# Upgrade all apt packages and reboot only if the upgrade asks for it. # Don't run against the OctoPrint Pi while a print is running — a reboot kills it. # OctoPrint itself lives in its own Python venv and is updated from its web UI, not apt. - name: Update Debian-based hosts hosts: octoprint become: true tasks: - name: Upgrade all packages ansible.builtin.apt: update_cache: true upgrade: dist autoremove: true # Raspberry Pi OS doesn't create /var/run/reboot-required after kernel updates, # so compare the running kernel (from facts, gathered before the upgrade) with the # newest installed kernel of the same flavour (e.g. rpi-v8). - name: Find the newest installed kernel of the running flavour ansible.builtin.shell: | set -o pipefail ls /lib/modules | grep -- '-{{ ansible_facts['kernel'] | regex_replace("^[^-]*-", "") }}$' | sort -V | tail -n 1 args: executable: /bin/bash register: newest_kernel changed_when: false check_mode: false # read-only, so safe to run in --check mode too - name: Check whether a package asked for a reboot ansible.builtin.stat: path: /var/run/reboot-required register: reboot_flag - name: Reboot if needed ansible.builtin.reboot: when: reboot_flag.stat.exists or newest_kernel.stdout != ansible_facts['kernel']