All Products
Search
Document Center

CloudOps Orchestration Service:Patch baseline

Last Updated:Sep 04, 2026

The patch management service provides a predefined default patch baseline for each supported operating system. To create custom rules to scan for and install patches for a specific operating system, you can use patch baselines to specify the operating system type, patch types, severity levels, and auto-approval conditions. After you create a custom baseline, you can set it as the new default for that operating system to apply these custom rules.

Create a patch baseline

  1. Log on to the CloudOps Orchestration Service console. In the left-side navigation pane, choose Server Management > Patch Management.

  2. Click Configure Patch Baseline. On the Patch Baseline page, click Create.

  3. Enter a name and description for the baseline.image

  4. Select the target operating system.image

  5. Define patch rules, including the patch type, severity, and approval conditions.image

    The default patch baseline ACS-Windows-DefaultPatchBaseline for Windows instances includes only the Security Updates and Critical Updates patch types. To scan for and install other patch types, such as Definition Updates and Update Rollups, create a custom patch baseline, set its patch type to all, and then call RegisterDefaultPatchBaseline to register the custom baseline as the default baseline.

  6. (Optional) If the defined rules cannot handle certain patches for specific reasons, you can configure patch exceptions to explicitly approve or reject them.

    Configure patch exception rules

    • Alibaba Cloud Linux and CentOS

      • Package manager: YUM (Dandified YUM (DNF) is used for Amazon Linux 2022 and 2023, Red Hat Enterprise Linux (RHEL) 8, and CentOS 8).

      • Approved patches:

        • CVE ID: For example, CVE-2025-0395.

        • Security notice ID: For example, RHSA-2025:14177 or ALINUX3-SA-2025:0138.

        • Package name: For example, glibc-utils-2.32-1.21.al8.x86_64 can be entered as:

          • glibc-utils-2.32-1.21

          • glibc-utils-2.32-1.21.al8

          • glibc-utils-2.32-1.21.al8.x86_64

        • Wildcard characters are supported, such as glibc-utils* and glibc-utils-2.32-1.21.al8*.

      • Rejected patches:

        • The format is the same as for approved patches.

    • Ubuntu and Debian

      • Package manager: APT.

      • Patch format: Specify only the package name. For example, XXXPkg123.

    • Windows

      • Patch format: Use the Microsoft Knowledge Base (KB) ID or security bulletin ID. For example, KB2032276, KB2124261, or MS10-048.

  7. Click Create.

Related operations

  • Set the default patch baseline: In the list of patch baselines, find the baseline that you want to set as the default, click Set as Default Baseline in the Actions column, and then click Confirm.

    Important

    The default patch baseline serves as the reference for patch scanning. Therefore, choose the default baseline with caution.

  • View patch baseline details: In the list of patch baselines, find the target baseline and click Details in the Actions column.

  • Update a patch baseline: In the list of patch baselines, find the target baseline and click Update in the Actions column.

  • Delete a patch baseline: In the list of patch baselines, find the target baseline, click the image icon in the Actions column, click Delete, and then click Confirm.

    Important

    Before you delete a patch baseline, make sure that no instances are using it. This prevents disruptions to patch scanning.