41_patch_and_reboot_nodes.yml - Usage Guide
⚠️ Can update packages and reboot live nodes
A default run only reports pending packages and whether a reboot is needed. Changes require node_patch_confirm=true.
Confirmed maintenance flow:
- If it is a Kubernetes node, drain via the first control-plane
apt dist-upgradeon Debian,dnf updateon RedHat- Reboot if reboot was also confirmed and is required
- Uncordon the node
- On error, attempt uncordon from the rescue block
Hosts are processed one at a time with serial: 1.
Variables
| Variable | Default | Description |
|---|---|---|
node_patch_confirm | false | Enables package updates |
node_reboot_confirm | false | Allows a reboot when required |
node_reboot_always | false | Reboots even if there is no reboot flag |
node_allow_single_node_maintenance | false | Extra confirmation for singlenode maintenance |
kubernetes_node_name | ansible_hostname | Node name in the Kubernetes API |
How to run
# Report only:
ansible-playbook -i inventories/musteri_a/hosts.ini playbooks/41_patch_and_reboot_nodes.yml
# Patch a worker and reboot if required:
ansible-playbook -i inventories/musteri_a/hosts.ini playbooks/41_patch_and_reboot_nodes.yml \
--limit worker1 \
--extra-vars 'node_patch_confirm=true node_reboot_confirm=true'
A singlenode cluster also requires node_allow_single_node_maintenance=true. Before maintenance, verify a current etcd backup with 32_verify_etcd_backup.yml.