Patch Management Requirements
Cloudaware Patch Management relies on the Breeze Agent, CMDB discovery, and appropriate connectivity between your environments and Cloudaware.
Use this guide to review the main prerequisites and confirm readiness before enabling Patch Management.
Breeze Agent and Connectivity
For a host to participate in Patch Management:
- Breeze Agent must be installed and running.
- The host must be able to reach the Breeze endpoints over the required ports (typically outbound HTTPS).
- Package managers (for example,
yum,dnf,apt, or Windows Update sources) must be reachable from the host, either via the internet or via internal repositories.
Refer to the Breeze Agent Requirements for supported installation methods and network details.
Supported Operating Systems
Cloudaware Patch Management supports a broad range of enterprise operating systems, including:
- Red Hat Enterprise Linux and compatible distributions such as CentOS.
- Other major Linux distributions commonly used in the cloud (for example, Ubuntu or SUSE families, where supported by Breeze Agent).
- Microsoft Windows Server versions supported by Breeze Agent (for example, 2012 and later).
For Windows Server 2012, an active Extended Security Updates (ESU) subscription is required, as the operating system reached end of life (EOL) on October 10, 2023. ESU coverage remains available through October 13, 2026.
Support may vary by environment and Breeze version; consult your Cloudaware onboarding materials for the exact list of supported OS versions in your account.
Cloud and Data Center Environments
Patch Management works across:
- Cloud VMs discovered via CMDB (AWS, Microsoft Azure, Google Cloud, and others where supported).
- Auto‑scaling or scale‑set style groups, where patch groups and maintenance windows can be aligned with how instances are rolled out.
- On‑premises or colocation hosts where Breeze Agent can be deployed and can reach Cloudaware.
Permissions
Cloudaware typically does not require direct OS‑level credentials for patching. Actions are executed via Breeze Agent running with sufficient privileges on the host. You should:
- Ensure the agent’s service account has permission to install and uninstall packages and to reboot the system when necessary.
- Confirm that any local hardening or endpoint security software allows package management and the Breeze Agent binaries to operate.
Network and Security Considerations
- Review egress firewall rules so that hosts can reach Cloudaware endpoints and any internal repositories/mirrors.
- Where you use proxies or forwarding hosts, make sure Breeze Agent is configured accordingly.
- Align Patch Management usage with your organization’s change management and security policies, especially around maintenance windows and emergency patch releases.