OMG it is working.
Ansible was recently updated to version 2.0 and while most of the changes make life better (and some worse!) the issue of the Windows modules was #1 on my list that needed addressing.
So, here is the result of my excitement after a bit of trial and error - the ability to run, from remote, against a set of hosts, Microsoft Windows Updates, and if needed, reboot the server.
The play is quite straightforward.
---
- hosts: all tasks: - name: install (all) updates win_updates: category_names: - Application - Connectors - DefinitionUpdates - DeveloperKits - FeaturePacks - Guidance - ServicePacks - Tools - UpdateRollups - CriticalUpdates - SecurityUpdates register: check_finish
- name: check on reboot requirement raw: shutdown.exe /r /t 10 /d p:2:3 when: check_finish.reboot_required != falseSo, we have a task that calls win_updates and updates all the categories in the list (which is everything according to the documentation so far) and at the end we register a variable with the resulting output.
TL:DR; the registered variable check_finish is a JSON datatype returned at the end of the win_updates step. We use these results to look for a variable named reboot_required; set to either true or false and if not false start a reboot using a 10 second delay and log the reboot as a planned reboot for system upgrades.
My command line:
ansible-playbook -l windows-servers-fusion run-updates-all.yml
Below is JSON output from the Ansible run if you wish to continue.
Successful run without any changes or updates applied, no reboot required:
ok: [192.168.242.135] => {"changed": false, "found_update_count": 0, "installed_update_count": 0, "invocation": {"module_name": "win_updates"}, "reboot_required": false, "updates": {}}ok: [192.168.242.137] => {"changed": false, "found_update_count": 0, "installed_update_count": 0, "invocation": {"module_name": "win_updates"}, "reboot_required": false, "updates": {}}ok: [192.168.242.136] => {"changed": false, "found_update_count": 0, "installed_update_count": 0, "invocation": {"module_name": "win_updates"}, "reboot_required": false, "updates": {}}Notice the JSON field reboot_required as it is false - updates were not installed and no reboot required.
Next, the JSON output from a run where many installed updates completed and the reboot_required field is true. The systems automatically rebooted when completed.
changed: [192.168.242.137] => {"changed": true, "failed_update_count": 0, "found_update_count": 65, "installed_update_count": 65, "invocation": {"module_name": "win_updates"}, "reboot_required": true, "updates": {"...(65 updates)..."}}changed: [192.168.242.135] => {"changed": true, "failed_update_count": 0, "found_update_count": 66, "installed_update_count": 66, "invocation": {"module_name": "win_updates"}, "reboot_required": true, "updates": {"...(66 updates)..."}}changed: [192.168.242.136] => {"changed": true, "failed_update_count": 0, "found_update_count": 66, "installed_update_count": 66, "invocation": {"module_name": "win_updates"}, "reboot_required": true, "updates": {"...(66 updates)..."}}Someday I’ll finish up some items for public Github release. I promise.