Creating a patch catalog for Debian or Ubuntu


Related BMC Communities article

BMC Customers using Automation for Patching use cases depend on OS vendors for Patches and metadata.  To view a document that tracks the service status of the different OS Vendors as known to BMC Support, see the following BMC Communities document:

OS Patching Vendor Health Dashboard

The patch catalog is used to maintain and work with the patch repository through the TrueSight Server Automation Console. For both types of repositories, online and offline, you create a patch catalog through the TrueSight Server Automation console. Patches are added to the catalog as depot objects according to filters defined for the catalog.

This topic describes how to set up a patch catalog for Debian or Ubuntu, and includes the following sections:

Step 1: Review prerequisites for the catalog

Review the following prerequisites for creating patch catalogs for Debian and Ubuntu.

  • Ensure that security policies on the repository server do not block the download of the catalog.
  • Ensure that the system you will use for the patch repository is supported by TrueSight Server Automation.

    Click here to see the platforms supported for storing your repository

    For the complete list of deprecated platforms, see Deprecated-and-discontinued-features.

Step 2: Create the patch catalog


  1. Right-click a folder in the Depot and select New > Patch catalog > Debian Linux Patch Catalog.
    The New Patch Catalog dialog panel opens. This option applies to both Debian and Ubuntu.
  2. Provide information for the patch catalog as described in the following table:

    Panel section

    Description

    General

    Enter a Name for the patch catalog and a Description of its contents. Then, browse to the folder in which you want to store the catalog.

    Catalog options

    Define options such as locations (location of the source files, the repository, the signature file, and so on) as well as filters and whether local copies of the files are created on the target server or downloaded directly during deployment.

    The referenced document [xwiki:Automation-DevSecOps.Server-Automation.TrueSight-Server-Automation.tssa252.Using.Creating-and-modifying-TrueSight-Server-Automation-jobs.Panel-reference-for-Patch-Management-Jobs.Patch-Catalog-job-panels.Patch-catalog-Debian-Catalog.WebHome] was not found.

  3. In the bottom right corner, select Job options. (You can also edit the catalog at a later time to set these options).
  4. Provide information for the patch catalog options as described in the following table:

    Tab

    Description

    Schedules

    Job Run Notifications

    Depot Object Options

    Network URL Type for Payload Deployment

    • (default) Copy to agent at staging: The TrueSight Server Automation Application Server copies patch payloads to a staging directory on the target server during the Deploy Job staging phase.
    • Agent mounts source for direct use at deployment (no local copy): A Deploy Job instructs the agent on a target server to: mount the device specified in the URl and deploy patch payloads directly to the agent. The Deploy Job does not copy patch payloads to a staging area on the agent, so the job does not create any local copies of the patches on target servers.

    Network URL for Payload Deployment

    The value entered here depends on your selection in the Network URL Type for Payload Deployment box:

    • If you chose Copy to agent at staging, do not enter a value here. The value is autopopulated based on the repository location.
    • If you chose Agent mounts source for direct use at deployment (no local copy), enter the NFS-accessible path to the location of the payload.
      If you specify the host in this path as an IPv6 address, enclose the IPv6 address in square brackets.

    RBAC Policy

    Browse to and select a predefined ACL Policy. Permissions defined by the ACL Policy are assigned to all Depot objects created in the catalog.

    Max Deport Object Work Items to Process in Parallel

    Maximum number of work items that can be performed in parallel.

    Job Properties

    Permissions

  5. Click Finish
    A Patch Catalog is stored in the appropriate Depot folder.


Editing the options

  1. In the Depot, right-click the Debian Linux Patch Catalog you just created.
  2. Select Open.
  3. Set or update any information for the patch catalog options.
  4. When finished, save the catalog.

Where to go from here

Downloading-patch-payloads-to-the-catalog

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*