Patch Management
Cloudaware Patch Management is a low‑friction, continuous patching service that keeps operating systems secure without disrupting critical workloads. The module leverages Breeze Agent telemetry, CMDB context, and policy‑driven processes to orchestrate updates across large inventories based on agreed maintenance windows.
- Audience: Cloudaware administrators, cloud/platform and operations teams, security engineers, and compliance owners
- Outcome: Patch discovery and centrally managed OS patching performed by Cloudaware, with patch status, exceptions, and evidence visible in related dashboards
Use Cloudaware Patch Management if you want to:
- Identify Linux and Windows hosts with missing or outdated packages.
- Determine whether available updates address known security vulnerabilities.
- Apply consistent patch versions across development, staging, and production environments.
- Coordinate patching through maintenance windows, blackout periods, canary groups, and rollout waves.
- Control reboot behavior and dependencies.
- Verify that patches were installed successfully.
- Prepare rollback procedures for failed or disruptive updates.
- Track patch coverage, compliance, exceptions, and remediation progress.
- Coordinate patching with Vulnerability Management, Change Management, and ITSM workflows.
Core Capabilities
Cloudaware Patch Management provides:
- Patch discovery and coverage – installed and available package data collected from supported Linux and Windows hosts, with visibility into unpatched or stale systems through coverage reporting.
- Security patch correlation – available updates associated with security relevance and related vulnerability findings where data is available.
- CMDB-based scoping – patch jobs targeted using applications, environments, accounts, owners, tags, relationships, and other CMDB context.
- Patch baselines and snapshots – approved package versions captured as patch baselines and reused across environments for consistent deployments.
- Maintenance controls – maintenance windows, blackout periods, reboot policies, dependencies, retries, and timeout behavior applied to patch jobs.
- Controlled rollout – patch groups, canary deployments, batches, and waves managed through job orchestration and scheduling to limit operational risk.
- Verification and rollback – package state validation, host-health checks, vulnerability rescans, rollback scripts, and supported snapshot restoration.
- Compliance and exception management – patch status, due dates, exclusions, risk acceptance, SLA tracking, and audit evidence maintained across patch workflows.
- Dashboards and reporting – patch coverage, outstanding updates, deployment status, package age, failures, and compliance trends available through dashboards and reports.
- Workflow integrations – patch activity connected to vulnerability findings, change approvals, ITSM tickets, notifications, and operational ownership.
How Patch Management Works
Cloudaware Patch Management is available in two service tiers:
- Standard Patch Management (discovery) – focuses on visibility and matching patches to findings from Vulnerability Management.
- Premium Patch Management (patch deployment) – adds the ability to deploy patches from Cloudaware and orchestrate rollbacks.
Cloudaware Patch Management follows a discovery-to-verification workflow:
- Discovers hosts and package state. Breeze Agent reports installed and available packages from supported Linux and Windows hosts to Cloudaware CMDB.
- Determines patch eligibility. Cloudaware identifies missing updates, target package versions, and whether updates are security-related.
- Groups systems by context. CMDB relationships, tags, applications, environments, accounts, and ownership data define patch scope and rollout groups.
- Creates patch baselines and snapshots. Cloudaware captures the packages and target versions approved for a patch cycle. The same snapshot can be reused across environments to maintain consistency.
- Plans the rollout. Operators select eligible hosts, maintenance windows, blackout periods, reboot rules, deployment waves, notifications, and required approvals.
- Deploys patches. Breeze Agent installs approved packages on each host according to the configured schedule and rollout sequence.
- Verifies results. Cloudaware checks installed package versions, host status, job results, and, where applicable, subsequent vulnerability scan results.
- Supports rollback and reporting. Rollback scripts or platform snapshots can be used where configured, while dashboards and reports record deployment status, failures, exceptions, and compliance evidence.
Patch Operations and Visibility
Patch Cadence (Repo Day)
Cloudaware uses Repo Day to create a consistent package snapshot for each patch cycle. The snapshot establishes the package versions used throughout the rollout so that different environments receive the same approved updates.
Linux Repo Day: The 10th day of each month Windows Repo Day: Aligned with Microsoft Patch Tuesday, which occurs on the second Tuesday of each month
Windows patching typically begins after the Patch Tuesday release. The deployment schedule can be adjusted to meet operational requirements.
A staged rollout can follow this sequence:
- Development: Apply the snapshot to non-critical systems and validate application behavior.
- Staging: Apply the same snapshot after initial validation.
- Production: Apply the validated snapshot after the configured observation period.
The exact timing and number of stages depend on the organization’s maintenance policy, risk tolerance, and environment structure.
Emergency Security Releases
Cloudaware can prepare an emergency patch release to address critical vulnerabilities that cannot wait for the regular patch cycle.
An emergency release can:
- Target only affected hosts and packages.
- Include required package dependencies.
- Use an accelerated approval and deployment schedule.
- Apply dedicated maintenance or reboot controls.
- Verify remediation through installed package state and Vulnerability Management scan results.
Patch Data in CMDB
Cloudaware stores patch presence, eligibility, installation status, and relevant dates as CMDB data.
Teams can use this information to:
- Identify hosts with outstanding patches.
- Group missing updates by severity or security relevance.
- Review the Upgradable Packages KPI tile on supported CI records to check on package availability.
- Measure package age and remediation time to estimate how quickly the organization applies updates.
- Correlate patches with vulnerabilities, applications, environments, owners, and business units.
- Build list views, dashboards, reports, and audit evidence.
For details on how to navigate CMDB views and tiles, see CMDB UI & Navigation.
Relationship to Other Modules and Services
Patch Management works closely with:
- CMDB for the inventory, ownership, and environment context to scope patch jobs and report coverage.
- Breeze Agent that collects patch state on hosts and acts as the secure execution channel for applying and verifying patches.
- Vulnerability Management for prioritizing what to patch.
- Change Management for approvals, change records, and audit trail.
Explore the Patch Management Documentation
Use these guides together as the Cloudaware Patch Management documentation set.
Prepare Patch Management
-
Review requirements. Confirm Breeze Agent deployment, supported operating systems, connectivity, permissions, and security prerequisites.
-
Review sources and coverage. Understand patch telemetry, supported platforms, coverage metrics, and reporting dashboards.
-
Configure policies and maintenance. Define baselines, maintenance windows, blackout periods, and reboot behavior.
Schedule and Deploy Patches
- Scheduling: Configure recurrence, patch cadence, pre-checks, dependencies, retries, and timeout behavior.
- Deployment Workflows: Configure job orchestration, approvals, notifications, deployment waves, and rollout controls.
- Playbooks: Follow workflows for monthly patching, kernel updates, emergency fixes, and ad hoc releases.
Verify and Govern Patching
- Verification & Rollback: Validate patch installation, perform vulnerability rescans, and prepare rollback scripts or snapshot restores.
- Compliance & Exceptions: Manage patch compliance, SLAs, exclusions, risk exceptions, and audit evidence.
- Dashboards & Reporting: Review patch coverage, status, outstanding updates, and remediation progress.
Integrate and Operate
- Integrations: Connect CMDB ownership, vulnerability feeds, ITSM workflows, and collaboration channels.
- Operations: Manage RBAC, data governance, performance, scale, and audit readiness.
- Reference: Review limits & quotas.
- FAQ: Find answers about patch scope, package versions, failures, maintenance windows, Kubernetes, and access control.