Regular playbooks now use state: present, so they no longer upgrade packages as a side effect. This adds two separate, explicit mechanisms to keep the fleet patched instead: - update-packages.yml: ad hoc / to-be-scheduled fleet-wide upgrade (safe by default, dist available via -e), plus update-packages-pinned-example.yml as a template for pinning or bumping a single package outside that. - roles/unattended_upgrades: automatic security-only patching via unattended-upgrades, with a scheduled reboot window and mail left disabled pending a configured MTA. Applied to every host in full.yml and server.yml. Also removes a leftover `upgrade: yes` apt task from pi_standard_setup and server_basic_environment that was still doing a full upgrade on every routine run, defeating the point of the state: present switch. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
23 lines
527 B
YAML
23 lines
527 B
YAML
---
|
|
- name: Refresh apt cache
|
|
ansible.builtin.apt:
|
|
update_cache: "yes"
|
|
cache_valid_time: "300"
|
|
- name: Apt install download & unzip packages
|
|
ansible.builtin.apt:
|
|
name:
|
|
- wget
|
|
- zip
|
|
- htop
|
|
- xz-utils
|
|
- python3
|
|
- python3-venv
|
|
- python3-wheel
|
|
- git
|
|
- iotop
|
|
- name: Download and install mbenv
|
|
ansible.builtin.unarchive:
|
|
src: "https://owncloud.bauer.tech/s/vMu7X4mRl2vComu/download?path=%2F&files=mbenv.tar.xz"
|
|
remote_src: true
|
|
dest: "/home/core/"
|