--- - name: Patching | Initialize single Windows update result ansible.builtin.set_fact: _aim_windows_single_result: {} _aim_windows_single_task_failed: false - name: Patching | Install one Windows update block: - name: 'Patching | Install {{ _aim_windows_update.title }}' ansible.windows.win_updates: category_names: '{{ os_patching_windows_categories }}' state: installed reboot: false accept_list: - '{{ _aim_windows_update.selector }}' register: _aim_windows_single_result rescue: - name: Patching | Retain failed single-update result ansible.builtin.set_fact: _aim_windows_single_result: '{{ ansible_failed_result | default({}) }}' _aim_windows_single_task_failed: true - name: Patching | Append single-update evidence ansible.builtin.set_fact: _aim_windows_update_runs: >- {{ _aim_windows_update_runs + [ { 'requested': _aim_windows_update, 'result': _aim_windows_single_result, 'task_failed': _aim_windows_single_task_failed | bool } ] }} - name: Patching | Classify single-update execution state ansible.builtin.set_fact: _aim_windows_single_failed: >- {{ (_aim_windows_single_task_failed | bool) or (_aim_windows_single_result | aim_windows_update_result_failed) }} _aim_patch_reboot_required_after: '{{ _aim_windows_single_result.reboot_required | default(false) | bool }}' - name: Patching | Stop this patch wave after an update failure ansible.builtin.set_fact: _aim_patch_action_failed: true _aim_patch_cycle_stop: true _aim_patch_done: true _aim_patch_continuation_required: true _aim_patch_remaining_updates_known: false _aim_patch_blocked_reason: '{{ _aim_windows_single_result | aim_windows_update_block_reason }}' when: _aim_windows_single_failed | bool - name: Patching | Reboot Windows at a sequential update boundary ansible.windows.win_reboot: msg: '{{ os_patching_reboot_message }}' pre_reboot_delay: '{{ [2, (os_patching_reboot_delay_minutes | int) * 60] | max }}' reboot_timeout: '{{ os_patching_reboot_timeout | int }}' register: _aim_windows_single_reboot when: - not (_aim_windows_single_failed | bool) - _aim_windows_single_result.reboot_required | default(false) | bool - os_patching_reboot | bool - name: Patching | Record completed sequential reboot boundary ansible.builtin.set_fact: _aim_patch_cycle_stop: true _aim_patch_cycle_reboot_performed: '{{ _aim_windows_single_reboot.rebooted | default(false) | bool }}' _aim_patch_any_reboot_performed: >- {{ (_aim_patch_any_reboot_performed | bool) or (_aim_windows_single_reboot.rebooted | default(false) | bool) }} _aim_patch_reboot_required_after: >- {{ false if (_aim_windows_single_reboot.rebooted | default(false) | bool) else (_aim_windows_single_result.reboot_required | default(false) | bool) }} when: - _aim_windows_single_reboot is defined - not (_aim_windows_single_reboot.skipped | default(false) | bool) - name: Patching | Defer required reboot and stop the current patch wave ansible.builtin.set_fact: _aim_patch_cycle_stop: true _aim_patch_done: true _aim_patch_reboot_deferred: true _aim_patch_reboot_required_after: true _aim_patch_continuation_required: true _aim_patch_remaining_updates_known: false when: - not (_aim_windows_single_failed | bool) - _aim_windows_single_result.reboot_required | default(false) | bool - not (os_patching_reboot | bool)