1 hour ago · 23 min read4584 words · Tech · hide · 0 comments

There is a special kind of embarrassment in being the person who explains Ansible to other people during the week and then spends Sunday evening typing freebsd-update fetch install into a dozen SSH sessions. My RHEL machines were fine. They have been patched from Satellite through Ansible for a long time. Everything else was not: FreeBSD routers, jail hosts with Bastille and with classic jail.conf jails, a mail server, a Proxmox cluster, a Proxmox Backup Server. Each one had its own little ritual, and the rituals lived in my head and in my shell history. This article is about replacing those rituals with playbooks. Not with one clever generic “update everything” task, but with patching logic that knows the difference between freebsd-update and pkgbase, between a thin and a thick jail, between a router that may reboot and a hypervisor that must not. All host names and addresses in this article are placeholders (example.com, RFC 5737 and RFC 3849 documentation ranges). The structure and…

No comments yet. Log in to reply on the Fediverse. Comments will appear here.