Skip to content

Commit 4e5afe1

Browse files
committed
Merge branch 'feature/patch-mgmt' of https://github.com/mk-amz/aws-security-reference-architecture-examples into feature/patch-mgmt
2 parents 177df8f + 210b5f9 commit 4e5afe1

File tree

13 files changed

+2183
-379
lines changed

13 files changed

+2183
-379
lines changed

aws_sra_examples/easy_setup/customizations_for_aws_control_tower/manifest.yaml

Lines changed: 80 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -241,32 +241,95 @@ resources:
241241
# Patch Manager Solution
242242
- parameter_key: pPatchMgmtRoleName
243243
parameter_value: "sra-patch-mgmt-configuration"
244-
- parameter_key: pPatchMgmtMaintWindowName
244+
# Window 1
245+
- parameter_key: pPatchMgmtMaintWindow1Name
245246
parameter_value: "Update_SSM"
246-
- parameter_key: pPatchMgmtMaintWindowDesc
247+
- parameter_key: pPatchMgmtMaintWindow1Desc
247248
parameter_value: "Maintenance Window update the SSM Agent on managed Instances"
248-
- parameter_key: pPatchMgmtMaintWindowSchedule
249-
parameter_value: "cron(0 0 1 ? * THU *)"
250-
- parameter_key: pPatchMgmtMaintWindowDuration
249+
- parameter_key: pPatchMgmtMaintWindow1Schedule
250+
parameter_value: "cron(0 0 1 ? * WED *)"
251+
- parameter_key: pPatchMgmtMaintWindow1Duration
251252
parameter_value: "6"
252-
- parameter_key: pPatchMgmtMaintWindowCutoff
253+
- parameter_key: pPatchMgmtMaintWindow1Cutoff
253254
parameter_value: "1"
254-
- parameter_key: pPatchMgmtMaintWindowTZ
255+
- parameter_key: pPatchMgmtMaintWindow1TZ
255256
parameter_value: "America/New_York"
256-
- parameter_key: pPatchMgmtTaskName
257-
parameter_value: "Update_SSMAgent"
258-
- parameter_key: pPatchMgmtTaskDesc
257+
- parameter_key: pPatchMgmtTask1Name
258+
parameter_value: "Update_SSM"
259+
- parameter_key: pPatchMgmtTask1Desc
259260
parameter_value: "Task to update SSM Agent"
260-
- parameter_key: pPatchMgmtTaskRunCmd
261+
- parameter_key: pPatchMgmtTask1Operation
262+
parameter_value: "Scan"
263+
- parameter_key: pPatchMgmtTask1RebootOption
264+
parameter_value: "RebootIfNeeded"
265+
- parameter_key: pPatchMgmtTask1RunCmd
261266
parameter_value: "AWS-UpdateSSMAgent"
262-
- parameter_key: pPatchMgmtTargetName
263-
parameter_value: "AWS-UpdateSSMAgent"
264-
- parameter_key: pPatchMgmtTargetDesc
265-
parameter_value: "Maintenance Window to update SSM Agent"
266-
- parameter_key: pPatchMgmtTargetValue1
267+
- parameter_key: pPatchMgmtTarget1Name
268+
parameter_value: "Update_SSM"
269+
- parameter_key: pPatchMgmtTarget1Desc
270+
parameter_value: "Targets to update SSM Agent on"
271+
- parameter_key: pPatchMgmtTarget1Value1
267272
parameter_value: "Linux"
268-
- parameter_key: pPatchMgmtTargetValue2
273+
- parameter_key: pPatchMgmtTarget1Value2
269274
parameter_value: "Windows"
275+
# Window 2
276+
- parameter_key: pPatchMgmtMaintWindow2Name
277+
parameter_value: "Windows_Scan"
278+
- parameter_key: pPatchMgmtMaintWindow2Desc
279+
parameter_value: "Maintenance Window to scan Windows Instances"
280+
- parameter_key: pPatchMgmtMaintWindow2Schedule
281+
parameter_value: "cron(0 0 1 ? * THU *)"
282+
- parameter_key: pPatchMgmtMaintWindow2Duration
283+
parameter_value: "6"
284+
- parameter_key: pPatchMgmtMaintWindow2Cutoff
285+
parameter_value: "1"
286+
- parameter_key: pPatchMgmtMaintWindow2TZ
287+
parameter_value: "America/New_York"
288+
- parameter_key: pPatchMgmtTask2Name
289+
parameter_value: "Windows_Scan"
290+
- parameter_key: pPatchMgmtTask2Desc
291+
parameter_value: "Task to scan Windows Instances"
292+
- parameter_key: pPatchMgmtTask2Operation
293+
parameter_value: "Scan"
294+
- parameter_key: pPatchMgmtTask2RebootOption
295+
parameter_value: "RebootIfNeeded"
296+
- parameter_key: pPatchMgmtTask2RunCmd
297+
parameter_value: "AWS-RunPatchBaseline"
298+
- parameter_key: pPatchMgmtTarget2Name
299+
parameter_value: "Windows_Scan"
300+
- parameter_key: pPatchMgmtTarget2Desc
301+
parameter_value: "Targets to run the command to scan for Windows updates"
302+
- parameter_key: pPatchMgmtTarget2Value1
303+
parameter_value: "Windows"
304+
# Window 3
305+
- parameter_key: pPatchMgmtMaintWindow3Name
306+
parameter_value: "Linux_Scan"
307+
- parameter_key: pPatchMgmtMaintWindow3Desc
308+
parameter_value: "Maintenance Window scan Linux Instances"
309+
- parameter_key: pPatchMgmtMaintWindow3Schedule
310+
parameter_value: "cron(0 0 1 ? * FRI *)"
311+
- parameter_key: pPatchMgmtMaintWindow3Duration
312+
parameter_value: "6"
313+
- parameter_key: pPatchMgmtMaintWindow3utoff
314+
parameter_value: "1"
315+
- parameter_key: pPatchMgmtMaintWindow3TZ
316+
parameter_value: "America/New_York"
317+
- parameter_key: pPatchMgmtTask3Name
318+
parameter_value: "Linux_Scan"
319+
- parameter_key: pPatchMgmtTask3Desc
320+
parameter_value: "Task to scan Linux Instances"
321+
- parameter_key: pPatchMgmtTask3Operation
322+
parameter_value: "Scan"
323+
- parameter_key: pPatchMgmtTask3RebootOption
324+
parameter_value: "RebootIfNeeded"
325+
- parameter_key: pPatchMgmtTask3RunCmd
326+
parameter_value: "AWS-RunPatchBaseline"
327+
- parameter_key: pPatchMgmtTarget3Name
328+
parameter_value: "Linux_Scan"
329+
- parameter_key: pPatchMgmtTarget3Desc
330+
parameter_value: "Targets to run the command to scan for Linux updates"
331+
- parameter_key: pPatchMgmtTarget3Value1
332+
parameter_value: "Linux"
270333

271334
# Common Properties
272335
- parameter_key: pSRAAlarmEmail

0 commit comments

Comments
 (0)