Skip to content
Geek and I
Go back

Ansible v2.0 vs Windows Update

Updated:
Mike Horwath2 min read

OMG it is working.

Ansible was recently updated to version 2.0 and while most of the changes make life better (and some worse!) the issue of the Windows modules was #1 on my list that needed addressing.

So, here is the result of my excitement after a bit of trial and error - the ability to run, from remote, against a set of hosts, Microsoft Windows Updates, and if needed, reboot the server.

The play is quite straightforward.

---
- hosts: all
tasks:
- name: install (all) updates
win_updates:
category_names:
- Application
- Connectors
- DefinitionUpdates
- DeveloperKits
- FeaturePacks
- Guidance
- ServicePacks
- Tools
- UpdateRollups
- CriticalUpdates
- SecurityUpdates
register: check_finish
- name: check on reboot requirement
raw: shutdown.exe /r /t 10 /d p:2:3
when: check_finish.reboot_required != false

So, we have a task that calls win_updates and updates all the categories in the list (which is everything according to the documentation so far) and at the end we register a variable with the resulting output.

TL:DR; the registered variable check_finish is a JSON datatype returned at the end of the win_updates step. We use these results to look for a variable named reboot_required; set to either true or false and if not false start a reboot using a 10 second delay and log the reboot as a planned reboot for system upgrades.

My command line:

ansible-playbook -l windows-servers-fusion run-updates-all.yml

Below is JSON output from the Ansible run if you wish to continue.

Successful run without any changes or updates applied, no reboot required:

ok: [192.168.242.135] => {"changed": false, "found_update_count": 0, "installed_update_count": 0, "invocation": {"module_name": "win_updates"}, "reboot_required": false, "updates": {}}
ok: [192.168.242.137] => {"changed": false, "found_update_count": 0, "installed_update_count": 0, "invocation": {"module_name": "win_updates"}, "reboot_required": false, "updates": {}}
ok: [192.168.242.136] => {"changed": false, "found_update_count": 0, "installed_update_count": 0, "invocation": {"module_name": "win_updates"}, "reboot_required": false, "updates": {}}

Notice the JSON field reboot_required as it is false - updates were not installed and no reboot required.

Next, the JSON output from a run where many installed updates completed and the reboot_required field is true. The systems automatically rebooted when completed.

changed: [192.168.242.137] => {"changed": true, "failed_update_count": 0, "found_update_count": 65, "installed_update_count": 65, "invocation": {"module_name": "win_updates"}, "reboot_required": true, "updates": {"...(65 updates)..."}}
changed: [192.168.242.135] => {"changed": true, "failed_update_count": 0, "found_update_count": 66, "installed_update_count": 66, "invocation": {"module_name": "win_updates"}, "reboot_required": true, "updates": {"...(66 updates)..."}}
changed: [192.168.242.136] => {"changed": true, "failed_update_count": 0, "found_update_count": 66, "installed_update_count": 66, "invocation": {"module_name": "win_updates"}, "reboot_required": true, "updates": {"...(66 updates)..."}}

Someday I’ll finish up some items for public Github release. I promise.



Related Posts

Previous Post
Ansible reboot Debian/Ubuntu systems in sequence (update 08/18/2018)
Next Post
Configure Syslog for VMware ESXi via vMA