SlideShare una empresa de Scribd logo
1 de 25
Descargar para leer sin conexión
AUTOMATED PATCH MANAGEMENT
WITH ANSIBLE AND RUNDECK
Schwarz IT KG - @crsp & @shakalandy
ABOUT US
2
Andreas Lehr
@shakalandy
Rico Spiesberger
@crsp
“Hosting and Domain Services” department
- lidl.de
- lidl-reisen.de/.at/.ch/...
- lidl-shop.nl/.be/.cz/.pl/...
- mobile app backend (30 countries)
ABOUT SCHWARZ IT
➔ Central IT of the Schwarz Group (Lidl, Kaufland, PreZero,
GreenCycle,...)
➔ ~ 3000 employees
➔ HQ in Weinsberg/Heilbronn - Location in Berlin
➔ We have Jobs - https://jobs.schwarz
3
WHAT’S WRONG HERE?
4
WTF?
AUTOMATED PATCHING
5
WHY WE’VE DONE IT
HOW WE’VE DONE IT
LIVE-DEMO (sort of)
WHY AUTOMATED PATCHING?
6
manual patching takes too
much valuable time
WHY AUTOMATED PATCHING?
7
Make security and auditors
happy
WHY AUTOMATED PATCHING?
8
Have a mature and reliable
process
HOW WE’VE DONE IT
c 9
Ansible and Rundeck
• 1 week cycle for DEV/TEST/QA
• 4 week cycle for PROD
• Emergency stuff can be patched
without prior information
• Target: no manual process, but fully
automated
PATCHING WORKFLOW
10
Set Monitoring Downtime
PATCHING WORKFLOW
11
Create VMWare Snapshot
PATCHING WORKFLOW
12
Send Notifications
PATCHING WORKFLOW
13
Host Preparation
PATCHING WORKFLOW
14
finally: upgrade time
PATCHING WORKFLOW
15
reboot if needs-restarting
PATCHING WORKFLOW
c 16
● remove old kernels
● patching date > /etc/last_patching (Monitoring, motd, ansible
CMDB)
● activate Loadbalancer health checks
● clean up (yum clean up, etc)
● update “patchlist” documentation (For auditors and POs)
● remove downtime
● remove snapshot (3 days later)
after reboot tasks
IMPEDIMENTS AND RECOMMENDATIONS ON AUTOMATED PATCHING
17
have fixed timeslots
IMPEDIMENTS AND RECOMMENDATIONS ON AUTOMATED PATCHING
18
Delete Snapshots
automatically
IMPEDIMENTS AND RECOMMENDATIONS ON AUTOMATED PATCHING
19
Rebooting HW servers
takes some time…..
IMPEDIMENTS AND RECOMMENDATIONS ON AUTOMATED PATCHING
20
preload packages
IMPEDIMENTS AND RECOMMENDATIONS ON AUTOMATED PATCHING
21
have enough space in
/var/yum and /tmp
IMPEDIMENTS AND RECOMMENDATIONS ON AUTOMATED PATCHING
22
parallel patching:
ansible forks=20+ and strategy: free
LIVE-DEMO!?!?
QUESTIONS?
Thanks. Don’t forget - https://jobs.schwarz
25

Más contenido relacionado

Similar a OSDC 2019 | Automated patch management with Ansible and Rundeck by Andreas Lehr and Rico Spießberger

Similar a OSDC 2019 | Automated patch management with Ansible and Rundeck by Andreas Lehr and Rico Spießberger (20)

AWSome Day Helsinki Intro
AWSome Day Helsinki IntroAWSome Day Helsinki Intro
AWSome Day Helsinki Intro
 
AGILOS GmbH - Custom Made SAP Outsourcing and Hosting
AGILOS GmbH -  Custom Made SAP Outsourcing and HostingAGILOS GmbH -  Custom Made SAP Outsourcing and Hosting
AGILOS GmbH - Custom Made SAP Outsourcing and Hosting
 
DTIM 2016 - Post Event Report
DTIM 2016 - Post Event ReportDTIM 2016 - Post Event Report
DTIM 2016 - Post Event Report
 
Debunking serverless myths
Debunking serverless mythsDebunking serverless myths
Debunking serverless myths
 
ECS News Letter Issue #3
ECS News Letter Issue #3ECS News Letter Issue #3
ECS News Letter Issue #3
 
NA Adabas & Natural User Group Meeting April 2023
NA Adabas & Natural User Group Meeting April 2023NA Adabas & Natural User Group Meeting April 2023
NA Adabas & Natural User Group Meeting April 2023
 
CloudCamp
CloudCampCloudCamp
CloudCamp
 
S504 mainframe and cloud (and cics) arnold
S504   mainframe and cloud (and cics) arnoldS504   mainframe and cloud (and cics) arnold
S504 mainframe and cloud (and cics) arnold
 
Seeberger
Seeberger Seeberger
Seeberger
 
Peak Hosting Corporate brochure
Peak Hosting Corporate brochurePeak Hosting Corporate brochure
Peak Hosting Corporate brochure
 
Bauer
Bauer Bauer
Bauer
 
Trivadis TechEvent 2016 Office 365 and Therefore Online by Eberhard Lösch, Cl...
Trivadis TechEvent 2016 Office 365 and Therefore Online by Eberhard Lösch, Cl...Trivadis TechEvent 2016 Office 365 and Therefore Online by Eberhard Lösch, Cl...
Trivadis TechEvent 2016 Office 365 and Therefore Online by Eberhard Lösch, Cl...
 
DIGITAL TRANSFORMATION IN MINING
DIGITAL TRANSFORMATION IN MININGDIGITAL TRANSFORMATION IN MINING
DIGITAL TRANSFORMATION IN MINING
 
PowerBI: Real Time streaming information from Sensors
PowerBI: Real Time streaming information from SensorsPowerBI: Real Time streaming information from Sensors
PowerBI: Real Time streaming information from Sensors
 
How Autodesk Leverages Splunk as an Assurance Platform on AWS
How Autodesk Leverages Splunk as an Assurance Platform on AWSHow Autodesk Leverages Splunk as an Assurance Platform on AWS
How Autodesk Leverages Splunk as an Assurance Platform on AWS
 
Compliant by Default - Digitaler Wandel - 14.08.2019 - Schlomo Schapiro
Compliant by Default - Digitaler Wandel - 14.08.2019 - Schlomo SchapiroCompliant by Default - Digitaler Wandel - 14.08.2019 - Schlomo Schapiro
Compliant by Default - Digitaler Wandel - 14.08.2019 - Schlomo Schapiro
 
Building powerful apps with ArangoDB & KeyLines
Building powerful apps with ArangoDB & KeyLinesBuilding powerful apps with ArangoDB & KeyLines
Building powerful apps with ArangoDB & KeyLines
 
Business Data Lake Best Practices
Business Data Lake Best PracticesBusiness Data Lake Best Practices
Business Data Lake Best Practices
 
Welcome Keynote - AWS Summit Stockholm
Welcome Keynote - AWS Summit Stockholm Welcome Keynote - AWS Summit Stockholm
Welcome Keynote - AWS Summit Stockholm
 
MarvelClient for iOS - Client Management for Domino Mobile App
MarvelClient for iOS - Client Management for Domino Mobile AppMarvelClient for iOS - Client Management for Domino Mobile App
MarvelClient for iOS - Client Management for Domino Mobile App
 

Último

TECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service providerTECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service provider
mohitmore19
 
AI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM TechniquesAI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
VictorSzoltysek
 

Último (20)

Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
 
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
 
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
 
Azure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdf
Azure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdfAzure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdf
Azure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdf
 
Software Quality Assurance Interview Questions
Software Quality Assurance Interview QuestionsSoftware Quality Assurance Interview Questions
Software Quality Assurance Interview Questions
 
The Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdfThe Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdf
 
The Guide to Integrating Generative AI into Unified Continuous Testing Platfo...
The Guide to Integrating Generative AI into Unified Continuous Testing Platfo...The Guide to Integrating Generative AI into Unified Continuous Testing Platfo...
The Guide to Integrating Generative AI into Unified Continuous Testing Platfo...
 
TECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service providerTECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service provider
 
AI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM TechniquesAI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
 
How To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.jsHow To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.js
 
Unlocking the Future of AI Agents with Large Language Models
Unlocking the Future of AI Agents with Large Language ModelsUnlocking the Future of AI Agents with Large Language Models
Unlocking the Future of AI Agents with Large Language Models
 
VTU technical seminar 8Th Sem on Scikit-learn
VTU technical seminar 8Th Sem on Scikit-learnVTU technical seminar 8Th Sem on Scikit-learn
VTU technical seminar 8Th Sem on Scikit-learn
 
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
 
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdfLearn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
 
Direct Style Effect Systems - The Print[A] Example - A Comprehension Aid
Direct Style Effect Systems -The Print[A] Example- A Comprehension AidDirect Style Effect Systems -The Print[A] Example- A Comprehension Aid
Direct Style Effect Systems - The Print[A] Example - A Comprehension Aid
 
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
 
Exploring the Best Video Editing App.pdf
Exploring the Best Video Editing App.pdfExploring the Best Video Editing App.pdf
Exploring the Best Video Editing App.pdf
 
A Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docxA Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docx
 
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS LiveVip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
 
How to Choose the Right Laravel Development Partner in New York City_compress...
How to Choose the Right Laravel Development Partner in New York City_compress...How to Choose the Right Laravel Development Partner in New York City_compress...
How to Choose the Right Laravel Development Partner in New York City_compress...
 

OSDC 2019 | Automated patch management with Ansible and Rundeck by Andreas Lehr and Rico Spießberger