1. 配置Windows Server自动下载更新,手动安装
- name: set-update-config
win_command: 'reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v AUOptions /t REG_DWORD /d 3 /f'
when: ansible_distribution == 'Microsoft Windows Server 2012 R2 Standard'- name: start-service
win_command: 'net start wuauserv' wuauclt.exe /updatenow
when: ansible_distribution == 'Microsoft Windows Server 2012 R2 Standard'
- name: start-service
win_command: 'C:\Windows\system32\wuauclt.exe /updatenow'
when: ansible_distribution == 'Microsoft Windows Server 2012 R2 Standard'
2. 安装补丁包
- name: copy 2012
win_copy:
src: '/root/ansible/windows_patch/windows2012r2.msu'
dest: 'C:\Temp\CVE-2020-1472.msu'
when: ansible_distribution == 'Microsoft Windows Server 2012 R2 Standard'- name: install 2012
win_command: 'cmd.exe /C "C:\Windows\system32\wusa.exe C:\Temp\CVE-2020-1472.msu /quiet /norestart'"
when: ansible_distribution == 'Microsoft Windows Server 2012 R2 Standard'