- name: Patching | Initialize Debian report state ansible.builtin.set_fact: _aim_patch_action_failed: false _aim_patch_pre_reboot_performed: false _aim_patch_post_reboot_performed: false - name: Patching | Detect pending Debian reboot before patching become: true ansible.builtin.stat: path: /var/run/reboot-required register: _aim_patch_pre_reboot_probe - name: Patching | Record pre-existing Debian reboot state ansible.builtin.set_fact: _aim_patch_preexisting_reboot_required: '{{ _aim_patch_pre_reboot_probe.stat.exists | default(false) | bool }}' - name: Patching | Publish blocked Debian result when reboot is deferred when: - _aim_patch_preexisting_reboot_required | bool - not (os_patching_reboot | bool) block: - name: Patching | Build blocked Debian patch report ansible.builtin.set_fact: _aim_patch_report: >- {{ 'debian' | aim_report_patch_blocked(ansible_check_mode, os_patching_reboot_delay_minutes | int) }} - name: AIM | Publish blocked operation result ansible.builtin.set_stats: per_host: true aggregate: false data: aim_output: protocol: aim_output_v1 schema: patch_summary_v1 data: '{{ _aim_patch_report }}' - name: Patching | Require reboot before continuing Debian patching ansible.builtin.fail: msg: >- A reboot is already pending from a previous update or installation. Reboot the host first, or rerun with "Reboot when required" enabled. No new package upgrade was started by this run. - name: Patching | Clear pre-existing Debian reboot before patching become: true ansible.builtin.reboot: msg: '{{ os_patching_reboot_message }}' pre_reboot_delay: '{{ (os_patching_reboot_delay_minutes | int) * 60 }}' reboot_timeout: '{{ os_patching_reboot_timeout | int }}' register: _aim_patch_pre_reboot when: - _aim_patch_preexisting_reboot_required | bool - os_patching_reboot | bool - not ansible_check_mode - name: Patching | Record pre-patch Debian reboot ansible.builtin.set_fact: _aim_patch_pre_reboot_performed: '{{ _aim_patch_pre_reboot.rebooted | default(false) | bool }}' - name: Patching | Collect installed package facts before operation ansible.builtin.package_facts: manager: auto - name: Patching | Snapshot installed package facts before operation ansible.builtin.set_fact: _aim_packages_before: '{{ ansible_facts.packages | default({}) }}' - name: Patching | Apply native Debian updates block: - name: Update Debian-based host become: true ansible.builtin.apt: upgrade: safe update_cache: true cache_valid_time: 3600 autoremove: true - name: Check if Debian-based host requires reboot become: true ansible.builtin.stat: path: /var/run/reboot-required register: os_patching_reboot_required rescue: - name: Patching | Retain failed action for reporting ansible.builtin.set_fact: _aim_patch_action_failed: true - name: Patching | Reboot Debian host after updates when required become: true ansible.builtin.reboot: msg: '{{ os_patching_reboot_message }}' pre_reboot_delay: '{{ (os_patching_reboot_delay_minutes | int) * 60 }}' reboot_timeout: '{{ os_patching_reboot_timeout | int }}' register: _aim_patch_post_reboot when: - os_patching_reboot | bool - not ansible_check_mode - os_patching_reboot_required.stat.exists | default(false) | bool - name: Patching | Record post-update Debian reboot ansible.builtin.set_fact: _aim_patch_post_reboot_performed: '{{ _aim_patch_post_reboot.rebooted | default(false) | bool }}' - name: Patching | Collect installed package facts after operation ansible.builtin.package_facts: manager: auto - name: Patching | Snapshot installed package facts after operation ansible.builtin.set_fact: _aim_packages_after: '{{ ansible_facts.packages | default({}) }}' - name: Patching | Compare package database snapshots ansible.builtin.set_fact: _aim_patch_report: >- {{ _aim_packages_before | aim_report_patch_linux( _aim_packages_after, 'debian', ansible_check_mode, not _aim_patch_action_failed, os_patching_reboot_required.stat.exists | default(none), (_aim_patch_pre_reboot_performed | bool) or (_aim_patch_post_reboot_performed | bool), _aim_patch_preexisting_reboot_required | bool, os_patching_reboot | bool, os_patching_reboot_delay_minutes | int ) }} - name: Patching | Package change summary ansible.builtin.debug: msg: '{{ _aim_patch_report }}' - name: AIM | Publish operation result ansible.builtin.set_stats: per_host: true aggregate: false data: aim_output: protocol: aim_output_v1 schema: patch_summary_v1 data: '{{ _aim_patch_report }}' - name: Patching | Preserve native operation failure ansible.builtin.fail: msg: >- The native Debian patch operation failed. Available observed package changes and reboot state are in the structured result. If a reboot is reported as required, reboot before retrying. when: _aim_patch_action_failed | bool