Zabbix Agent 2 Over A Pre-Shared Key
Zabbix agent 2 from the vendor's repository, its key pinned by fingerprint: passive checks only for the servers you list, over a pre-shared key generated on the host, no active checks until you name a server, remote commands refused. The live test asks with zabbix_get and is refused from an unlisted address, with a wrong key and in plaintext. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-03 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-zabbix-agent2?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [Zabbix Agent 2 Over A Pre-Shared Key](https://www.iac-bazaar.com/catalog/ansible-zabbix-agent2?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# Zabbix Agent 2 Over A Pre-Shared Key: https://www.iac-bazaar.com/catalog/ansible-zabbix-agent2 (download from your IaC Bazaar account)
```Preview:
Documentation
zabbix-agent2
Zabbix agent 2 from Zabbix's own repository, its signing key checked against a pinned fingerprint: passive checks answered only to the servers you list, every connection over a pre-shared key generated on the host, active checks off until you name a server, and remote commands refused. Original role for EL 10, live-tested with podman on Rocky Linux 10.
The vendor's repository, the vendor's key. EPEL carries only the classic
agent; agent 2 comes from repo.zabbix.com, added by the role only after the
signing key's fingerprint matches the one pinned in defaults (RSA 4096, Zabbix
LLC, 2024-2034). The role installs the agent from the 7.0 LTS line and takes
what that line ships.
The vendor's unit, our configuration. The unit runs the agent as the
zabbix user and checks the configuration in ExecStartPre. The role writes the
whole configuration root:zabbix 0640, listens on 127.0.0.1:10050 (the
package's own listener is *:10050, every address), and waits for the port and
for one steady process, because the unit is Type=simple and counts as started
the moment it forks.
A checker that does not read the key. zabbix_agent2 -T refuses an
unknown setting (exit 1) but passed a configuration whose pre-shared key file
was missing, three characters long, or unreadable by the agent - and the agent
then failed at start on the unreadable one (all measured). The role generates
the key (256 bits, hex) or checks yours (32-512 hex digits), and writes it
root:zabbix 0640.
Proven by zabbix_get. With the key, agent.ping answers 1 and
agent.hostname the name you set; system.run is "Unknown metric"; the right
key from an address the agent does not list is reset; a wrong key fails the
TLS handshake; a connection without TLS is reset. With no active server named,
the agent's log holds no heartbeat failures.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-victoria-logs
VictoriaLogs from the upstream release as a hardened service on loopback. Its JSON-lines endpoint answers 200 and stores nothing when the content type is wrong, so the README names the one it needs. The live test ingests two lines, gets the right one back from LogsQL, and sees an unwritten stream come back empty and bad LogsQL refused. Original role, live-tested on Rocky Linux 10.
ansible-alertmanager
Prometheus Alertmanager from the upstream release (sha256-verified) as a hardened system service on loopback, its cluster gossip listener switched off and its configuration checked by amtool before it lands. The live test posts an alert through the API and reads it back active, held by the default receiver, and expects no 9094 listener at all. Original role, live-tested on Rocky Linux 10.
ansible-alloy
Grafana Alloy from the upstream release (sha256-verified) as a hardened system service on loopback with --disable-reporting, a self-scrape pipeline that proves the collector runs, and its configuration checked by alloy validate before it lands. The live test reads Alloy's own metrics and asks the component API for the scrape component's health. Original role, live-tested on Rocky Linux 10.
ansible-blackbox-exporter
Prometheus Blackbox exporter from the upstream release (sha256-verified) as a hardened system service on loopback with HTTP and TCP modules, checked by --config.check before the file lands. The live test has it probe itself over HTTP and TCP (probe_success 1) and a port with nothing behind it (probe_success 0): it measures, not only answers. Original role, live-tested on Rocky Linux 10.
ansible-cockpit
Cockpit from BaseOS bound to loopback, with logins limited to an admin group through PAM and root refused outright. The live test sees an administrator log in while an ordinary account, a wrong password and root, placed in the admin group to isolate its own rule, are refused, and reads the login banner. Original role, live-tested on Rocky Linux 10.
ansible-fluent-bit
fluent-bit from EPEL, following a log-file glob it re-reads every few seconds and shipping over the Forward protocol, with retries unlimited instead of the default single retry. Its config is checked with --dry-run before it lands. The live test writes a line to a new file and watches it arrive at an aggregator it started. Original role, live-tested on Rocky Linux 10.