Skip to content

Commit 6649859

Browse files
committed
refactor ssh update from sig/security to work on existing fatimage
1 parent bce768c commit 6649859

File tree

1 file changed

+14
-8
lines changed

1 file changed

+14
-8
lines changed

ansible/bootstrap.yml

Lines changed: 14 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -157,6 +157,20 @@
157157
tags:
158158
- update
159159
tasks:
160+
- name: Install SIG/security release repo
161+
dnf:
162+
name: rocky-release-security
163+
- name: Update openssh
164+
dnf:
165+
name:
166+
- openssh
167+
- openssh-askpass
168+
- openssh-clients
169+
- openssh-server
170+
state: latest
171+
update_only: true
172+
enablerepo:
173+
- security-common
160174
- block:
161175
- name: Update selected packages
162176
yum:
@@ -167,14 +181,6 @@
167181
async: "{{ 30 * 60 }}" # wait for up to 30 minutes
168182
poll: 15 # check every 15 seconds
169183
register: updates
170-
- name: Install SIG/security release repo
171-
dnf:
172-
name: rocky-release-security
173-
- name: Upgrade openssh
174-
dnf:
175-
name: openssh*
176-
enablerepo:
177-
- security-common
178184
- name: Ensure update log directory on localhost exists
179185
file:
180186
path: "{{ update_log_path | dirname }}"

0 commit comments

Comments
 (0)