115 lines
4.7 KiB
YAML
115 lines
4.7 KiB
YAML
---
|
|
- name: Patching | Start Windows patch cycle
|
|
ansible.builtin.set_fact:
|
|
_aim_patch_cycles: '{{ _aim_patch_cycle_number | int }}'
|
|
_aim_patch_cycle_stop: false
|
|
_aim_patch_cycle_reboot_performed: false
|
|
|
|
- name: Patching | Search available Windows updates for this wave
|
|
ansible.windows.win_updates:
|
|
category_names: '{{ os_patching_windows_categories }}'
|
|
state: searched
|
|
reboot: false
|
|
register: _aim_windows_cycle_search
|
|
|
|
- name: Patching | Record Windows update discovery
|
|
ansible.builtin.set_fact:
|
|
_aim_windows_searches: '{{ _aim_windows_searches + [_aim_windows_cycle_search] }}'
|
|
_aim_windows_update_queue: '{{ _aim_windows_cycle_search | aim_windows_update_queue }}'
|
|
|
|
- name: Patching | Reboot when discovery itself reports a required reboot
|
|
ansible.windows.win_reboot:
|
|
msg: '{{ os_patching_reboot_message }}'
|
|
pre_reboot_delay: '{{ [2, (os_patching_reboot_delay_minutes | int) * 60] | max }}'
|
|
reboot_timeout: '{{ os_patching_reboot_timeout | int }}'
|
|
register: _aim_windows_search_reboot
|
|
when:
|
|
- _aim_windows_cycle_search.reboot_required | default(false) | bool
|
|
- os_patching_reboot | bool
|
|
|
|
- name: Patching | Record discovery-time reboot boundary
|
|
ansible.builtin.set_fact:
|
|
_aim_patch_cycle_stop: true
|
|
_aim_patch_cycle_reboot_performed: '{{ _aim_windows_search_reboot.rebooted | default(false) | bool }}'
|
|
_aim_patch_any_reboot_performed: >-
|
|
{{ (_aim_patch_any_reboot_performed | bool) or
|
|
(_aim_windows_search_reboot.rebooted | default(false) | bool) }}
|
|
_aim_patch_reboot_required_after: >-
|
|
{{ false if (_aim_windows_search_reboot.rebooted | default(false) | bool) else true }}
|
|
when:
|
|
- _aim_windows_search_reboot is defined
|
|
- not (_aim_windows_search_reboot.skipped | default(false) | bool)
|
|
|
|
- name: Patching | Defer discovery-time required reboot
|
|
ansible.builtin.set_fact:
|
|
_aim_patch_cycle_stop: true
|
|
_aim_patch_done: true
|
|
_aim_patch_reboot_deferred: true
|
|
_aim_patch_reboot_required_after: true
|
|
_aim_patch_continuation_required: true
|
|
_aim_patch_remaining_updates_known: true
|
|
when:
|
|
- _aim_windows_cycle_search.reboot_required | default(false) | bool
|
|
- not (os_patching_reboot | bool)
|
|
|
|
- name: Patching | Finish when no updates are available
|
|
ansible.builtin.set_fact:
|
|
_aim_patch_done: true
|
|
_aim_patch_remaining_updates_known: true
|
|
_aim_patch_continuation_required: '{{ _aim_windows_cycle_search.reboot_required | default(false) | bool }}'
|
|
_aim_patch_reboot_required_after: '{{ _aim_windows_cycle_search.reboot_required | default(false) | bool }}'
|
|
when:
|
|
- (_aim_windows_update_queue | length) == 0
|
|
- not (_aim_patch_cycle_stop | bool)
|
|
|
|
- name: Patching | Install discovered Windows updates sequentially
|
|
ansible.builtin.include_tasks: windows_update_one.yml
|
|
loop: '{{ _aim_windows_update_queue }}'
|
|
loop_control:
|
|
loop_var: _aim_windows_update
|
|
label: '{{ _aim_windows_update.title }}'
|
|
when:
|
|
- not (_aim_patch_done | bool)
|
|
- not (_aim_patch_cycle_stop | bool)
|
|
|
|
- name: Patching | Final read-only discovery after completed non-reboot wave
|
|
ansible.windows.win_updates:
|
|
category_names: '{{ os_patching_windows_categories }}'
|
|
state: searched
|
|
reboot: false
|
|
register: _aim_windows_cycle_final_search
|
|
when:
|
|
- not (_aim_patch_done | bool)
|
|
- not (_aim_patch_cycle_stop | bool)
|
|
- not (_aim_patch_action_failed | bool)
|
|
|
|
- name: Patching | Record final non-reboot wave state
|
|
ansible.builtin.set_fact:
|
|
_aim_windows_searches: '{{ _aim_windows_searches + [_aim_windows_cycle_final_search] }}'
|
|
_aim_patch_remaining_updates_known: true
|
|
_aim_patch_continuation_required: '{{ (_aim_windows_cycle_final_search.found_update_count | default(0) | int) > 0 }}'
|
|
_aim_patch_reboot_required_after: '{{ _aim_windows_cycle_final_search.reboot_required | default(false) | bool }}'
|
|
_aim_patch_done: true
|
|
when:
|
|
- _aim_windows_cycle_final_search is defined
|
|
- not (_aim_windows_cycle_final_search.skipped | default(false) | bool)
|
|
|
|
- name: Patching | Stop after operator-approved reboot boundary by default
|
|
ansible.builtin.set_fact:
|
|
_aim_patch_done: true
|
|
_aim_patch_continuation_required: true
|
|
_aim_patch_remaining_updates_known: false
|
|
when:
|
|
- _aim_patch_cycle_reboot_performed | bool
|
|
- not (os_patching_rescan_after_reboot | bool)
|
|
|
|
- name: Patching | Continue only when post-reboot rescan was explicitly enabled
|
|
ansible.builtin.debug:
|
|
msg: >-
|
|
AIM completed a reboot boundary and will start another Windows patch cycle because
|
|
os_patching_rescan_after_reboot is explicitly enabled.
|
|
when:
|
|
- _aim_patch_cycle_reboot_performed | bool
|
|
- os_patching_rescan_after_reboot | bool
|
|
- not (_aim_patch_action_failed | bool)
|