--- # PURPOSE: Patch operating systems # DESCRIPTION: Apply updates on Windows, Debian and RedHat-family systems; optionally reboot when required. # TARGETS: linux, windows # INPUTS (omitted values inherit inventory / role defaults): # aim_debug [bool]: false # os_patching_reboot [bool]: true # os_patching_windows_categories [list]: SecurityUpdates, CriticalUpdates, UpdateRollups, DefinitionUpdates, Updates # os_patching_serial [serial]: 100% # os_patching_reboot_timeout [int]: 600 # os_patching_reboot_delay_minutes [int]: 0 # os_patching_reboot_message [text]: AIM maintenance: operating system patching requires a reboot. # os_patching_rescan_after_reboot [bool]: false (Windows only; continue with a newly discovered patch wave after reboot) # AUTH: existing inventory / Vault credentials; no embedded passwords. # CHANGES: Updates production operating systems. Optional AIM-initiated reboots notify logged-in users and honor the configured delay. # EXAMPLE: ansible-playbook -i inventories//hosts.yml # playbooks/maintenance_patch_os.yml --limit --vault-id @prompt - name: Maintenance | Patch Linux hosts: linux gather_facts: true pre_tasks: - name: AIM | Validate diagnostics option ansible.builtin.assert: that: - (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true', 'false'] fail_msg: aim_debug must be a YAML/JSON boolean. quiet: true - name: AIM | Reject mixed platform membership ansible.builtin.assert: that: - (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1 fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups. quiet: true - name: AIM | Execution context ansible.builtin.debug: msg: host: '{{ inventory_hostname }}' diagnostics: Enabled; secret values are never included by this task. when: aim_debug | default(false) | bool become: true serial: '{{ os_patching_serial | default(''100%'') }}' roles: - role: maintenance_patch_os - name: Maintenance | Patch Windows hosts: windows gather_facts: true pre_tasks: - name: AIM | Validate diagnostics option ansible.builtin.assert: that: - (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true', 'false'] fail_msg: aim_debug must be a YAML/JSON boolean. quiet: true - name: AIM | Reject mixed platform membership ansible.builtin.assert: that: - (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1 fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups. quiet: true - name: AIM | Execution context ansible.builtin.debug: msg: host: '{{ inventory_hostname }}' diagnostics: Enabled; secret values are never included by this task. when: aim_debug | default(false) | bool serial: '{{ os_patching_serial | default(''100%'') }}' roles: - role: maintenance_patch_os