name: drift run_id: commands[0] env HOME: /home/zuul env LANG: C.UTF-8 env PATH: /home/zuul/src/github.com/osism/release/.tox/drift/bin:/usr/local/bin:/usr/bin:/bin:/usr/games env PIP_DISABLE_PIP_VERSION_CHECK: 1 env PIP_USER: 0 env PYTHONHASHSEED: 1140718786 env PYTHONIOENCODING: utf-8 env PYTHONPATH: /home/zuul/src/github.com/osism/release/src env TOX_ENV_DIR: /home/zuul/src/github.com/osism/release/.tox/drift env TOX_ENV_NAME: drift env TOX_WORK_DIR: /home/zuul/src/github.com/osism/release/.tox env VIRTUAL_ENV: /home/zuul/src/github.com/osism/release/.tox/drift metadata pid: 1817 cwd: /home/zuul/src/github.com/osism/release allow: /home/zuul/src/github.com/osism/release/.tox/drift/bin/* cmd: python3 src/check-drift.py --group all exit_code: 1 Checks follow an image's version pin: release base.yml → rendered manager images.yml → role defaults. role_shadows — 9 DORMANT — overridden by the rendered images.yml; the release pin wins at deploy: adminer_tag (4.7 → 5.4.2) roles/adminer/defaults/main.yml ara_server_mariadb_tag (11.8.3 → 11.8.4) roles/manager/defaults/main.yml manager_redis_tag (7.4.6-alpine → 7.4.7-alpine) roles/manager/defaults/main.yml vault_tag (1.21.0 → 1.21.4) roles/manager/defaults/main.yml netbox_redis_tag (7.4.6-alpine → 7.4.7-alpine) roles/netbox/defaults/main.yml postgres_tag (16.10-alpine → 16.11-alpine) roles/netbox/defaults/main.yml nexus_tag (3.82.0 → 3.93.1) roles/nexus/defaults/main.yml phpmyadmin_tag (5.2 → 5.2.3) roles/phpmyadmin/defaults/main.yml traefik_tag (v3.4.4 → v3.5.0) roles/traefik/defaults/main.yml Fix: lower priority; sync when convenient. Refs: release/latest/base.yml role_shadows — 3 LIVE — no images.yml override; the role default is what actually deploys: dnsmasq_tag (2.90 → 2.91) roles/dnsmasq/defaults/main.yml scaphandre_tag (1.0.0 → 1.0.2) roles/scaphandre/defaults/main.yml stepca_tag (0.28.4 → 0.30.2) roles/stepca/defaults/main.yml Fix: add `_tag`/`_image` to the manager render template (images.yml.j2) so the latest/base.yml pin governs the deployed version. Refs: release/latest/base.yml role_unpinned — 4 _tag pins in role defaults with no release base.yml pin: httpd_tag (alpine, no release pin) roles/httpd/defaults/main.yml httpd_data_tag (latest, no release pin) roles/httpd/defaults/main.yml kepler_tag (v0.11.2, no release pin) roles/kepler/defaults/main.yml thanos_sidecar_tag (v0.32.5, no release pin) roles/thanos_sidecar/defaults/main.yml Fix: add a pin to release base.yml (and wire _tag into the manager render template) to make it release-managed, or allowlist it if the image is intentionally role-managed. Refs: release/latest/base.yml image_orphan — 3 image vars emitted by the manager images.yml that no role or playbook consumes: nginx, osism_netbox, registry Fix: remove the orphaned _tag/_image (and its etc/images.yml + role-default remnants), or allowlist it if the image is genuinely consumed in a form this scan misses — it flags an alias only when no literal {{ _image }} reference is found in the scanned roles/playbooks. Refs: ansible-collection-services/roles/, ansible-playbooks-manager/playbooks/ generics/environments/manager/images.yml Checks follow a service's path: enabled → built → version-pinned → deployed. kolla_enablement_orphan — 9 OSISM enable flags whose service upstream kolla-ansible no longer defines at any supported release; the service was removed or renamed upstream, leaving the flag orphaned: auditd, chrony, horizon_karbor, horizon_qinling, horizon_searchlight, karbor, openstack_exporter, qinling, searchlight Fix: remove the stale enable_ from osism/defaults, or migrate it to the upstream replacement. Some flags (e.g. common, kolla_operations) are OSISM inventions with no upstream counterpart — keep those allowlisted rather than removed. Refs: openstack/kolla-ansible group_vars enable-defaults @ supported refs osism/defaults all/*.yml kolla_groupvars_missing — 27 upstream kolla-ansible group_vars OSISM defaults never mirrored; each is undefined in the deploy var context and aborts any role task that uses it: ceph_cinder_backup_keyring, ceph_cinder_keyring, ceph_glance_keyring, ceph_gnocchi_keyring, ceph_manila_keyring, ceph_nova_keyring, default_container_dimensions_docker, default_container_dimensions_podman, distro_python_version_map, enable_cinder_backend_hnas_nfs, enable_swift_recon, enable_swift_s3api, glance_backend_swift, prometheus_msteams_port, prometheus_msteams_webhook_url, swift_account_server_port, swift_container_server_port, swift_external_fqdn, swift_internal_base_endpoint, swift_internal_endpoint, swift_internal_fqdn, swift_object_server_port, swift_proxy_server_listen_port, swift_proxy_server_port, swift_public_base_endpoint, swift_public_endpoint, swift_rsync_port Fix: mirror the missing var into osism/defaults all/*.yml (copying upstream's definition — harmless when the service is off, needed when an environment enables it), or allowlist it with a reason if OSISM deliberately omits it: the related service is not shipped/supported by OSISM at all (so the var is never evaluated anywhere), a var OSISM supplies another way, or an upstream typo. Refs: openstack/kolla-ansible group_vars/all @ supported refs osism/defaults all/*.yml kolla_orphan_config — 2 dead companion/image config vars for services upstream removed (their enable_ flag is reported separately by kolla_enablement_orphan); these must be removed too: chrony_image, chrony_tag Fix: remove these vars from the listed osism/defaults file, or allowlist any that are intentionally kept (an OSISM invention with no upstream service). Refs: openstack/kolla-ansible (service removed upstream) osism/defaults all/002-images-kolla.yml kolla_orphan_config — 2 dead companion/image config vars for services upstream removed (their enable_ flag is reported separately by kolla_enablement_orphan); these must be removed too: chrony_allowed_subnets, chrony_servers Fix: remove these vars from the listed osism/defaults file, or allowlist any that are intentionally kept (an OSISM invention with no upstream service). Refs: openstack/kolla-ansible (service removed upstream) osism/defaults all/099-generic.yml kolla_orphan_config — 5 dead companion/image config vars for services upstream removed (their enable_ flag is reported separately by kolla_enablement_orphan); these must be removed too: openstack_exporter_clouds_yml_cloud, openstack_exporter_clouds_yml_path, openstack_exporter_secure_yml_path, openstack_exporter_service_monitor_scrape_interval, openstack_exporter_service_monitor_scrape_timeout Fix: remove these vars from the listed osism/defaults file, or allowlist any that are intentionally kept (an OSISM invention with no upstream service). Refs: openstack/kolla-ansible (service removed upstream) osism/defaults all/099-infrastructure.yml Summary: 64 to act on, 42 allowlisted, 0 stale allowlist entries (106 total) standard error: Resolving sources (0 base dir(s)): ansible_collection_services remote osism/ansible-collection-services @ main [remote] ansible_playbooks_manager remote osism/ansible-playbooks-manager @ main [remote] cfg_cookiecutter remote osism/cfg-cookiecutter @ main [remote] container_image_kolla_ansible remote osism/container-image-kolla-ansible @ main [remote] container_image_osism_ansible remote osism/container-image-osism-ansible @ main [remote] container_images_kolla remote osism/container-images-kolla @ main [remote] defaults remote osism/defaults @ main [remote] generics remote osism/generics @ main [remote] kolla remote openstack/kolla @ stable/2025.2 (+per-release range refs) [remote] kolla_ansible remote openstack/kolla-ansible @ stable/2025.2 (+per-release range refs) [remote] release remote osism/release @ main [remote] testbed remote osism/testbed @ main [remote]