Patch Management FAQ
This FAQ answers common questions about Cloudaware Patch Management.
Can I Apply Patches from Cloudaware?
Yes. Standard Patch Management focuses on discovery, eligibility, and reporting (see Patch Management Overview). If you enable Premium Patch Management, Cloudaware can also orchestrate patch deployment, including selecting which patches to apply and executing them on specific hosts (see Deployment Workflows).
How Do I See Current and Available Versions of Packages?
For any Breeze‑enabled host, you can open the object record in Cloudaware CMDB and review the related patch information. This typically includes:
- Installed vs. available versions.
- Whether a patch is security‑related.
- How long a package has been outstanding.
You can also use Patch Management dashboards and reports for an aggregate view - see Coverage Reporting and Compliance Reporting.
Do You Patch Kubernetes?
No. Cloudaware focuses on patching for operating system instances where Breeze Agent can run (for example, cloud VMs). See Requirements for supported platforms.
What Happens if a Patch Fails?
If a patch installation fails on a host:
- The failure is reported in the Patch Management job results and dashboards.
- Any pre‑ or post‑checks that fail (for example, service health) are surfaced as part of the job logs.
- Cloudaware will use the generated rollback script/snapshot restore or schedule a follow‑up job after remediation - see Verification & Rollback and Retries & Timeouts.
Integration with ITSM tools lets you automatically open incidents or change tasks when failures occur. See ITSM & Ticketing.
How Do Maintenance Windows and Blackout Windows Interact?
Cloudaware does not use blackout windows. Patch jobs are allowed to run only when the job’s schedule falls within at least one maintenance window for the relevant environment or service (see Maintenance Windows).
How Is Access to Patch Management Controlled?
Patch Management follows Cloudaware’s RBAC model:
- You can assign roles that allow viewing patch data, planning jobs, or approving/deploying patches.
- Patching actions are audited so you can track who initiated or approved a given release.
- Integration with SSO providers lets you map existing groups to Patch Management roles.
See RBAC for example role patterns and guidance.