A Patch Schedule Assigned to Machines that Reboots When Needed
A maintenance configuration is a schedule and a filter; a machine follows it only through an assignment, and one with no assignment appears scheduled and touches no host. reboot Never installs the kernel and runs the old one; a VM on image-default patching is assigned and skipped. Machines or a dynamic scope come with it; IfRequired reboots; the patch mode every VM needs is an output.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- No applicable security policies for this provider
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-14 · how we verify
Use it from the registry
terraform · opentofumodule "update_manager" {
source = "www.iac-bazaar.com/iac-bazaar/azure-update-manager/azure"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
azure-update-manager
An Update Manager maintenance configuration that is assigned to machines,
reboots when a patch needs it, and does not run forever by accident. Works
with Terraform and OpenTofu (>= 1.6), azurerm provider
>= 4.0, < 5.0.
A maintenance configuration assigned to nothing patches nothing. VMs or
a dynamic scope come with the configuration; none needs
accept_unassigned_configuration.
reboot = "Never" installs the kernel and runs the old one. IfRequired
here; Never needs accept_no_reboot.
The VMs must be set to platform-orchestrated patching - patch_mode = AutomaticByPlatform with the user-schedule bypass - or the window skips
them. vm_patch_mode_required says so.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
azure-vmss
A self-contained Linux VM Scale Set (Uniform orchestration) on Azure - one apply creates the resource group, VNet, subnet, NSG and an SSH-key-only scale set with deny-all-inbound and no public IPs.
azure-virtual-machine
A fully self-contained general-purpose Linux VM on Azure - one apply creates the resource group, VNet, subnet, NSG, NIC, optional public IP and an SSH-key-only VM with a system-assigned identity.
azure-image-gallery
Community sharing publishes every image version to every Azure customer, unauthenticated, with your publisher email attached; trusted launch supported means a VM may boot without Secure Boot, and an image with no end-of-life date is a 2021 build still being deployed. Private by default, trusted launch required on every definition, an end-of-life date on each, and Hyper-V generation 2 throughout.