Skip to content

AWS-RunPatchBaseline - BaselineOverride Upload Details #562

Description

@CDCR-Bradley-Griffin

Hello,

Feature Request: Upload patch details to Patch Manager when using the BaselineOverride parameter.

After configuring my AWS-RunPatchBaseline association to use a central BaselineOverride parameter, I found the instances do not upload their patch details anywhere. Specifically, the contents of "patch-states-configuration.json" is saved locally on the machine but not uploaded to any AWS service.

After opening a support case, I was told this is intended and I would need to use a separate task to upload the contents from the instance to a shared S3 bucket. While this method may work, it seems strange for AWS to not provide a built-in method to collect this critical patch data.

My use case involves using patch baselines from a shared services account that are exported to a baseline override JSON file. The patch baselines are dynamic such as updating the approval date. This allows my organization to control a single set of patch baselines that all accounts will use.

Unfortunately, the Quick Setup Patch Policies were not a viable option for me because they don't support the Schedule Offset parameter available in SSM associations. This would be used to base our maintenance activities around Microsoft's Patch Tuesday.

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions