Files
infra-automation/roles/system_info/tasks/gather_network.yml
ansible 70b57d223f Add system_info role for comprehensive infrastructure inventory
New role for gathering detailed system information including CPU, GPU,
RAM, disk, network, and hypervisor details with JSON export capabilities.

Role capabilities:
- Comprehensive hardware detection (CPU, GPU, RAM, disk, network)
- Hypervisor detection (KVM, Proxmox, LXD, Docker, Podman, VMware, Hyper-V)
- System information gathering (OS, kernel, uptime, security modules)
- Health checks and validation tasks
- JSON export with timestamped backups
- Human-readable summary generation
- Support for multiple Linux distributions

Features:
- Modular task organization by information type
- Feature toggles for selective gathering
- CLAUDE.md compliant validation tasks including:
  * Disk usage monitoring (>80% warnings)
  * Memory usage statistics
  * Top CPU and memory processes
  * System uptime tracking
  * Logged users reporting
- OS-specific variable handling
- DMI/SMBIOS hardware information
- SMART disk health status
- Network interface statistics

File structure:
roles/system_info/
├── README.md              # Comprehensive documentation
├── defaults/main.yml      # Configurable defaults
├── vars/main.yml          # Role variables
├── meta/main.yml          # Galaxy metadata
├── tasks/
│   ├── main.yml          # Main task coordinator
│   ├── install.yml       # Package installation
│   ├── gather_system.yml # OS and system info
│   ├── gather_cpu.yml    # CPU details
│   ├── gather_gpu.yml    # GPU detection
│   ├── gather_memory.yml # RAM information
│   ├── gather_disk.yml   # Disk and LVM info
│   ├── gather_network.yml # Network configuration
│   ├── detect_hypervisor.yml # Virtualization detection
│   ├── export_stats.yml  # JSON export
│   └── validate.yml      # Health checks (CLAUDE.md compliant)
├── templates/
│   └── summary.txt.j2    # Human-readable summary
├── handlers/
│   └── main.yml          # Service handlers
└── tests/
    └── test.yml          # Basic test playbook

Use cases:
- Infrastructure inventory for CMDB integration
- Capacity planning and resource optimization
- Hardware audit and compliance reporting
- Hypervisor and VM tracking
- System health monitoring
- Documentation generation

Output:
- JSON: ./stats/machines/<fqdn>/system_info.json
- Backup: ./stats/machines/<fqdn>/system_info_<timestamp>.json
- Summary: ./stats/machines/<fqdn>/summary.txt

Requirements:
- Ansible >= 2.9
- Root/sudo access for hardware information
- Packages: lshw, dmidecode, pciutils, usbutils, smartmontools, ethtool

Compliance:
- CLAUDE.md health check requirements implemented
- CIS Benchmark support for system auditing
- NIST compliance documentation support
- Security-first design with minimal system impact

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-11 01:36:01 +01:00

91 lines
2.7 KiB
YAML

---
# Network information gathering tasks
- name: Gather network interfaces information
set_fact:
system_info_interfaces: "{{ ansible_interfaces }}"
tags: [gather, network]
- name: Gather IP addresses
shell: ip -br addr show | grep -v "^lo"
register: system_info_ip_addr_raw
changed_when: false
failed_when: false
tags: [gather, network]
- name: Gather detailed network configuration
shell: ip addr show
register: system_info_ip_full_raw
changed_when: false
tags: [gather, network]
- name: Gather routing table
shell: ip route show
register: system_info_routes_raw
changed_when: false
tags: [gather, network]
- name: Gather DNS configuration
shell: |
if [ -f /etc/resolv.conf ]; then
grep "^nameserver" /etc/resolv.conf
else
echo "No resolv.conf found"
fi
register: system_info_dns_raw
changed_when: false
tags: [gather, network]
- name: Gather network interface statistics
shell: ip -s link show
register: system_info_net_stats_raw
changed_when: false
tags: [gather, network]
- name: Check for active connections
shell: ss -tunapl | head -20
register: system_info_connections_raw
changed_when: false
become: true
failed_when: false
tags: [gather, network]
- name: Gather listening ports
shell: ss -tlnp
register: system_info_listening_raw
changed_when: false
become: true
failed_when: false
tags: [gather, network]
- name: Build network interface details
set_fact:
system_info_network_interfaces: {}
tags: [gather, network]
- name: Gather details for each interface
set_fact:
system_info_network_interfaces: "{{ system_info_network_interfaces | combine({item: {
'ipv4': ansible_facts[item]['ipv4'] | default({}),
'ipv6': ansible_facts[item]['ipv6'] | default([]),
'mac': ansible_facts[item]['macaddress'] | default('N/A'),
'mtu': ansible_facts[item]['mtu'] | default('N/A'),
'state': ansible_facts[item]['active'] | default(false) | string,
'type': ansible_facts[item]['type'] | default('unknown')
}}) }}"
loop: "{{ ansible_interfaces }}"
when: item != 'lo'
tags: [gather, network]
- name: Aggregate network information
set_fact:
system_info_network:
interfaces: "{{ system_info_network_interfaces }}"
ip_addresses: "{{ system_info_ip_addr_raw.stdout_lines | default([]) }}"
routes: "{{ system_info_routes_raw.stdout_lines }}"
dns_servers: "{{ system_info_dns_raw.stdout_lines | default([]) }}"
listening_ports: "{{ system_info_listening_raw.stdout_lines | default([]) }}"
default_ipv4: "{{ ansible_default_ipv4 | default({}) }}"
default_ipv6: "{{ ansible_default_ipv6 | default({}) }}"
tags: [gather, network]