AWS-RunPatchBaseline - BaselineOverride Upload Details
- Dominant language
- Go
- Stars
- 1.2k
- Forks
- 357
- PR merge metrics
- No merged PRs in 30d
Description
Hello,
Feature Request: Upload patch details to Patch Manager when using the BaselineOverride parameter.
After configuring my AWS-RunPatchBaseline association to use a central BaselineOverride parameter, I found the instances do not upload their patch details anywhere. Specifically, the contents of "patch-states-configuration.json" is saved locally on the machine but not uploaded to any AWS service.
After opening a support case, I was told this is intended and I would need to use a separate task to upload the contents from the instance to a shared S3 bucket. While this method may work, it seems strange for AWS to not provide a built-in method to collect this critical patch data.
My use case involves using patch baselines from a shared services account that are exported to a baseline override JSON file. The patch baselines are dynamic such as updating the approval date. This allows my organization to control a single set of patch baselines that all accounts will use.
Unfortunately, the Quick Setup Patch Policies were not a viable option for me because they don't support the Schedule Offset parameter available in SSM associations. This would be used to base our maintenance activities around Microsoft's Patch Tuesday.
Thanks!
Contributor guide
Research direction
Start by tracing how the AWS-RunPatchBaseline association handles the BaselineOverride parameter and the locally saved patch-states-configuration.json; the issue names no source file or test. Define the upload behavior and verify that patch details are collected by an AWS service without requiring a separate S3 task.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, go
- Domain
- cloud, devops
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100