--- - name: Patching | Start Windows patch cycle ansible.builtin.set_fact: _aim_patch_cycles: '{{ _aim_patch_cycle_number | int }}' _aim_patch_cycle_stop: false _aim_patch_cycle_reboot_performed: false - name: Patching | Search available Windows updates for this wave ansible.windows.win_updates: category_names: '{{ os_patching_windows_categories }}' state: searched reboot: false register: _aim_windows_cycle_search - name: Patching | Record Windows update discovery ansible.builtin.set_fact: _aim_windows_searches: '{{ _aim_windows_searches + [_aim_windows_cycle_search] }}' _aim_windows_update_queue: '{{ _aim_windows_cycle_search | aim_windows_update_queue }}' - name: Patching | Reboot when discovery itself reports a required reboot ansible.windows.win_reboot: msg: '{{ os_patching_reboot_message }}' pre_reboot_delay: '{{ [2, (os_patching_reboot_delay_minutes | int) * 60] | max }}' reboot_timeout: '{{ os_patching_reboot_timeout | int }}' register: _aim_windows_search_reboot when: - _aim_windows_cycle_search.reboot_required | default(false) | bool - os_patching_reboot | bool - name: Patching | Record discovery-time reboot boundary ansible.builtin.set_fact: _aim_patch_cycle_stop: true _aim_patch_cycle_reboot_performed: '{{ _aim_windows_search_reboot.rebooted | default(false) | bool }}' _aim_patch_any_reboot_performed: >- {{ (_aim_patch_any_reboot_performed | bool) or (_aim_windows_search_reboot.rebooted | default(false) | bool) }} _aim_patch_reboot_required_after: >- {{ false if (_aim_windows_search_reboot.rebooted | default(false) | bool) else true }} when: - _aim_windows_search_reboot is defined - not (_aim_windows_search_reboot.skipped | default(false) | bool) - name: Patching | Defer discovery-time required reboot ansible.builtin.set_fact: _aim_patch_cycle_stop: true _aim_patch_done: true _aim_patch_reboot_deferred: true _aim_patch_reboot_required_after: true _aim_patch_continuation_required: true _aim_patch_remaining_updates_known: true when: - _aim_windows_cycle_search.reboot_required | default(false) | bool - not (os_patching_reboot | bool) - name: Patching | Finish when no updates are available ansible.builtin.set_fact: _aim_patch_done: true _aim_patch_remaining_updates_known: true _aim_patch_continuation_required: '{{ _aim_windows_cycle_search.reboot_required | default(false) | bool }}' _aim_patch_reboot_required_after: '{{ _aim_windows_cycle_search.reboot_required | default(false) | bool }}' when: - (_aim_windows_update_queue | length) == 0 - not (_aim_patch_cycle_stop | bool) - name: Patching | Install discovered Windows updates sequentially ansible.builtin.include_tasks: windows_update_one.yml loop: '{{ _aim_windows_update_queue }}' loop_control: loop_var: _aim_windows_update label: '{{ _aim_windows_update.title }}' when: - not (_aim_patch_done | bool) - not (_aim_patch_cycle_stop | bool) - name: Patching | Final read-only discovery after completed non-reboot wave ansible.windows.win_updates: category_names: '{{ os_patching_windows_categories }}' state: searched reboot: false register: _aim_windows_cycle_final_search when: - not (_aim_patch_done | bool) - not (_aim_patch_cycle_stop | bool) - not (_aim_patch_action_failed | bool) - name: Patching | Record final non-reboot wave state ansible.builtin.set_fact: _aim_windows_searches: '{{ _aim_windows_searches + [_aim_windows_cycle_final_search] }}' _aim_patch_remaining_updates_known: true _aim_patch_continuation_required: '{{ (_aim_windows_cycle_final_search.found_update_count | default(0) | int) > 0 }}' _aim_patch_reboot_required_after: '{{ _aim_windows_cycle_final_search.reboot_required | default(false) | bool }}' _aim_patch_done: true when: - _aim_windows_cycle_final_search is defined - not (_aim_windows_cycle_final_search.skipped | default(false) | bool) - name: Patching | Stop after operator-approved reboot boundary by default ansible.builtin.set_fact: _aim_patch_done: true _aim_patch_continuation_required: true _aim_patch_remaining_updates_known: false when: - _aim_patch_cycle_reboot_performed | bool - not (os_patching_rescan_after_reboot | bool) - name: Patching | Continue only when post-reboot rescan was explicitly enabled ansible.builtin.debug: msg: >- AIM completed a reboot boundary and will start another Windows patch cycle because os_patching_rescan_after_reboot is explicitly enabled. when: - _aim_patch_cycle_reboot_performed | bool - os_patching_rescan_after_reboot | bool - not (_aim_patch_action_failed | bool)