Ansible role to install and configure the Zabbix Agent 2
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Simon Cornet 264fcbb5b5
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
docs: improve readme
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 17:28:33 +02:00
.woodpecker chore(package): update cr.simoncor.net/dockerhub/davidanson/markdownlint-cli2 docker tag to v0.23.3 2026-09-20 05:51:56 +00:00
defaults feat: add role enablement gate 2026-07-22 08:59:34 +02:00
files/zabbix/plugins.d feat: test attempt 2 2025-10-03 11:07:26 +02:00
handlers feat: test attempt 2 2025-10-03 11:07:26 +02:00
meta feat: move deps to playbook 2026-05-08 15:44:27 +02:00
roles fix: add missing zabbix_prereq 2026-06-15 17:08:17 +02:00
tasks feat: add role enablement gate 2026-07-22 08:59:34 +02:00
templates feat: test attempt 2 2025-10-03 11:07:26 +02:00
.ansible-lint fix: exclude only sops yml files from lint 2026-07-14 16:24:02 +02:00
.editorconfig chore: add .editorconfig and .gitattributes 2026-05-27 14:24:08 +02:00
.gitattributes chore: add .editorconfig and .gitattributes 2026-05-27 14:24:08 +02:00
.gitignore feat: initial commit 2025-04-16 17:32:51 +02:00
.markdownlint-cli2.jsonc style: ignore line length for markdown tables 2026-05-15 13:44:06 +02:00
.sops.yaml fix: correct sops regex to ya?ml 2026-07-14 16:02:09 +02:00
.yamllint chore: exclude .yml files from lint configs 2026-07-14 16:17:45 +02:00
AGENTS.md style: align markdown table formatting for MD060 compliance 2026-05-18 18:26:21 +02:00
ansible.cfg chore: sync linting and config files from common 2026-07-14 11:33:16 +02:00
playbook.yaml chore(playbook): run galaxy install only on first host 2026-08-13 08:49:04 +02:00
readme.md docs: improve readme 2026-10-05 17:28:33 +02:00
renovate.json fix(ci): use central config 2025-06-17 17:58:22 +02:00

Ansible Role: Zabbix Agent

This role installs and configures the Zabbix Agent 2. The agent is configured to talk to a Zabbix proxy (or server) and, by default, uses a pre-shared key (PSK) for encryption.

Requirements

Operating System Version
Alpine 3.23
Debian 13
SLES 15
Ubuntu 24.04 LTS

Dependencies

The role zabbix_prereq must run first. It installs the Zabbix package repository (not needed on Alpine, which uses its own packages). The included playbook.yaml does this for you.

Variables

Variable Required Default Description
zabbix_agent_enable No true Enable or disable the whole role
zabbix_major_version No "7.4" Zabbix major version to install (reinstalls on mismatch)
zabbix_agent_psk_enable No true Enable PSK encryption (TLSConnect and TLSAccept)
zabbix_agent_psk_id Yes* PSK identity
zabbix_agent_psk Yes* "superlongpsk" PSK value, written to /etc/zabbix/zabbix_agent.psk
zabbix_agent_listen_port No "10050" Port the agent listens on
zabbix_agent_hostname No inventory_hostname Host name as shown in Zabbix
zabbix_agent_hostinterface No inventory_hostname Address Zabbix uses to connect to the host
zabbix_proxy_address No "zabbix.example.com" Zabbix proxy or server (used for Server and ServerActive)
zabbix_proxy_port No "10051" Port of the proxy or server for active checks
zabbix_user_sudo No true Install a sudoers file giving the zabbix user passwordless sudo

* Only if zabbix_agent_psk_enable is true. The default PSK is a placeholder: always override it.

The PSK is a secret and belongs in sops-encrypted inventory variables.

Example

With PSK:

zabbix_proxy_address: "proxy.monitor.localnet.internal"
zabbix_agent_psk_id: "client-psk"
zabbix_agent_psk: "replace-with-sops-encrypted-psk"

Without PSK:

zabbix_proxy_address: "proxy.monitor.localnet.internal"
zabbix_agent_psk_enable: false

DNS override

If DNS is complicated or permanently broken for some reason, the hostname and hostinterface can be overridden. The hostname is the visible name in Zabbix. The hostinterface is what Zabbix uses to connect to the host.

zabbix_agent_hostname: "server.example.com"
zabbix_agent_hostinterface: "192.168.10.10"

This is possible, but please only use it if really required.

What the role does

  • Installs zabbix-agent2 and its plugins (zabbix-agent2-plugin-*) when the installed version does not match zabbix_major_version. The existing agent packages are removed first.
  • Writes /etc/zabbix/zabbix_agent2.conf and the PSK file /etc/zabbix/zabbix_agent.psk.
  • Copies the plugin configuration files from files/zabbix/plugins.d/ (currently nvidia.conf) to /etc/zabbix/zabbix_agent2.d/plugins.d/.
  • Adds the zabbix user to the docker group when that group exists.
  • Installs /etc/sudoers.d/zabbix (zabbix ALL=(ALL) NOPASSWD: ALL) when zabbix_user_sudo is true.
  • Restarts and enables the zabbix-agent2 service when configuration changes.

The generated configuration also sets AllowKey=system.run[*], so remote commands are permitted. Keep the agent reachable only from your proxy or server.

Usage

Run the role through Semaphore using playbook.yaml. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml on the controller to fetch the latest zabbix_prereq and zabbix_agent roles, then executes both on all hosts.

The agent listens on TCP zabbix_agent_listen_port (default 10050).