aim-web2.1.0rc9
This commit is contained in:
@@ -1,35 +1,70 @@
|
||||
---
|
||||
- name: "Maintenance | Patch operating system"
|
||||
hosts: all
|
||||
# PURPOSE: Patch operating systems
|
||||
# DESCRIPTION: Apply updates on Windows, Debian and RedHat-family systems; optionally reboot when required.
|
||||
# TARGETS: linux, windows
|
||||
# INPUTS (omitted values inherit inventory / role defaults):
|
||||
# aim_debug [bool]: false
|
||||
# os_patching_reboot [bool]: true
|
||||
# os_patching_windows_categories [list]: SecurityUpdates, CriticalUpdates, UpdateRollups, DefinitionUpdates, Updates
|
||||
# os_patching_serial [serial]: 100%
|
||||
# os_patching_reboot_timeout [int]: 600
|
||||
# os_patching_reboot_delay_minutes [int]: 0
|
||||
# os_patching_reboot_message [text]: AIM maintenance: operating system patching requires a reboot.
|
||||
# os_patching_rescan_after_reboot [bool]: false (Windows only; continue with a newly discovered patch wave after reboot)
|
||||
# AUTH: existing inventory / Vault credentials; no embedded passwords.
|
||||
# CHANGES: Updates production operating systems. Optional AIM-initiated reboots notify logged-in users and honor the configured delay.
|
||||
# EXAMPLE: ansible-playbook -i inventories/<customer>/hosts.yml
|
||||
# playbooks/maintenance_patch_os.yml --limit <host> --vault-id <customer>@prompt
|
||||
- name: Maintenance | Patch Linux
|
||||
hosts: linux
|
||||
gather_facts: true
|
||||
|
||||
tasks:
|
||||
- name: "Debian | Update package cache and upgrade packages"
|
||||
when: ansible_facts['os_family'] == 'Debian'
|
||||
ansible.builtin.apt:
|
||||
update_cache: true
|
||||
upgrade: dist
|
||||
|
||||
- name: "RedHat | Upgrade installed packages"
|
||||
when: ansible_facts['os_family'] == 'RedHat'
|
||||
ansible.builtin.dnf:
|
||||
name: '*'
|
||||
state: latest
|
||||
|
||||
- name: "Windows | Install available updates"
|
||||
when: ansible_facts['os_family'] == 'Windows'
|
||||
ansible.windows.win_updates:
|
||||
category_names:
|
||||
- CriticalUpdates
|
||||
- SecurityUpdates
|
||||
- UpdateRollups
|
||||
- Updates
|
||||
reboot: false
|
||||
register: windows_updates
|
||||
|
||||
- name: "Windows | Report reboot requirement"
|
||||
when:
|
||||
- ansible_facts['os_family'] == 'Windows'
|
||||
- windows_updates.reboot_required | default(false)
|
||||
pre_tasks:
|
||||
- name: AIM | Validate diagnostics option
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true',
|
||||
'false']
|
||||
fail_msg: aim_debug must be a YAML/JSON boolean.
|
||||
quiet: true
|
||||
- name: AIM | Reject mixed platform membership
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1
|
||||
fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups.
|
||||
quiet: true
|
||||
- name: AIM | Execution context
|
||||
ansible.builtin.debug:
|
||||
msg: "Windows updates were installed and a reboot is required. No reboot was performed."
|
||||
msg:
|
||||
host: '{{ inventory_hostname }}'
|
||||
diagnostics: Enabled; secret values are never included by this task.
|
||||
when: aim_debug | default(false) | bool
|
||||
become: true
|
||||
serial: '{{ os_patching_serial | default(''100%'') }}'
|
||||
roles:
|
||||
- role: maintenance_patch_os
|
||||
- name: Maintenance | Patch Windows
|
||||
hosts: windows
|
||||
gather_facts: true
|
||||
pre_tasks:
|
||||
- name: AIM | Validate diagnostics option
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true',
|
||||
'false']
|
||||
fail_msg: aim_debug must be a YAML/JSON boolean.
|
||||
quiet: true
|
||||
- name: AIM | Reject mixed platform membership
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1
|
||||
fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups.
|
||||
quiet: true
|
||||
- name: AIM | Execution context
|
||||
ansible.builtin.debug:
|
||||
msg:
|
||||
host: '{{ inventory_hostname }}'
|
||||
diagnostics: Enabled; secret values are never included by this task.
|
||||
when: aim_debug | default(false) | bool
|
||||
serial: '{{ os_patching_serial | default(''100%'') }}'
|
||||
roles:
|
||||
- role: maintenance_patch_os
|
||||
|
||||
Reference in New Issue
Block a user