Unpinned package versions

Validate production package updates and specify the required versions and dependency scope.

Description

Using state: latest for package installation can install a new version available from the repository at execution time. The same playbook can produce different results over time, and compatibility or dependency changes can disrupt service.

Automatic updates can be part of a planned security-patching policy. Pinning versions also requires a validation and update process so security fixes continue to be applied.

Potential impact

  • Unvalidated package or dependency updates can cause outages or performance degradation.
  • Changes between executions can reduce deployment reproducibility.

Remediation

  • For production deployments requiring version control, use an explicit package version with state: present. present alone does not pin the version.
  • Manage relevant dependencies and repositories, and test updates in a validation environment first. update_only: true restricts new package installations; it does not pin versions.
  • Review security updates for pinned versions and refresh them regularly.

Examples

These existing yum excerpts require support from the installed Ansible version and package backend. The repository must provide the selected version; 1.24.0 is a comparison value, not a recommendation for current production use.

Before

yaml
---
- name: 패키지 설치
  hosts: localhost
  tasks:
    - name: nginx 최신 버전 설치
      ansible.builtin.yum:
        name: nginx
        state: latest

The task installs or updates to the latest version available from the repository at execution time.

After

yaml
---
- name: 패키지 설치
  hosts: localhost
  tasks:
    - name: nginx 고정 버전 설치
      ansible.builtin.yum:
        name: nginx-1.24.0
        state: present

The task specifies the nginx version to install. It does not pin every dependency or distribution package release, so manage those separately where required.

References