
- Default:
'https://{{ icinga2_agent__icinga2_master_host }}/icingaweb2'
icinga2_agent__icingaweb2_user_login
- A IcingaWeb2 user with
module/director,director/api,director/hostspermissions. This will be used to register the host in the Icinga Director. - Type: Dictionary.
- Default: unset
icinga2_agent__parent_zone
- The Icinga2 parent zone of the host.
- Type: String.
- Default:
'master'
icinga2_agent__service_enabled
- Enables or disables the Icinga2 service, analogous to
systemctl enable/disable --now. - Type: Bool.
- Default:
true
icinga2_agent__skip_pki_ticket
- Do not request a ticket from the Icinga2 master, and set the agent up without one. The certificate request of the agent then has to be signed on the master by hand, after every run of the role. See "How the Role Behaves".
- Type: Bool.
- Default:
false
icinga2_agent__validate_certs
- If false, TLS certificates offered by the Icinga Master will not be validated. This should only set to false used on personally controlled sites using self-signed certificates.
- Type: Bool.
- Default:
true
icinga2_agent__windows_download_path
- The path where the Icinga2.exe will be downloaded to. Certain Windows versions disallow the creation of files in
C:which requires one to adjust this setting. Note that the path has to exist. - Type: String.
- Default:
'C:'
icinga2_agent__windows_service_user
- The Windows user account under which the Icinga2 service will be run.
- Type: String.
- Default:
'NT AUTHORITY\SYSTEM'
icinga2_agent__zone
- The zone of the agent (endpoint). Change this if you are installing a satellite.
- Type: String.
- Default:
'{{ icinga2_agent__cn }}'
Example:
# optional
icinga2_agent__additional_icinga2_master_endpoints:
- host: 'master2.example.com'
port: 5665
- host: 'master3.example.com'
icinga2_agent__bind_host: '0.0.0.0'
icinga2_agent__cn: '{{ ansible_facts["nodename"] }}'
icinga2_agent__director_host_object_address: '{{ ansible_facts["default_ipv4"]["address"] }}'
icinga2_agent__director_host_object_display_name: '{{ ansible_facts["hostname"] }}'
icinga2_agent__director_host_object_import:
- 'tpl-host-linux'
icinga2_agent__icinga2_api_url: 'https://master3.example.com:{{ icinga2_agent__icinga2_master_port }}'
icinga2_agent__icinga2_master_host: '192.0.2.10'
icinga2_agent__icinga2_master_port: 5665
icinga2_agent__icingaweb2_url: 'https://monitoring.example.com/icingaweb2'
icinga2_agent__icingaweb2_user_login:
password: 'password'
username: 'enrolment-user'
icinga2_agent__parent_zone: 'satellite01'
icinga2_agent__service_enabled: true
icinga2_agent__skip_pki_ticket: false
icinga2_agent__validate_certs: true
icinga2_agent__windows_download_path: 'D:\Downloads'
icinga2_agent__windows_service_user: 'Icinga Service User'
icinga2_agent__zone: 'satellite'
Troubleshooting¶
The run aborts with icinga2_agent: Could not get a PKI ticket from ...
-
The message contains the answer of the Icinga2 master API. Fix the cause and run the role again:
Status code was 401: The username or password inicinga2_agent__icinga2_api_user_loginis wrong.Status code was 404: The API user lacks theactions/generate-ticketpermission on the master; Icinga2 answers 404 instead of 403 in this case. Also check thaticinga2_agent__icinga2_api_urlpoints to the Icinga2 API (port 5665 by default), not to IcingaWeb2.Status code was 500: Check the log of the Icinga2 master. It answers 500 for example if itsTicketSaltconstant is not set.Status code was -1: The master API did not answer at all. Check thaticinga2_agent__icinga2_api_urlis reachable from the agent (DNS, firewall).
-
To sign the agent certificate on the master by hand instead, set
icinga2_agent__skip_pki_ticket: true(see "How the Role Behaves").
The run aborts with icinga2_agent: icinga2_agent__icinga2_api_user_login is not set
- Set
icinga2_agent__icinga2_api_user_login, or seticinga2_agent__skip_pki_ticket: trueto sign the agent certificate on the master by hand.
icinga2_agent: The agent requested its certificate without a ticket
icinga2_agent__skip_pki_ticketistrue. On the Icinga2 master, runicinga2 ca list, and sign the newest request for the agent's CN withicinga2 ca sign <fingerprint>.