Infrastructure/ansible/playbooks/update.yml

34 lines
1.4 KiB
YAML

# Upgrade all apt packages and reboot only if the upgrade asks for it.
# Don't run against the OctoPrint Pi while a print is running — a reboot kills it.
# OctoPrint itself lives in its own Python venv and is updated from its web UI, not apt.
- name: Update Debian-based hosts
hosts: octoprint
become: true
tasks:
- name: Upgrade all packages
ansible.builtin.apt:
update_cache: true
upgrade: dist
autoremove: true
# Raspberry Pi OS doesn't create /var/run/reboot-required after kernel updates,
# so compare the running kernel (from facts, gathered before the upgrade) with the
# newest installed kernel of the same flavour (e.g. rpi-v8).
- name: Find the newest installed kernel of the running flavour
ansible.builtin.shell: |
set -o pipefail
ls /lib/modules | grep -- '-{{ ansible_facts['kernel'] | regex_replace("^[^-]*-", "") }}$' | sort -V | tail -n 1
args:
executable: /bin/bash
register: newest_kernel
changed_when: false
check_mode: false # read-only, so safe to run in --check mode too
- name: Check whether a package asked for a reboot
ansible.builtin.stat:
path: /var/run/reboot-required
register: reboot_flag
- name: Reboot if needed
ansible.builtin.reboot:
when: reboot_flag.stat.exists or newest_kernel.stdout != ansible_facts['kernel']