Patch Management across clouds
The service that patches a fleet on a schedule - Systems Manager Patch Manager, Azure Update Manager, VM Manager OS patch - with a baseline that says what is approved and a window that says when.
3 verified modules - all static-validated and publish-checked; live-test pending.
Compare by provider
| Provider | Module | Verification |
|---|---|---|
| AWS | A Patch Baseline, Its Patch Group and a Maintenance Window that Installs | static-validated |
| Azure | A Patch Schedule Assigned to Machines that Reboots When Needed | static-validated |
| Google Cloud | A Patch Deployment that Targets Hosts and Reboots When Needed | static-validated |
How to choose
Compare what the baseline can express (severity and classification, a delay after release, a reject list), whether a run installs or only scans, how reboots are handled, and what the run leaves behind: a compliance view that names the instance and the patch, or a job status.
When not to use
A patch service that only scans produces a compliance dashboard and nothing else. Install mode and a reboot policy are the decisions; a fleet that must never reboot is a fleet whose kernel never changes.