Files
Ansible/playbooks/maintenance_patch_os.yml
2026-09-22 19:23:17 +02:00

71 lines
3.2 KiB
YAML

---
# PURPOSE: Patch operating systems
# DESCRIPTION: Apply updates on Windows, Debian and RedHat-family systems; optionally reboot when required.
# TARGETS: linux, windows
# INPUTS (omitted values inherit inventory / role defaults):
# aim_debug [bool]: false
# os_patching_reboot [bool]: true
# os_patching_windows_categories [list]: SecurityUpdates, CriticalUpdates, UpdateRollups, DefinitionUpdates, Updates
# os_patching_serial [serial]: 100%
# os_patching_reboot_timeout [int]: 600
# os_patching_reboot_delay_minutes [int]: 0
# os_patching_reboot_message [text]: AIM maintenance: operating system patching requires a reboot.
# os_patching_rescan_after_reboot [bool]: false (Windows only; continue with a newly discovered patch wave after reboot)
# AUTH: existing inventory / Vault credentials; no embedded passwords.
# CHANGES: Updates production operating systems. Optional AIM-initiated reboots notify logged-in users and honor the configured delay.
# EXAMPLE: ansible-playbook -i inventories/<customer>/hosts.yml
# playbooks/maintenance_patch_os.yml --limit <host> --vault-id <customer>@prompt
- name: Maintenance | Patch Linux
hosts: linux
gather_facts: true
pre_tasks:
- name: AIM | Validate diagnostics option
ansible.builtin.assert:
that:
- (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true',
'false']
fail_msg: aim_debug must be a YAML/JSON boolean.
quiet: true
- name: AIM | Reject mixed platform membership
ansible.builtin.assert:
that:
- (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1
fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups.
quiet: true
- name: AIM | Execution context
ansible.builtin.debug:
msg:
host: '{{ inventory_hostname }}'
diagnostics: Enabled; secret values are never included by this task.
when: aim_debug | default(false) | bool
become: true
serial: '{{ os_patching_serial | default(''100%'') }}'
roles:
- role: maintenance_patch_os
- name: Maintenance | Patch Windows
hosts: windows
gather_facts: true
pre_tasks:
- name: AIM | Validate diagnostics option
ansible.builtin.assert:
that:
- (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true',
'false']
fail_msg: aim_debug must be a YAML/JSON boolean.
quiet: true
- name: AIM | Reject mixed platform membership
ansible.builtin.assert:
that:
- (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1
fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups.
quiet: true
- name: AIM | Execution context
ansible.builtin.debug:
msg:
host: '{{ inventory_hostname }}'
diagnostics: Enabled; secret values are never included by this task.
when: aim_debug | default(false) | bool
serial: '{{ os_patching_serial | default(''100%'') }}'
roles:
- role: maintenance_patch_os