Oracle CloudStatic-verified

A Weekly OS Management Hub Job that Installs Every Update on the Groups You Name

An OS Management Hub scheduled job that installs every available update (security-only and the other partial operations by name) on the managed instance groups or compartments you name, weekly by an RRULE from a first run you set in the future, with a reboot window per instance and retries. Instances have to run the agent and be registered with a software source to be seen.

terraformOracle Cloudoci

Compare Patch Management across clouds →

oci-os-management-patchingvizier v1.2.0

Verification

Static-verified

Passed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-09-15 · how we verify

Use it from the registry

terraform · opentofu
module "os_management_patching" {
  source  = "www.iac-bazaar.com/iac-bazaar/oci-os-management-patching/oci"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

oci-os-management-patching

An OS Management Hub scheduled job that installs every update on the managed instance groups or compartments you name, weekly, with a reboot window. Works with Terraform and OpenTofu (>= 1.6), oci provider >= 8.0, < 9.0.

A job with no target patches nothing; groups or compartments required.

All updates, not security only; partial by name.

Reboots are part of patching; a fifteen-minute window.

Verification

Static validation runs tofu fmt, init, validate, tflint and checkov. This module has not yet had a live test, so it is published as statically validated with its live test pending and does not carry the live-tested mark.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage

Related modules

Static validatedLive test pending

oci-custom-image

A custom Compute image from exactly one source: an instance you built (its boot volume, secrets and all, so build it clean) or a QCOW2 or VMDK object in Object Storage with its operating system named, in the launch mode the workload needs (NATIVE for images built on OCI, PARAVIRTUALIZED for imports). OCI has no image family; the name carries the build.

View module
Static validatedLive test pending

oci-instance-pool-autoscaling

Self-healing instance pool from an instance configuration with metric- or schedule-based autoscaling and LB attachment.

View module
Static validatedLive test pending

oci-compute-instance

Opinionated VM with E5/A1 flex shapes, cloud-init, attached block volumes, NSGs and in-transit encryption.

View module
Static validatedLive test pending

aws-ssm-patch-manager

A patch baseline that approves security patches after a delay, the patch group that binds instances to it by tag, and a maintenance window that runs AWS-RunPatchBaseline on a schedule with the output in CloudWatch. Install rather than Scan (scan-only by name), RebootIfNeeded, and unapproved security updates counted as non-compliant so the approval delay shows on the dashboard.

View module
Static validatedLive test pending

gcp-os-config-patch

An instance filter that matches nothing patches nothing - the deployment runs on schedule, reports success and touches no host - and reboot_config NEVER installs the kernel and keeps running the old one. Refuses an empty filter, makes all-instances a stated choice because it includes the databases, reboots when the packages need it, and caps the share of a zone patched at once.

View module
Static validatedLive test pending

azure-update-manager

A maintenance configuration is a schedule and a filter; a machine follows it only through an assignment, and one with no assignment appears scheduled and touches no host. reboot Never installs the kernel and runs the old one; a VM on image-default patching is assigned and skipped. Machines or a dynamic scope come with it; IfRequired reboots; the patch mode every VM needs is an output.

View module