Creating a Patch Baseline
You can customize a patch baseline to scan the patches of an instance. The patches that do not comply with the baseline can be fixed.
You can create patch baselines for ECSs, BMSs, and CCE instances as required.
Currently, patch baselines are available for multiple OSs, such as EulerOS and CentOS. COC will match the default patch baseline based on the OS of the selected instance for scanning and repair.
COC provides the public patch baseline of each OS as the preset patch baseline for ECSs and BMSs when they are used for the first time. To use the patch baseline function for CCE instances, manually create a patch baseline.
Constraints
Public baselines cannot be modified or deleted.
Creating a Patch Baseline
- Log in to COC.
- In the navigation pane, choose Resource O&M > Automated O&M.
- In the Routine O&M area, click Patch Management. The Patch Management page is displayed.
- Click Patch Baseline to switch to the patch baseline tab page.
- Click Create Patch Baseline and set the patch baseline information by referring to Table 1.
Table 1 Basic information parameters Parameter
Description
Example Value
Baseline Name
Customize the name of the patch baseline based on the naming rule.
Test baseline
Description
(Optional) You can describe the remarks or usage instructions of the baseline.
-
Scenario Type
The value can be ECS, CCE, or BMS.
ECS
OS
The value can be Huawei Cloud EulerOS, CentOS, or EulerOS.
Huawei Cloud EulerOS
Default Baseline or Not
Select the option to set this patch as the preset patch baseline.
-
Baseline Type
Select a baseline type.
-
Table 2 Installation rule baseline Type
Option
Description
Product
- Huawei Cloud EulerOS
- All
- Huawei Cloud EulerOS 1.1
- Huawei Cloud EulerOS 2.0
- CentOS
- All
- CentOS 7.2
- CentOS 7.3
- CentOS 7.4
- CentOS 7.5
- CentOS 7.6
- CentOS 7.7
- CentOS 7.8
- CentOS 7.9
- CentOS 8.0
- CentOS 8.1
- CentOS 8.2
- EulerOS
- All
- EulerOS 2.2
- EulerOS 2.5
- EulerOS 2.8
- EulerOS 2.9
- EulerOS 2.10
Product for which you want to scan patches. Only the patches of the selected product are scanned and fixed.
Category
- All
- Security
- Bugfix
- Enhancement
- Recommended
- New package
Category of patches. Only the patches of the selected category are scanned and fixed.
Severity
- All
- Critical
- Important
- Moderate
- Low
- None
Severity level of patches. Only the patches of the selected severity are scanned and fixed.
Automatic Approval
- Approve the patch after a specified number of days.
- Approve patches released before the specified date.
Automatically approve patches that meet specified conditions.
Specified Days
0-365
This parameter is mandatory when Automatic Approval is set to Approve the patch after a specified number of days.
Specified Days
-
This parameter is mandatory when Automatic Approval is set to Approve patches released before the specified date.
Compliance Reporting
- Unspecified
- Critical
- High
- Medium
- Low
- Suggestion
Level at which patches that meet the patch baseline are displayed in the compliance report
Install Non-Security Patches
-
If you do not select this option, the patches with vulnerabilities will not be updated during patch repair.
Abnormal Patches
-
Approved patches and rejected patches can be in the following formats:
- Complete software package name: example-1.0.0-1.r1.hce2.x86_64
- Software package names that contain a single wildcard: example-1.0.0*.x86_64
Table 3 Custom baseline Type
Option
Description
Product
- Huawei Cloud EulerOS
- All
- Huawei Cloud EulerOS 1.1
- Huawei Cloud EulerOS 2.0
- CentOS
- All
- CentOS 7.2
- CentOS 7.3
- CentOS 7.4
- CentOS 7.5
- CentOS 7.6
- CentOS 7.7
- CentOS 7.8
- CentOS 7.9
- CentOS 8.0
- CentOS 8.1
- CentOS 8.2
- EulerOS
- All
- EulerOS 2.2
- EulerOS 2.5
- EulerOS 2.8
- EulerOS 2.9
- EulerOS 2.10
Product for which you want to scan patches. Only the patches of the selected product are scanned and fixed.
Compliance Reporting
- Unspecified
- Critical
- High
- Medium
- Low
- Suggestion
Level at which patches that meet the patch baseline are displayed in the compliance report
Baseline Patches
None
You can customize the version and release number of a baseline path. Only the patches that match the customized baseline patch can be scanned and installed.
- A maximum of 1,000 baseline patches can be uploaded for a baseline.
- The patch name can contain a maximum of 200 characters, including letters, digits, underscores (_), hyphens (-), dots (.), asterisks (*), and plus signs (+).
- The data in the second column consists of the version number (including letters, digits, underscores, periods, and colons) and the release number (including letters, digits, underscores, and periods) that are separated by a hyphen (-). Both types of numbers can contain a maximum of 50 characters.
- Huawei Cloud EulerOS
- Click OK. The patch baseline is created.
Setting a Default Baseline
- Log in to COC.
- In the navigation pane, choose Resource O&M > Automated O&M.
- In the Routine O&M area, click Patch Management. The Patch Management page is displayed.
- Click the Patch Baseline tab.
- Locate the target baseline and click Set Default Baseline in the Operation column.
More Operations
After a patch baseline is created, you can perform the following operations based on service requirements.
| Function | Scenario Description | Operation |
|---|---|---|
| Modifying a patch baseline | The created custom patch baseline can be modified. | On the Patch Management > Patch Baseline tab page, locate the baseline you want to modify and click Modify in the Operation column. |
| Deleting a patch baseline | If a created custom patch baseline is no longer required, you can delete it. |
|
Helpful Links
- COC matches the preset patch baseline based on the OS of the selected instance to scan patch compliance and repair non-compliant patches.
- If a patch baseline does not take effect after being created, refer to What Can I Do If the Patch Baselines Do Not Take Effect?
- COC can call APIs to obtain node compliance reports and query patch details on nodes by page. For details, see Patch Management.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot