145 lines
5.2 KiB
YAML
145 lines
5.2 KiB
YAML
- name: Patching | Initialize Debian report state
|
|
ansible.builtin.set_fact:
|
|
_aim_patch_action_failed: false
|
|
_aim_patch_pre_reboot_performed: false
|
|
_aim_patch_post_reboot_performed: false
|
|
|
|
- name: Patching | Detect pending Debian reboot before patching
|
|
become: true
|
|
ansible.builtin.stat:
|
|
path: /var/run/reboot-required
|
|
register: _aim_patch_pre_reboot_probe
|
|
|
|
- name: Patching | Record pre-existing Debian reboot state
|
|
ansible.builtin.set_fact:
|
|
_aim_patch_preexisting_reboot_required: '{{ _aim_patch_pre_reboot_probe.stat.exists | default(false) | bool }}'
|
|
|
|
- name: Patching | Publish blocked Debian result when reboot is deferred
|
|
when:
|
|
- _aim_patch_preexisting_reboot_required | bool
|
|
- not (os_patching_reboot | bool)
|
|
block:
|
|
- name: Patching | Build blocked Debian patch report
|
|
ansible.builtin.set_fact:
|
|
_aim_patch_report: >-
|
|
{{ 'debian' | aim_report_patch_blocked(ansible_check_mode,
|
|
os_patching_reboot_delay_minutes | int) }}
|
|
- name: AIM | Publish blocked operation result
|
|
ansible.builtin.set_stats:
|
|
per_host: true
|
|
aggregate: false
|
|
data:
|
|
aim_output:
|
|
protocol: aim_output_v1
|
|
schema: patch_summary_v1
|
|
data: '{{ _aim_patch_report }}'
|
|
- name: Patching | Require reboot before continuing Debian patching
|
|
ansible.builtin.fail:
|
|
msg: >-
|
|
A reboot is already pending from a previous update or installation. Reboot the host first,
|
|
or rerun with "Reboot when required" enabled. No new package upgrade was started by this run.
|
|
|
|
- name: Patching | Clear pre-existing Debian reboot before patching
|
|
become: true
|
|
ansible.builtin.reboot:
|
|
msg: '{{ os_patching_reboot_message }}'
|
|
pre_reboot_delay: '{{ (os_patching_reboot_delay_minutes | int) * 60 }}'
|
|
reboot_timeout: '{{ os_patching_reboot_timeout | int }}'
|
|
register: _aim_patch_pre_reboot
|
|
when:
|
|
- _aim_patch_preexisting_reboot_required | bool
|
|
- os_patching_reboot | bool
|
|
- not ansible_check_mode
|
|
|
|
- name: Patching | Record pre-patch Debian reboot
|
|
ansible.builtin.set_fact:
|
|
_aim_patch_pre_reboot_performed: '{{ _aim_patch_pre_reboot.rebooted | default(false) | bool }}'
|
|
|
|
- name: Patching | Collect installed package facts before operation
|
|
ansible.builtin.package_facts:
|
|
manager: auto
|
|
|
|
- name: Patching | Snapshot installed package facts before operation
|
|
ansible.builtin.set_fact:
|
|
_aim_packages_before: '{{ ansible_facts.packages | default({}) }}'
|
|
|
|
- name: Patching | Apply native Debian updates
|
|
block:
|
|
- name: Update Debian-based host
|
|
become: true
|
|
ansible.builtin.apt:
|
|
upgrade: safe
|
|
update_cache: true
|
|
cache_valid_time: 3600
|
|
autoremove: true
|
|
- name: Check if Debian-based host requires reboot
|
|
become: true
|
|
ansible.builtin.stat:
|
|
path: /var/run/reboot-required
|
|
register: os_patching_reboot_required
|
|
rescue:
|
|
- name: Patching | Retain failed action for reporting
|
|
ansible.builtin.set_fact:
|
|
_aim_patch_action_failed: true
|
|
|
|
- name: Patching | Reboot Debian host after updates when required
|
|
become: true
|
|
ansible.builtin.reboot:
|
|
msg: '{{ os_patching_reboot_message }}'
|
|
pre_reboot_delay: '{{ (os_patching_reboot_delay_minutes | int) * 60 }}'
|
|
reboot_timeout: '{{ os_patching_reboot_timeout | int }}'
|
|
register: _aim_patch_post_reboot
|
|
when:
|
|
- os_patching_reboot | bool
|
|
- not ansible_check_mode
|
|
- os_patching_reboot_required.stat.exists | default(false) | bool
|
|
|
|
- name: Patching | Record post-update Debian reboot
|
|
ansible.builtin.set_fact:
|
|
_aim_patch_post_reboot_performed: '{{ _aim_patch_post_reboot.rebooted | default(false) | bool }}'
|
|
|
|
- name: Patching | Collect installed package facts after operation
|
|
ansible.builtin.package_facts:
|
|
manager: auto
|
|
|
|
- name: Patching | Snapshot installed package facts after operation
|
|
ansible.builtin.set_fact:
|
|
_aim_packages_after: '{{ ansible_facts.packages | default({}) }}'
|
|
|
|
- name: Patching | Compare package database snapshots
|
|
ansible.builtin.set_fact:
|
|
_aim_patch_report: >-
|
|
{{ _aim_packages_before |
|
|
aim_report_patch_linux(
|
|
_aim_packages_after,
|
|
'debian',
|
|
ansible_check_mode,
|
|
not _aim_patch_action_failed,
|
|
os_patching_reboot_required.stat.exists | default(none),
|
|
(_aim_patch_pre_reboot_performed | bool) or (_aim_patch_post_reboot_performed | bool),
|
|
_aim_patch_preexisting_reboot_required | bool,
|
|
os_patching_reboot | bool,
|
|
os_patching_reboot_delay_minutes | int
|
|
) }}
|
|
|
|
- name: Patching | Package change summary
|
|
ansible.builtin.debug:
|
|
msg: '{{ _aim_patch_report }}'
|
|
|
|
- name: AIM | Publish operation result
|
|
ansible.builtin.set_stats:
|
|
per_host: true
|
|
aggregate: false
|
|
data:
|
|
aim_output:
|
|
protocol: aim_output_v1
|
|
schema: patch_summary_v1
|
|
data: '{{ _aim_patch_report }}'
|
|
|
|
- name: Patching | Preserve native operation failure
|
|
ansible.builtin.fail:
|
|
msg: >-
|
|
The native Debian patch operation failed. Available observed package changes and reboot state
|
|
are in the structured result. If a reboot is reported as required, reboot before retrying.
|
|
when: _aim_patch_action_failed | bool
|