--- patch_mode: "full" # full or security auto_reboot: false # set true per client if reboots are approved packages_updated: [] packages_pre_patch: {} packages_post_patch: {}