88 lines
3.5 KiB
YAML
88 lines
3.5 KiB
YAML
---
|
|
- name: Patching | Initialize single Windows update result
|
|
ansible.builtin.set_fact:
|
|
_aim_windows_single_result: {}
|
|
_aim_windows_single_task_failed: false
|
|
|
|
- name: Patching | Install one Windows update
|
|
block:
|
|
- name: 'Patching | Install {{ _aim_windows_update.title }}'
|
|
ansible.windows.win_updates:
|
|
category_names: '{{ os_patching_windows_categories }}'
|
|
state: installed
|
|
reboot: false
|
|
accept_list:
|
|
- '{{ _aim_windows_update.selector }}'
|
|
register: _aim_windows_single_result
|
|
rescue:
|
|
- name: Patching | Retain failed single-update result
|
|
ansible.builtin.set_fact:
|
|
_aim_windows_single_result: '{{ ansible_failed_result | default({}) }}'
|
|
_aim_windows_single_task_failed: true
|
|
|
|
- name: Patching | Append single-update evidence
|
|
ansible.builtin.set_fact:
|
|
_aim_windows_update_runs: >-
|
|
{{ _aim_windows_update_runs + [
|
|
{
|
|
'requested': _aim_windows_update,
|
|
'result': _aim_windows_single_result,
|
|
'task_failed': _aim_windows_single_task_failed | bool
|
|
}
|
|
] }}
|
|
|
|
- name: Patching | Classify single-update execution state
|
|
ansible.builtin.set_fact:
|
|
_aim_windows_single_failed: >-
|
|
{{ (_aim_windows_single_task_failed | bool) or
|
|
(_aim_windows_single_result | aim_windows_update_result_failed) }}
|
|
_aim_patch_reboot_required_after: '{{ _aim_windows_single_result.reboot_required | default(false) | bool }}'
|
|
|
|
- name: Patching | Stop this patch wave after an update failure
|
|
ansible.builtin.set_fact:
|
|
_aim_patch_action_failed: true
|
|
_aim_patch_cycle_stop: true
|
|
_aim_patch_done: true
|
|
_aim_patch_continuation_required: true
|
|
_aim_patch_remaining_updates_known: false
|
|
_aim_patch_blocked_reason: '{{ _aim_windows_single_result | aim_windows_update_block_reason }}'
|
|
when: _aim_windows_single_failed | bool
|
|
|
|
- name: Patching | Reboot Windows at a sequential update boundary
|
|
ansible.windows.win_reboot:
|
|
msg: '{{ os_patching_reboot_message }}'
|
|
pre_reboot_delay: '{{ [2, (os_patching_reboot_delay_minutes | int) * 60] | max }}'
|
|
reboot_timeout: '{{ os_patching_reboot_timeout | int }}'
|
|
register: _aim_windows_single_reboot
|
|
when:
|
|
- not (_aim_windows_single_failed | bool)
|
|
- _aim_windows_single_result.reboot_required | default(false) | bool
|
|
- os_patching_reboot | bool
|
|
|
|
- name: Patching | Record completed sequential reboot boundary
|
|
ansible.builtin.set_fact:
|
|
_aim_patch_cycle_stop: true
|
|
_aim_patch_cycle_reboot_performed: '{{ _aim_windows_single_reboot.rebooted | default(false) | bool }}'
|
|
_aim_patch_any_reboot_performed: >-
|
|
{{ (_aim_patch_any_reboot_performed | bool) or
|
|
(_aim_windows_single_reboot.rebooted | default(false) | bool) }}
|
|
_aim_patch_reboot_required_after: >-
|
|
{{ false if (_aim_windows_single_reboot.rebooted | default(false) | bool)
|
|
else (_aim_windows_single_result.reboot_required | default(false) | bool) }}
|
|
when:
|
|
- _aim_windows_single_reboot is defined
|
|
- not (_aim_windows_single_reboot.skipped | default(false) | bool)
|
|
|
|
- name: Patching | Defer required reboot and stop the current patch wave
|
|
ansible.builtin.set_fact:
|
|
_aim_patch_cycle_stop: true
|
|
_aim_patch_done: true
|
|
_aim_patch_reboot_deferred: true
|
|
_aim_patch_reboot_required_after: true
|
|
_aim_patch_continuation_required: true
|
|
_aim_patch_remaining_updates_known: false
|
|
when:
|
|
- not (_aim_windows_single_failed | bool)
|
|
- _aim_windows_single_result.reboot_required | default(false) | bool
|
|
- not (os_patching_reboot | bool)
|