Add deliberate update playbook and unattended-upgrades role
Regular playbooks now use state: present, so they no longer upgrade packages as a side effect. This adds two separate, explicit mechanisms to keep the fleet patched instead: - update-packages.yml: ad hoc / to-be-scheduled fleet-wide upgrade (safe by default, dist available via -e), plus update-packages-pinned-example.yml as a template for pinning or bumping a single package outside that. - roles/unattended_upgrades: automatic security-only patching via unattended-upgrades, with a scheduled reboot window and mail left disabled pending a configured MTA. Applied to every host in full.yml and server.yml. Also removes a leftover `upgrade: yes` apt task from pi_standard_setup and server_basic_environment that was still doing a full upgrade on every routine run, defeating the point of the state: present switch. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
4
full.yml
4
full.yml
@@ -11,6 +11,7 @@
|
||||
- name: Musikserver Wohnzimmer oben
|
||||
hosts: musikserverwohnzimmeroben
|
||||
roles:
|
||||
- unattended_upgrades
|
||||
- pi_standard_setup
|
||||
- pi_hifiberry_amp
|
||||
- pi_squeezelite_custom
|
||||
@@ -22,6 +23,7 @@
|
||||
- name: Kitchen pi
|
||||
hosts: kitchenpi
|
||||
roles:
|
||||
- unattended_upgrades
|
||||
- pi_standard_setup
|
||||
- pi_hifiberry_amp
|
||||
- pi_squeezelite_custom
|
||||
@@ -34,6 +36,7 @@
|
||||
- name: Bedroom pi
|
||||
hosts: bedroompi
|
||||
roles:
|
||||
- unattended_upgrades
|
||||
- pi_standard_setup
|
||||
- pi_squeezelite_custom
|
||||
- pi_shairport
|
||||
@@ -45,6 +48,7 @@
|
||||
- name: Musicmouse
|
||||
hosts: musicmouse
|
||||
roles:
|
||||
- unattended_upgrades
|
||||
- pi_standard_setup
|
||||
- pi_hifiberry_amp
|
||||
- pi_musicmouse
|
||||
|
||||
Reference in New Issue
Block a user