aim-web2.1.0rc9
This commit is contained in:
@@ -0,0 +1,124 @@
|
||||
---
|
||||
- name: Patching | Start Windows patch wave
|
||||
ansible.builtin.set_fact:
|
||||
_aim_patch_cycles: '{{ _aim_patch_wave_number | int }}'
|
||||
_aim_patch_wave_task_failed: false
|
||||
_aim_patch_wave_result: {}
|
||||
_aim_patch_wave_failed: false
|
||||
_aim_patch_wave_reboot_performed: false
|
||||
|
||||
- name: Patching | Install current Windows update wave
|
||||
block:
|
||||
- name: Patching | Install all currently selected Windows updates
|
||||
ansible.windows.win_updates:
|
||||
category_names: '{{ os_patching_windows_categories }}'
|
||||
state: installed
|
||||
reboot: false
|
||||
register: _aim_patch_wave_result
|
||||
rescue:
|
||||
- name: Patching | Retain failed Windows update wave result
|
||||
ansible.builtin.set_fact:
|
||||
_aim_patch_wave_result: '{{ ansible_failed_result | default({}) }}'
|
||||
_aim_patch_wave_task_failed: true
|
||||
|
||||
- name: Patching | Append Windows update wave evidence
|
||||
ansible.builtin.set_fact:
|
||||
_aim_windows_update_runs: >-
|
||||
{{ _aim_windows_update_runs + [
|
||||
{
|
||||
'result': _aim_patch_wave_result,
|
||||
'task_failed': _aim_patch_wave_task_failed | bool,
|
||||
'wave': _aim_patch_wave_number | int
|
||||
}
|
||||
] }}
|
||||
|
||||
- name: Patching | Classify Windows update wave
|
||||
ansible.builtin.set_fact:
|
||||
_aim_patch_wave_failed: >-
|
||||
{{ (_aim_patch_wave_task_failed | bool) or
|
||||
(_aim_patch_wave_result | aim_windows_update_result_failed) }}
|
||||
_aim_patch_reboot_required_after: '{{ _aim_patch_wave_result.reboot_required | default(false) | bool }}'
|
||||
|
||||
- name: Patching | Record Windows update wave failure
|
||||
ansible.builtin.set_fact:
|
||||
_aim_patch_action_failed: true
|
||||
_aim_patch_done: true
|
||||
_aim_patch_continuation_required: true
|
||||
_aim_patch_remaining_updates_known: false
|
||||
_aim_patch_blocked_reason: '{{ _aim_patch_wave_result | aim_windows_update_block_reason }}'
|
||||
when: _aim_patch_wave_failed | bool
|
||||
|
||||
- name: Patching | Reboot after the completed Windows update wave
|
||||
ansible.windows.win_reboot:
|
||||
msg: '{{ os_patching_reboot_message }}'
|
||||
pre_reboot_delay: '{{ [2, (os_patching_reboot_delay_minutes | int) * 60] | max }}'
|
||||
reboot_timeout: '{{ os_patching_reboot_timeout | int }}'
|
||||
register: _aim_patch_wave_reboot
|
||||
when:
|
||||
- _aim_patch_wave_result.reboot_required | default(false) | bool
|
||||
- os_patching_reboot | bool
|
||||
|
||||
- name: Patching | Record completed Windows wave reboot boundary
|
||||
ansible.builtin.set_fact:
|
||||
_aim_patch_wave_reboot_performed: '{{ _aim_patch_wave_reboot.rebooted | default(false) | bool }}'
|
||||
_aim_patch_any_reboot_performed: >-
|
||||
{{ (_aim_patch_any_reboot_performed | bool) or
|
||||
(_aim_patch_wave_reboot.rebooted | default(false) | bool) }}
|
||||
_aim_patch_reboot_required_after: >-
|
||||
{{ false if (_aim_patch_wave_reboot.rebooted | default(false) | bool)
|
||||
else (_aim_patch_wave_result.reboot_required | default(false) | bool) }}
|
||||
when:
|
||||
- _aim_patch_wave_reboot is defined
|
||||
- not (_aim_patch_wave_reboot.skipped | default(false) | bool)
|
||||
|
||||
- name: Patching | Defer required reboot after Windows update wave
|
||||
ansible.builtin.set_fact:
|
||||
_aim_patch_done: true
|
||||
_aim_patch_reboot_deferred: true
|
||||
_aim_patch_reboot_required_after: true
|
||||
_aim_patch_continuation_required: true
|
||||
_aim_patch_remaining_updates_known: false
|
||||
when:
|
||||
- not (_aim_patch_wave_failed | bool)
|
||||
- _aim_patch_wave_result.reboot_required | default(false) | bool
|
||||
- not (os_patching_reboot | bool)
|
||||
|
||||
- name: Patching | Stop after approved Windows reboot boundary by default
|
||||
ansible.builtin.set_fact:
|
||||
_aim_patch_done: true
|
||||
_aim_patch_continuation_required: true
|
||||
_aim_patch_remaining_updates_known: false
|
||||
when:
|
||||
- _aim_patch_wave_reboot_performed | bool
|
||||
- not (os_patching_rescan_after_reboot | bool)
|
||||
|
||||
- name: Patching | Stop automatic continuation after a failed Windows wave
|
||||
ansible.builtin.set_fact:
|
||||
_aim_patch_done: true
|
||||
_aim_patch_continuation_required: true
|
||||
_aim_patch_remaining_updates_known: false
|
||||
when:
|
||||
- _aim_patch_wave_failed | bool
|
||||
|
||||
- name: Patching | Final read-only discovery after completed non-reboot Windows wave
|
||||
ansible.windows.win_updates:
|
||||
category_names: '{{ os_patching_windows_categories }}'
|
||||
state: searched
|
||||
reboot: false
|
||||
register: _aim_windows_wave_final_search
|
||||
when:
|
||||
- not (_aim_patch_done | bool)
|
||||
- not (_aim_patch_wave_reboot_performed | bool)
|
||||
- not (_aim_patch_wave_result.reboot_required | default(false) | bool)
|
||||
- not (_aim_patch_wave_failed | bool)
|
||||
|
||||
- name: Patching | Record completed non-reboot Windows wave state
|
||||
ansible.builtin.set_fact:
|
||||
_aim_windows_searches: '{{ _aim_windows_searches + [_aim_windows_wave_final_search] }}'
|
||||
_aim_patch_remaining_updates_known: true
|
||||
_aim_patch_continuation_required: '{{ (_aim_windows_wave_final_search.found_update_count | default(0) | int) > 0 }}'
|
||||
_aim_patch_reboot_required_after: '{{ _aim_windows_wave_final_search.reboot_required | default(false) | bool }}'
|
||||
_aim_patch_done: true
|
||||
when:
|
||||
- _aim_windows_wave_final_search is defined
|
||||
- not (_aim_windows_wave_final_search.skipped | default(false) | bool)
|
||||
Reference in New Issue
Block a user