Updated on 2026-06-23 GMT+08:00

Creating a Patch Baseline

You can customize a patch baseline to scan the patches of an instance. The patches that do not comply with the baseline can be fixed.

You can create patch baselines for ECSs, BMSs, and CCE instances as required.

Currently, patch baselines are available for multiple OSs, such as EulerOS and CentOS. COC will match the default patch baseline based on the OS of the selected instance for scanning and repair.

COC provides the public patch baseline of each OS as the preset patch baseline for ECSs and BMSs when they are used for the first time. To use the patch baseline function for CCE instances, manually create a patch baseline.

Constraints

Public baselines cannot be modified or deleted.

Creating a Patch Baseline

  1. Log in to COC.
  2. In the navigation pane, choose Resource O&M > Automated O&M.
  3. In the Routine O&M area, click Patch Management. The Patch Management page is displayed.
  4. Click Patch Baseline to switch to the patch baseline tab page.
  5. Click Create Patch Baseline and set the patch baseline information by referring to Table 1.

    Table 1 Basic information parameters

    Parameter

    Description

    Example Value

    Baseline Name

    Customize the name of the patch baseline based on the naming rule.

    Test baseline

    Description

    (Optional) You can describe the remarks or usage instructions of the baseline.

    -

    Scenario Type

    The value can be ECS, CCE, or BMS.

    ECS

    OS

    The value can be Huawei Cloud EulerOS, CentOS, or EulerOS.

    Huawei Cloud EulerOS

    Default Baseline or Not

    Select the option to set this patch as the preset patch baseline.

    -

    Baseline Type

    Select a baseline type.

    • If you select Installation Rule Baseline, set the parameters by referring to Table 2.
    • If you select Custom Baseline, set the parameters by referring to Table 3.

    -

    Table 2 Installation rule baseline

    Type

    Option

    Description

    Product

    • Huawei Cloud EulerOS
      • All
      • Huawei Cloud EulerOS 1.1
      • Huawei Cloud EulerOS 2.0
    • CentOS
      • All
      • CentOS 7.2
      • CentOS 7.3
      • CentOS 7.4
      • CentOS 7.5
      • CentOS 7.6
      • CentOS 7.7
      • CentOS 7.8
      • CentOS 7.9
      • CentOS 8.0
      • CentOS 8.1
      • CentOS 8.2
    • EulerOS
      • All
      • EulerOS 2.2
      • EulerOS 2.5
      • EulerOS 2.8
      • EulerOS 2.9
      • EulerOS 2.10

    Product for which you want to scan patches. Only the patches of the selected product are scanned and fixed.

    Category

    • All
    • Security
    • Bugfix
    • Enhancement
    • Recommended
    • New package

    Category of patches. Only the patches of the selected category are scanned and fixed.

    Severity

    • All
    • Critical
    • Important
    • Moderate
    • Low
    • None

    Severity level of patches. Only the patches of the selected severity are scanned and fixed.

    Automatic Approval

    • Approve the patch after a specified number of days.
    • Approve patches released before the specified date.

    Automatically approve patches that meet specified conditions.

    Specified Days

    0-365

    This parameter is mandatory when Automatic Approval is set to Approve the patch after a specified number of days.

    Specified Days

    -

    This parameter is mandatory when Automatic Approval is set to Approve patches released before the specified date.

    Compliance Reporting

    • Unspecified
    • Critical
    • High
    • Medium
    • Low
    • Suggestion

    Level at which patches that meet the patch baseline are displayed in the compliance report

    Install Non-Security Patches

    -

    If you do not select this option, the patches with vulnerabilities will not be updated during patch repair.

    Abnormal Patches

    -

    Approved patches and rejected patches can be in the following formats:

    • Complete software package name: example-1.0.0-1.r1.hce2.x86_64
    • Software package names that contain a single wildcard: example-1.0.0*.x86_64
    Table 3 Custom baseline

    Type

    Option

    Description

    Product

    • Huawei Cloud EulerOS
      • All
      • Huawei Cloud EulerOS 1.1
      • Huawei Cloud EulerOS 2.0
    • CentOS
      • All
      • CentOS 7.2
      • CentOS 7.3
      • CentOS 7.4
      • CentOS 7.5
      • CentOS 7.6
      • CentOS 7.7
      • CentOS 7.8
      • CentOS 7.9
      • CentOS 8.0
      • CentOS 8.1
      • CentOS 8.2
    • EulerOS
      • All
      • EulerOS 2.2
      • EulerOS 2.5
      • EulerOS 2.8
      • EulerOS 2.9
      • EulerOS 2.10

    Product for which you want to scan patches. Only the patches of the selected product are scanned and fixed.

    Compliance Reporting

    • Unspecified
    • Critical
    • High
    • Medium
    • Low
    • Suggestion

    Level at which patches that meet the patch baseline are displayed in the compliance report

    Baseline Patches

    None

    You can customize the version and release number of a baseline path. Only the patches that match the customized baseline patch can be scanned and installed.

    • A maximum of 1,000 baseline patches can be uploaded for a baseline.
    • The patch name can contain a maximum of 200 characters, including letters, digits, underscores (_), hyphens (-), dots (.), asterisks (*), and plus signs (+).
    • The data in the second column consists of the version number (including letters, digits, underscores, periods, and colons) and the release number (including letters, digits, underscores, and periods) that are separated by a hyphen (-). Both types of numbers can contain a maximum of 50 characters.

  6. Click OK. The patch baseline is created.

Setting a Default Baseline

  1. Log in to COC.
  2. In the navigation pane, choose Resource O&M > Automated O&M.
  3. In the Routine O&M area, click Patch Management. The Patch Management page is displayed.
  4. Click the Patch Baseline tab.
  5. Locate the target baseline and click Set Default Baseline in the Operation column.

More Operations

After a patch baseline is created, you can perform the following operations based on service requirements.

Table 4 More operations

Function

Scenario Description

Operation

Modifying a patch baseline

The created custom patch baseline can be modified.

On the Patch Management > Patch Baseline tab page, locate the baseline you want to modify and click Modify in the Operation column.

Deleting a patch baseline

If a created custom patch baseline is no longer required, you can delete it.

  1. On the Patch Management > Patch Baseline tab page, locate the baseline you want to delete and click Delete in the Operation column.
  2. In the displayed dialog box, click OK. The patch baseline is deleted.

Helpful Links