--- # Template, not run on any schedule. Copy this when a package needs a # controlled bump outside update-packages.yml — e.g. a security fix you # want before the next scheduled run, or a version you deliberately don't # want update-packages.yml's `safe` upgrade to move past. # # Run explicitly against the hosts that need it: # venv/bin/ansible-playbook update-packages-pinned-example.yml --limit - name: Pin a package to an exact version hosts: all tasks: - name: Install nginx pinned to a specific version ansible.builtin.apt: name: "nginx=1.18.0-6.1+deb11u3" state: present update_cache: true # Pinning like this also protects the package from update-packages.yml's # `safe`/`dist` upgrade: apt won't move a pinned-by-version install # past the given version on a plain upgrade. - name: Bump a single named package to latest, deliberately hosts: all tasks: - name: Upgrade openssl to latest available ansible.builtin.apt: name: openssl state: latest # noqa: package-latest - deliberate, scoped to one named package, run ad hoc update_cache: true