Files
Ansible/roles/maintenance_patch_os/tasks/linux_debian.yml
T
2026-09-22 19:23:17 +02:00

145 lines
5.2 KiB
YAML

- name: Patching | Initialize Debian report state
ansible.builtin.set_fact:
_aim_patch_action_failed: false
_aim_patch_pre_reboot_performed: false
_aim_patch_post_reboot_performed: false
- name: Patching | Detect pending Debian reboot before patching
become: true
ansible.builtin.stat:
path: /var/run/reboot-required
register: _aim_patch_pre_reboot_probe
- name: Patching | Record pre-existing Debian reboot state
ansible.builtin.set_fact:
_aim_patch_preexisting_reboot_required: '{{ _aim_patch_pre_reboot_probe.stat.exists | default(false) | bool }}'
- name: Patching | Publish blocked Debian result when reboot is deferred
when:
- _aim_patch_preexisting_reboot_required | bool
- not (os_patching_reboot | bool)
block:
- name: Patching | Build blocked Debian patch report
ansible.builtin.set_fact:
_aim_patch_report: >-
{{ 'debian' | aim_report_patch_blocked(ansible_check_mode,
os_patching_reboot_delay_minutes | int) }}
- name: AIM | Publish blocked operation result
ansible.builtin.set_stats:
per_host: true
aggregate: false
data:
aim_output:
protocol: aim_output_v1
schema: patch_summary_v1
data: '{{ _aim_patch_report }}'
- name: Patching | Require reboot before continuing Debian patching
ansible.builtin.fail:
msg: >-
A reboot is already pending from a previous update or installation. Reboot the host first,
or rerun with "Reboot when required" enabled. No new package upgrade was started by this run.
- name: Patching | Clear pre-existing Debian reboot before patching
become: true
ansible.builtin.reboot:
msg: '{{ os_patching_reboot_message }}'
pre_reboot_delay: '{{ (os_patching_reboot_delay_minutes | int) * 60 }}'
reboot_timeout: '{{ os_patching_reboot_timeout | int }}'
register: _aim_patch_pre_reboot
when:
- _aim_patch_preexisting_reboot_required | bool
- os_patching_reboot | bool
- not ansible_check_mode
- name: Patching | Record pre-patch Debian reboot
ansible.builtin.set_fact:
_aim_patch_pre_reboot_performed: '{{ _aim_patch_pre_reboot.rebooted | default(false) | bool }}'
- name: Patching | Collect installed package facts before operation
ansible.builtin.package_facts:
manager: auto
- name: Patching | Snapshot installed package facts before operation
ansible.builtin.set_fact:
_aim_packages_before: '{{ ansible_facts.packages | default({}) }}'
- name: Patching | Apply native Debian updates
block:
- name: Update Debian-based host
become: true
ansible.builtin.apt:
upgrade: safe
update_cache: true
cache_valid_time: 3600
autoremove: true
- name: Check if Debian-based host requires reboot
become: true
ansible.builtin.stat:
path: /var/run/reboot-required
register: os_patching_reboot_required
rescue:
- name: Patching | Retain failed action for reporting
ansible.builtin.set_fact:
_aim_patch_action_failed: true
- name: Patching | Reboot Debian host after updates when required
become: true
ansible.builtin.reboot:
msg: '{{ os_patching_reboot_message }}'
pre_reboot_delay: '{{ (os_patching_reboot_delay_minutes | int) * 60 }}'
reboot_timeout: '{{ os_patching_reboot_timeout | int }}'
register: _aim_patch_post_reboot
when:
- os_patching_reboot | bool
- not ansible_check_mode
- os_patching_reboot_required.stat.exists | default(false) | bool
- name: Patching | Record post-update Debian reboot
ansible.builtin.set_fact:
_aim_patch_post_reboot_performed: '{{ _aim_patch_post_reboot.rebooted | default(false) | bool }}'
- name: Patching | Collect installed package facts after operation
ansible.builtin.package_facts:
manager: auto
- name: Patching | Snapshot installed package facts after operation
ansible.builtin.set_fact:
_aim_packages_after: '{{ ansible_facts.packages | default({}) }}'
- name: Patching | Compare package database snapshots
ansible.builtin.set_fact:
_aim_patch_report: >-
{{ _aim_packages_before |
aim_report_patch_linux(
_aim_packages_after,
'debian',
ansible_check_mode,
not _aim_patch_action_failed,
os_patching_reboot_required.stat.exists | default(none),
(_aim_patch_pre_reboot_performed | bool) or (_aim_patch_post_reboot_performed | bool),
_aim_patch_preexisting_reboot_required | bool,
os_patching_reboot | bool,
os_patching_reboot_delay_minutes | int
) }}
- name: Patching | Package change summary
ansible.builtin.debug:
msg: '{{ _aim_patch_report }}'
- name: AIM | Publish operation result
ansible.builtin.set_stats:
per_host: true
aggregate: false
data:
aim_output:
protocol: aim_output_v1
schema: patch_summary_v1
data: '{{ _aim_patch_report }}'
- name: Patching | Preserve native operation failure
ansible.builtin.fail:
msg: >-
The native Debian patch operation failed. Available observed package changes and reboot state
are in the structured result. If a reboot is reported as required, reboot before retrying.
when: _aim_patch_action_failed | bool