Cross platform automated patch management
-
Could probably pipe the results to Grafana and get a report from that.
-
@FATeknollogee said in Cross platform automated patch management:
What nice tools are available for cross platform patch management?
Must be able to generate monthly reports. (needed for compliance)I think Automox is something you will want to look at. They were at SW last year and I expect them to be back this year. We've got a few Automox people here in the community (most of them predate Automox and have joined them since being here.)
Like @Richard_Cylance who should probably change his name and @Nic
-
@scottalanmiller oh hai
Richard here. Prior Cylance and Webroot. Poacher of Nic from SW.
Automox is a cloud native cyber hygiene platform. You can patch, deploy software, enforce policies, and a whole lot more across Windows, Linux, and Mac including servers. You can pull a report as needed as well. Don't want to get too salesy but happy to talk more.
-
@Richard_Automox thanks for popping in.
-
Might be able to do it with Salt + Foreman. Or you do Salt + an Elastic logging stack
-
@scottalanmiller thanks for pinging us
I am indeed at Automox now. We're building a community for our user base to share tips and scripts that you can run through our agent. Once the community is out of beta I'll announce it here so you can check it out. In the meantime if you want a trial of the product to check it out, let me or Richard know and we can get you setup.
-
@marcinozga said in Cross platform automated patch management:
Ansible is the correct solution, and I guess you could save output to log file with log_plays plugin. Perhaps AWX or Tower have reporting capability, I haven't used Tower and I briefly looked and AWX.
Other configuration management solutions might do what you need too.
Tower is pricey, depending on your needs. AWX lacks "support", as it is free.
-
@Nic said in Cross platform automated patch management:
@scottalanmiller thanks for pinging us
I am indeed at Automox now. We're building a community for our user base to share tips and scripts that you can run through our agent. Once the community is out of beta I'll announce it here so you can check it out. In the meantime if you want a trial of the product to check it out, let me or Richard know and we can get you setup.
Welcome back to IT...
-
@Dashrender said in Cross platform automated patch management:
@Nic said in Cross platform automated patch management:
@scottalanmiller thanks for pinging us
I am indeed at Automox now. We're building a community for our user base to share tips and scripts that you can run through our agent. Once the community is out of beta I'll announce it here so you can check it out. In the meantime if you want a trial of the product to check it out, let me or Richard know and we can get you setup.
Welcome back to IT...
Thanks While I enjoyed the world of cannabis, it wasn't a true passion like technology.
-
@wrx7m said in Cross platform automated patch management:
@marcinozga said in Cross platform automated patch management:
Ansible is the correct solution, and I guess you could save output to log file with log_plays plugin. Perhaps AWX or Tower have reporting capability, I haven't used Tower and I briefly looked and AWX.
Other configuration management solutions might do what you need too.
Tower is pricey, depending on your needs. AWX lacks "support", as it is free.
Also, AWX is treated as a toy and has constant issues with the current release software. You can see all the issues I had when experimenting with it: https://mangolassi.it/topic/19300/install-awx-on-centos-7-with-docker
-
@travisdh1 said in Cross platform automated patch management:
@wrx7m said in Cross platform automated patch management:
@marcinozga said in Cross platform automated patch management:
Ansible is the correct solution, and I guess you could save output to log file with log_plays plugin. Perhaps AWX or Tower have reporting capability, I haven't used Tower and I briefly looked and AWX.
Other configuration management solutions might do what you need too.
Tower is pricey, depending on your needs. AWX lacks "support", as it is free.
Also, AWX is treated as a toy and has constant issues with the current release software. You can see all the issues I had when experimenting with it: https://mangolassi.it/topic/19300/install-awx-on-centos-7-with-docker
That is a complaint that I saw, as well.
-
Here's the link to the Automox community, for anyone who wants to check it out:
https://community.automox.com/Don't worry, I'm still here in MangoLassi to answer questions you have as well!
-
If you do use Ansible, I'd use Jenkins over AWX/Tower. There is a reporting tool called ARA that gives you per play and per node reports. You can also use a callback plugin to pipe to logs or other systems for reports.
-
@Nic said in Cross platform automated patch management:
Here's the link to the Automox community, for anyone who wants to check it out:
https://community.automox.com/Don't worry, I'm still here in MangoLassi to answer questions you have as well!
Are they still with their limited amount of packages or software?
-
@dbeato said in Cross platform automated patch management:
@Nic said in Cross platform automated patch management:
Here's the link to the Automox community, for anyone who wants to check it out:
https://community.automox.com/Don't worry, I'm still here in MangoLassi to answer questions you have as well!
Are they still with their limited amount of packages or software?
Yes, but we're working on it. We're in the midst of testing for rolling out a bunch more. Our goal is to get our list to over 100 third party apps by the end of the year.
-
@Nic We going to see you in a few days?
-
@scottalanmiller yep, I'll be there! Looking forward to seeing everyone!
-
So I told @fuznutz04 the other night I'd send him my Ansible role that creates KVM guests and I completely forgot. Here's a link to what I wrote: https://hooks.technology/2017/10/create-vms-on-kvm-with-ansible/
There is also a library that Larry Smith wrote. Here's a link to the PR https://github.com/ansible/ansible/pull/39340. I just copied what he wrote and put it in my libraries folder so I can use it as a custom module. This module will actually clone a template for you. Here's his example:
--- - hosts: kvm vars: vm_template: ubuntu1604-packer-template vms: - name: app01 state: started template: "{{ vm_template }}" - name: db01 state: started template: "{{ vm_template }}" - name: lb01 state: started template: "{{ vm_template }}" - name: web01 state: started template: "{{ vm_template }}" tasks: - name: Cloning VMs virt_clone: name: "{{ item['name'] }}" state: "{{ item['state'] }}" template: "{{ item['template'] }}" uuid: "{{ item['uuid']|default(omit) }}" become: true loop: "{{ vms }}"
Sorry it took so long to get this out there.
-
This is the provider I use to clone KVM guests with Terraform https://github.com/dmacvicar/terraform-provider-libvirt