Nom du modèle
ACS-ECS-ScheduleApplyPatchBaseline : planifie l'application d'une ligne de base de correctifs sur des instances ECS spécifiées.
description du modèle
Configure une ligne de base de correctifs pour les instances Elastic Compute Service (ECS) selon un planning défini.
type de modèle
Automatisé
Propriétaire
Alibaba Cloud
Paramètres d'entrée
|
Paramètre |
Description |
Type |
Obligatoire |
Valeur par défaut |
Limite |
|
targets |
Instance cible |
Json |
Oui |
||
|
timerTrigger |
Type de tâche planifiée. |
Json |
Oui |
||
|
regionId |
ID de la région. |
String |
Non |
{{ ACS::RegionId }} |
|
|
resourceType |
Type de ressource. |
String |
Non |
ALIYUN::ECS::Instance |
|
|
action |
Mode d'exécution. |
String |
Non |
install |
|
|
whetherCreateSnapshot |
Indique s'il faut créer un snapshot pour le disque système. |
Boolean |
Non |
False |
|
|
retentionDays |
Durée de rétention du snapshot. |
Number |
Non |
7 |
|
|
rebootIfNeed |
Indique s'il faut redémarrer l'instance. |
Boolean |
Non |
False |
|
|
timeout |
Délai d'expiration pour l'exécution des commandes sur les instances ECS. |
Number |
Non |
7200 |
|
|
rateControl |
Concurrence d'exécution des tâches |
Json |
Non |
{'Mode': 'Concurrency', 'MaxErrors': 0, 'Concurrency': 10} |
|
|
OOSAssumeRole |
Rôle RAM assumé par CloudOps Orchestration Service (OOS). |
String |
Non |
"" |
Paramètres de sortie
|
Paramètre |
Description |
Type |
|
commandOutputs |
List |
Politique d'autorisation requise pour exécuter le modèle
{
"Version": "1",
"Statement": [
{
"Action": [
"ecs:CreateSnapshot",
"ecs:DescribeCloudAssistantStatus",
"ecs:DescribeDisks",
"ecs:DescribeInstances",
"ecs:DescribeInvocationResults",
"ecs:DescribeInvocations",
"ecs:DescribeManagedInstances",
"ecs:DescribeSnapshots",
"ecs:InvokeCommand",
"ecs:RebootInstance",
"ecs:RunCommand"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"ecd:CreateSnapshot",
"ecd:DescribeCloudAssistantStatus",
"ecd:DescribeDesktops",
"ecd:DescribeInvocations",
"ecd:DescribeSnapshots",
"ecd:RebootDesktops",
"ecd:RunCommand"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"oos:GetApplicationGroup",
"oos:ListInstancePatchStates"
],
"Resource": "*",
"Effect": "Allow"
}
]
}
Détails
Pour plus d'informations, consultez le fichier ACS-ECS-ScheduleApplyPatchBaseline.yml sur GitHub.
Contenu du modèle
FormatVersion: OOS-2019-06-01
Description:
name-en: ACS-ECS-ScheduleApplyPatchBaseline
name-zh-cn: Schedules applying a patch baseline on specified ECS instances
en: Schedules applying a patch baseline on specified ECS instances.
zh-cn: Schedules applying a patch baseline on ECS instances.
Parameters:
regionId:
Label:
en: Region ID
zh-cn: Region ID
Type: String
AssociationProperty: RegionId
Default: '{{ ACS::RegionId }}'
resourceType:
Type: String
Label:
en: Resource type
zh-cn: Resource type
AssociationPropertyMetadata:
LocaleKey: TargetResourceType
AllowedValues:
- ALIYUN::ECS::Instance
- ALIYUN::ECS::ManagedInstance
- ALIYUN::ECD::Desktop
Default: ALIYUN::ECS::Instance
targets:
Type: Json
Label:
en: Target instance
zh-cn: Target instance
AssociationProperty: Targets
AssociationPropertyMetadata:
ResourceType: resourceType
RegionId: regionId
Status: Running
timerTrigger:
Type: Json
Label:
en: Timer trigger
zh-cn: Timer trigger
AssociationProperty: ALIYUN::OOS::Component::TimerTrigger
AssociationPropertyMetadata:
MinuteInterval: 30
action:
Label:
en: Execution mode
zh-cn: Execution mode
Type: String
AllowedValues:
- install
- scan
Default: install
AssociationPropertyMetadata:
LocaleKey: OOSPatchExecuteType
whetherCreateSnapshot:
Label:
en: Whether to create a snapshot for the system disk
zh-cn: Whether to create a snapshot for the system disk
Type: Boolean
Default: false
AssociationPropertyMetadata:
Visible:
Condition:
'Fn::Equals':
- '${action}'
- install
retentionDays:
Label:
en: Snapshot retention period in days
zh-cn: Snapshot retention period in days
Type: Number
MinValue: 1
MaxValue: 65536
Default: 7
AssociationPropertyMetadata:
Visible:
Condition:
'Fn::Equals':
- '${whetherCreateSnapshot}'
- true
rebootIfNeed:
Label:
en: Whether to restart
zh-cn: Whether to restart
Type: Boolean
Default: false
AssociationPropertyMetadata:
Visible:
Condition:
'Fn::Equals':
- '${action}'
- install
timeout:
Label:
en: The timeout period for running commands on ECS instances
zh-cn: The timeout period for running commands on ECS instances
Type: Number
Default: 7200
rateControl:
Label:
en: The concurrency rate for task execution
zh-cn: The concurrency rate for task execution
Type: Json
AssociationProperty: RateControl
Default:
Mode: Concurrency
MaxErrors: 0
Concurrency: 10
OOSAssumeRole:
Label:
en: The RAM role that OOS assumes
zh-cn: The RAM role that OOS assumes
Type: String
Default: ''
AssociationPropertyMetadata:
TimerTrigger: '${timerTrigger}'
RamRole: '{{ OOSAssumeRole }}'
Conditions:
isECSInstance:
Fn::Equals:
- '{{ resourceType }}'
- ALIYUN::ECS::Instance
isECSManagedInstance:
Fn::Equals:
- '{{ resourceType }}'
- ALIYUN::ECS::ManagedInstance
isECDInstance:
Fn::Equals:
- '{{ resourceType }}'
- ALIYUN::ECD::Desktop
Tasks:
- Name: timerTrigger
Action: ACS::TimerTrigger
Description:
en: Triggers a task based on a schedule.
zh-cn: Triggers a task based on a schedule.
Properties:
Type:
Fn::Select:
- type
- '{{timerTrigger}}'
Expression:
Fn::Select:
- expression
- '{{timerTrigger}}'
StartDate:
Fn::Select:
- startDate
- '{{ timerTrigger }}'
EndDate:
Fn::Select:
- endDate
- '{{ timerTrigger }}'
TimeZone:
Fn::Select:
- timeZone
- '{{ timerTrigger }}'
- Name: getInstance
Description:
en: Gets the specified ECS instances.
zh-cn: Gets the specified ECS instances.
Action: ACS::SelectTargets
Properties:
RegionId: '{{ regionId }}'
ResourceType: '{{ resourceType }}'
Filters:
- '{{ targets }}'
Outputs:
instanceIds:
Type: List
ValueSelector: Instances.Instance[].InstanceId
- Name: applyPatchBaseline
Description:
en: Applies a patch baseline on an ECS instance.
zh-cn: Applies a patch baseline on an ECS instance.
Action: ACS::ECS::ApplyPatchBaseline
When: isECSInstance
Properties:
regionId: '{{ regionId }}'
instanceId: '{{ ACS::TaskLoopItem }}'
action: '{{ action }}'
whetherCreateSnapshot: '{{ whetherCreateSnapshot }}'
retentionDays: '{{ retentionDays }}'
rebootIfNeed: '{{ rebootIfNeed }}'
timeout: '{{ timeout }}'
Loop:
RateControl: '{{ rateControl }}'
Items: '{{ getInstance.instanceIds }}'
Outputs:
commandOutputs:
AggregateType: Fn::ListJoin
AggregateField: commandOutput
Outputs:
commandOutput:
Type: String
ValueSelector: commandOutput
- Name: applyPatchBaselineOnManagedInstance
Description:
en: Applies a patch baseline on an ECS managed instance.
zh-cn: Applies a patch baseline on an ECS managed instance.
Action: ACS::ECS::ApplyPatchBaselineOnMangedInstance
When: isECSManagedInstance
Properties:
regionId: '{{ regionId }}'
instanceId: '{{ ACS::TaskLoopItem }}'
action: '{{ action }}'
timeout: '{{ timeout }}'
Loop:
RateControl: '{{ rateControl }}'
Items: '{{ getInstance.instanceIds }}'
Outputs:
commandOutputs:
AggregateType: Fn::ListJoin
AggregateField: commandOutput
Outputs:
commandOutput:
Type: String
ValueSelector: commandOutput
- Name: applyPatchBaselineOnECDInstance
Description:
en: Applies a patch baseline on an ECD instance.
zh-cn: Applies a patch baseline on an ECD instance.
Action: ACS::ECD::ApplyPatchBaseline
When: isECDInstance
Properties:
regionId: '{{ regionId }}'
desktopId: '{{ ACS::TaskLoopItem }}'
action: '{{ action }}'
rebootIfNeed: '{{ rebootIfNeed }}'
whetherCreateSnapshot: '{{ whetherCreateSnapshot }}'
timeout: '{{ timeout }}'
Loop:
RateControl: '{{ rateControl }}'
Items: '{{ getInstance.instanceIds }}'
Outputs:
commandOutputs:
AggregateType: Fn::ListJoin
AggregateField: commandOutput
Outputs:
commandOutput:
Type: String
ValueSelector: commandOutput
Outputs:
commandOutputs:
Type: List
Value: '{{ applyPatchBaseline.commandOutputs }}'