A Weekly OS Management Hub Job that Installs Every Update on the Groups You Name
An OS Management Hub scheduled job that installs every available update (security-only and the other partial operations by name) on the managed instance groups or compartments you name, weekly by an RRULE from a first run you set in the future, with a reboot window per instance and retries. Instances have to run the agent and be registered with a software source to be seen.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-15 · how we verify
Use it from the registry
terraform · opentofumodule "os_management_patching" {
source = "www.iac-bazaar.com/iac-bazaar/oci-os-management-patching/oci"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
oci-os-management-patching
An OS Management Hub scheduled job that installs every update on the
managed instance groups or compartments you name, weekly, with a
reboot window. Works with Terraform and OpenTofu (>= 1.6), oci
provider >= 8.0, < 9.0.
A job with no target patches nothing; groups or compartments required.
All updates, not security only; partial by name.
Reboots are part of patching; a fifteen-minute window.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
oci-custom-image
A custom Compute image from exactly one source: an instance you built (its boot volume, secrets and all, so build it clean) or a QCOW2 or VMDK object in Object Storage with its operating system named, in the launch mode the workload needs (NATIVE for images built on OCI, PARAVIRTUALIZED for imports). OCI has no image family; the name carries the build.
oci-instance-pool-autoscaling
Self-healing instance pool from an instance configuration with metric- or schedule-based autoscaling and LB attachment.
oci-compute-instance
Opinionated VM with E5/A1 flex shapes, cloud-init, attached block volumes, NSGs and in-transit encryption.
aws-ssm-patch-manager
A patch baseline that approves security patches after a delay, the patch group that binds instances to it by tag, and a maintenance window that runs AWS-RunPatchBaseline on a schedule with the output in CloudWatch. Install rather than Scan (scan-only by name), RebootIfNeeded, and unapproved security updates counted as non-compliant so the approval delay shows on the dashboard.
gcp-os-config-patch
An instance filter that matches nothing patches nothing - the deployment runs on schedule, reports success and touches no host - and reboot_config NEVER installs the kernel and keeps running the old one. Refuses an empty filter, makes all-instances a stated choice because it includes the databases, reboots when the packages need it, and caps the share of a zone patched at once.
azure-update-manager
A maintenance configuration is a schedule and a filter; a machine follows it only through an assignment, and one with no assignment appears scheduled and touches no host. reboot Never installs the kernel and runs the old one; a VM on image-default patching is assigned and skipped. Machines or a dynamic scope come with it; IfRequired reboots; the patch mode every VM needs is an output.