Driftdetector baseline management:
[root@dsm-ocbdlweb001 ~]# hostname -f
dsm-ocbdlweb001.srv.bmogc.net
#
# drifrtdetector daemon:
#
[root@dsm-ocbdlweb001 ~]# systemctl status driftdetector.service
[[green:●]] driftdetector.service - driftdetector, Ansible configuration drift detection
Loaded: loaded (/etc/systemd/system/driftdetector.service; enabled; preset: disabled)
Active: [[green:active (running)]] since Thu 2026-07-16 21:00:50 UTC; 6h ago
Main PID: 45304 (driftdetector.s)
Tasks: 2 (limit: 15343)
Memory: 3.1M (limit: 10.0M peak: 10.0M)
CPU: 24.614s
CGroup: /system.slice/driftdetector.service
├─45304 /bin/bash /home/driftdetector/driftdetector.sh
└─64636 /usr/bin/coreutils --coreutils-prog-shebang=sleep /usr/bin/sleep 300
Jul 17 03:11:21 dsm-ocbdlweb001.srv.bmogc.net sudo[64497]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=1000)
Jul 17 03:11:21 dsm-ocbdlweb001.srv.bmogc.net sudo[64497]: pam_unix(sudo:session): session closed for user root
Jul 17 03:11:21 dsm-ocbdlweb001.srv.bmogc.net sudo[64500]: driftdetector : PWD=/ ; USER=root ;
COMMAND=/bin/stat -c '/etc/ld.so.conf.d/httpd-lib.conf: %F %U %G %a' /etc/ld.so.conf.>
Jul 17 03:11:21 dsm-ocbdlweb001.srv.bmogc.net sudo[64500]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=1000)
Jul 17 03:11:21 dsm-ocbdlweb001.srv.bmogc.net sudo[64500]: pam_unix(sudo:session): session closed for user root
Jul 17 03:11:21 dsm-ocbdlweb001.srv.bmogc.net sudo[64506]: driftdetector : PWD=/ ; USER=root ; COMMAND=/bin/sha256sum /home/driftdetector/driftdetector.sh /home/driftdetector/mq_co>
Jul 17 03:11:21 dsm-ocbdlweb001.srv.bmogc.net sudo[64506]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=1000)
Jul 17 03:11:21 dsm-ocbdlweb001.srv.bmogc.net sudo[64506]: pam_unix(sudo:session): session closed for user root
[root@dsm-ocbdlweb001 /]# ps -aux | grep [d]riftdetector
driftde+ 13948 0.0 0.0 5252 3504 ? Ss 04:16 0:00 /bin/bash /home/driftdetector/driftdetector.sh
#
# /var/log/driftdetector:
#
[root@dsm-ocbdlweb001 /]# ls -ld /var/log/driftdetector
drwxr-xr-x 2 driftdetector driftdetector 4096 Jul 17 04:16 /var/log/driftdetector
[root@dsm-ocbdlweb001 /]# ls -l /var/log/driftdetector
-rw-r--r-- 1 driftdetector driftdetector 3003 Jul 17 04:26 driftdetector.log
[root@dsm-ocbdlweb001 /]# tail -f /var/log/driftdetector/driftdetector.log
{"timestamp": "2026-07-17T04:17:00", "host": "dsm-ocbdlweb001.srv.bmogc.net", "logLevel": "INFO", "appName": "DSM", "appCatCode": "23093",
"serviceName": "ansible", "additionalInfo": {"job_count_today": 1, "job_list": [{"tower_job_id": "dummyIDforLocalTest", "tower_user_name":
"dummyUserforLocalTest", "ansible_check_mode": "False"}]}}
{ "timestamp":"2026-07-17T04:21:53.341+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"INFO", "appName":"DSM", "appCatCode":"23093",
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"Total 8 objects checked: /home/driftdetector/driftdetector.sh /home/
driftdetector/mq_conf_snapshot.sh /home/driftdetector/was_conf_snapshot.sh /home/driftdetector/drift_state_manager.py /etc/systemd/system/
driftdetector.service /etc/logrotate.d/driftdetector /etc/sudoers.d/driftdetector /etc/ld.so.conf.d/httpd-lib.conf" }
{ "timestamp":"2026-07-17T04:21:53.342+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"INFO", "appName":"DSM", "appCatCode":"23093",
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"No configuration drift detected" }
{ "timestamp":"2026-07-17T04:21:53.382+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"INFO", "appName":"DSM", "appCatCode":"23093",
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"cac_collection/driftdetector version: v8.2.0-1" }
{ "timestamp":"2026-07-17T04:26:53.628+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"INFO", "appName":"DSM", "appCatCode":"23093",
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"Total 8 objects checked: /home/driftdetector/driftdetector.sh /home/
driftdetector/mq_conf_snapshot.sh /home/driftdetector/was_conf_snapshot.sh /home/driftdetector/drift_state_manager.py /etc/systemd/system/
driftdetector.service /etc/logrotate.d/driftdetector /etc/sudoers.d/driftdetector /etc/ld.so.conf.d/httpd-lib.conf" }
{ "timestamp":"2026-07-17T04:26:53.630+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"INFO", "appName":"DSM", "appCatCode":"23093",
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"No configuration drift detected" }
{ "timestamp":"2026-07-17T04:26:53.713+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"INFO", "appName":"DSM", "appCatCode":"23093",
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"cac_collection/driftdetector version: v8.2.0-1" }
{ "timestamp":"2026-07-17T04:31:53.953+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"INFO", "appName":"DSM", "appCatCode":"23093",
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"Total 8 objects checked: /home/driftdetector/driftdetector.sh /home/
driftdetector/mq_conf_snapshot.sh /home/driftdetector/was_conf_snapshot.sh /home/driftdetector/drift_state_manager.py /etc/systemd/system/
driftdetector.service /etc/logrotate.d/driftdetector /etc/sudoers.d/driftdetector /etc/ld.so.conf.d/httpd-lib.conf" }
{ "timestamp":"2026-07-17T04:31:53.955+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"INFO", "appName":"DSM", "appCatCode":"23093",
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"No configuration drift detected" }
{ "timestamp":"2026-07-17T04:31:54.008+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"INFO", "appName":"DSM", "appCatCode":"23093",
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"cac_collection/driftdetector version: v8.2.0-1" }
::
::
::
#
# /home/driftdetector:
#
[root@dsm-ocbdlweb001 /]# ls -ld /home/driftdetector
drwx------ 5 driftdetector driftdetector 4096 Jul 17 04:17 /home/driftdetector
[root@dsm-ocbdlweb001 /]# ls -l /home/driftdetector
-rwx------ 1 driftdetector driftdetector 19011 Jul 17 04:16 drift_state_manager.py
-rwx------ 1 driftdetector driftdetector 11801 Jul 17 04:16 driftdetector.sh
-rwx------ 1 driftdetector driftdetector 1077 Jul 17 04:17 managed_file_list
drw-r--r-- 2 driftdetector driftdetector 4096 Jul 17 03:52 managed_files
drwxr-xr-x 5 driftdetector driftdetector 4096 Jul 17 04:22 managed_files_bkup
drw-r--r-- 2 driftdetector driftdetector 4096 Jul 17 04:16 managed_vars
-rwx------ 1 driftdetector driftdetector 2801 Jul 17 04:16 mq_conf_snapshot.sh
-rwx------ 1 driftdetector driftdetector 2766 Jul 17 04:16 was_conf_snapshot.sh
[root@dsm-ocbdlweb001 /]# cat /home/driftdetector/managed_file_list
git commit: 90c3e3976e0185c0eda5aab39cd79c392d06f950
/home/driftdetector/driftdetector.sh 2fcdb2b242f577aa11dad7a74184c50c89c128d737574e17391b8e0df63a29e7 driftdetector driftdetector 0700
/home/driftdetector/mq_conf_snapshot.sh 443903071acd947c16c6902f8ffdf1a3de516418f5e97bba4b19aeb8cf3756dd driftdetector driftdetector 0700
/home/driftdetector/was_conf_snapshot.sh 9cdb485551c5086e090f31f382abfe3441c5e3437054fe1ae7d6056d18d22f44 driftdetector driftdetector 0700
/home/driftdetector/drift_state_manager.py c3961656018e44535fe22c0af16cebb84f10c6c6e7a278a0678ce09c2e0bb5e6 driftdetector driftdetector 0700
/etc/systemd/system/driftdetector.service d85f6cfb51dde5770f98e110c61d59e6e9824db0caebb4ba73e55a9de8a4db25 root root 0644
/etc/logrotate.d/driftdetector afe59ff2da23c01508b7da627416f147ec5f78baec3e3aba5f36e7e649425b04 root root 0644
/etc/sudoers.d/driftdetector 32a9d728adffe03b02e55b3e7553beb8fb89c3811d1970eb7362192e9efd9d16 root root 0644
/etc/ld.so.conf.d/httpd-lib.conf 38ad47c1c3715ff8ca665e30bb4dba902c18b8a97960106216c53cbca42b1c88 ihsadmin wasgroup 0644
drift in /etc/ld.so.conf.d/httpd-lib.conf file mode change from 0644 to 0744:
#
# /etc/ld.so.conf.d/httpd-lib.conf:
#
[root@dsm-ocbdlweb001 /]# ls -ld /var/log/driftdetector
-rw-r--r-- 1 ihsadmin wasgroup 54 Jul 17 04:17 /etc/ld.so.conf.d/httpd-lib.conf ---file mode: 0644
#
# manually change the file mode to 0744 and check the driftdetector log for ERROR message:
#
[root@dsm-ocbdlweb001 /]# chmod 744 /etc/ld.so.conf.d/httpd-lib.conf
[root@dsm-ocbdlweb001 /]# ls -l /etc/ld.so.conf.d/httpd-lib.conf
-rwxr--r-- 1 ihsadmin wasgroup 54 Jul 17 04:17 /etc/ld.so.conf.d/httpd-lib.conf ---file mode: 0744
(....wait for 5 minutes for driftdetector to run and check the file mode change....)
[root@dsm-ocbdlweb001 /]# grep ERROR /var/log/driftdetector/driftdetector.log
{ "timestamp":"2026-07-17T04:36:54.307+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"ERROR", "appName":"DSM", "appCatCode":"23093",
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"The following 1 object(s) changed! /etc/ld.so.conf.d/httpd-lib.conf" }
{ "timestamp":"2026-07-17T04:36:54.412+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"ERROR", "appName":"DSM", "appCatCode":"23093",
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"Auditd Change Report || /etc/ld.so.conf.d/httpd-lib.conf" }
{ "timestamp":"2026-07-17T04:36:54.447+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"ERROR", "appName":"DSM", "appCatCode":"23093",
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"cp: cannot stat '/var/log/audit/audit.log': No such file or directory\nrm:
cannot remove '/home/driftdetector/latest_audit.log': No such file or directory" }
::
::
Sample playbook for driftdetector baseline manaegement:
[[blue:---]]
[[blue:- name: Drift baseline lifecycle]]
[[blue: hosts: '{{ GROUP_LIMIT }}']]
[[blue: become: true]]
[[blue: gather_facts: false]]
[[blue: collections:]]
[[blue: - nacbsre.cac_collection]]
[[blue:]]
[[blue: tasks:]]
[[blue:]]
[[blue: - name: Fail if neither PATH_TO_MONITOR nor MONITOR_LIST is defined]]
[[blue: ansible.builtin.fail:]]
[[blue: msg: "You must provide either 'PATH_TO_MONITOR' or 'MONITOR_LIST'."]]
[[blue: when: PATH_TO_MONITOR is not defined and MONITOR_LIST is not defined]]
[[blue:]]
[[blue: - name: Manage drift baseline entry (single path)]]
[[blue: nacbsre.cac_collection.driftdetector_baseline:]]
[[blue: state: '{{ STATE | default("present") }}']]
[[blue: path: '{{ PATH_TO_MONITOR }}']]
[[blue: reason: '{{ CHANGE_REASON }}']]
[[blue: when: PATH_TO_MONITOR is defined]]
[[blue:]]
[[blue: - name: Manage drift baseline entries (list of paths)]]
[[blue: nacbsre.cac_collection.driftdetector_baseline:]]
[[blue: state: '{{ STATE | default("present") }}']]
[[blue: path: '{{ item }}']]
[[blue: reason: '{{ CHANGE_REASON }}']]
[[blue: loop: '{{ MONITOR_LIST | default([]) }}']]
[[blue: loop_control:]]
[[blue: label: '{{ item }}']]
Run “single path” baseline update playbook:
[root@dsm-ocbdlweb001 /]# grep "httpd-lib.conf" /home/driftdetector/managed_file_list
/etc/ld.so.conf.d/httpd-lib.conf 38ad47c1c3715ff8ca665e30bb4dba902c18b8a97960106216c53cbca42b1c88 ihsadmin wasgroup [[red:0644]]
[root@dsm-ocbdlweb001 /]# ls -l /etc/ld.so.conf.d/httpd-lib.conf
-rwxr--r-- 1 ihsadmin wasgroup 54 Jul 17 04:17 /etc/ld.so.conf.d/httpd-lib.conf ---file mode: [[red:0744]]
[root@tower NACBSRE_sre_client_app_86039]# ansible-playbook driftdetector_baseline.yml -i inventories/sre_dev \
[[yellow:-e "GROUP_LIMIT=dsm-ocbdlweb001.srv.bmogc.net"]] \
[[yellow:-e "STATE=present"]] \
[[yellow:-e "PATH_TO_MONITOR=/etc/ld.so.conf.d/httpd-lib.conf"]] \
[[yellow:-e "CHANGE_REASON=CHR009" -vvv -D]]
ansible-playbook [core 2.15.13]
config file = /mnt/NACBSRE_sre_client_app_86039/ansible.cfg
configured module search path = ['/root/.ansible/plugins/modules', '/usr/share/ansible/plugins/modules']
ansible python module location = /usr/local/lib/python3.9/site-packages/ansible
ansible collection location = /mnt/NACBSRE_sre_cac_86039:/root/.ansible/collections:/usr/share/ansible/collections
executable location = /usr/local/bin/ansible-playbook
python version = 3.9.25 (main, Jul 13 2026, 00:00:00) [GCC 11.5.0 20240719 (Red Hat 11.5.0-14)] (/usr/bin/python3)
jinja version = 3.1.6
libyaml = True
Using /mnt/NACBSRE_sre_client_app_86039/ansible.cfg as config file
host_list declined parsing /mnt/NACBSRE_sre_client_app_86039/inventories/sre_dev as it did not pass its verify_file() method
script declined parsing /mnt/NACBSRE_sre_client_app_86039/inventories/sre_dev as it did not pass its verify_file() method
auto declined parsing /mnt/NACBSRE_sre_client_app_86039/inventories/sre_dev as it did not pass its verify_file() method
Parsed /mnt/NACBSRE_sre_client_app_86039/inventories/sre_dev inventory source with ini plugin
Skipping callback 'default', as we already have a stdout callback.
Skipping callback 'minimal', as we already have a stdout callback.
Skipping callback 'oneline', as we already have a stdout callback.
PLAYBOOK: driftdetector_baseline.yml ***********************************************************************************************************
1 plays in driftdetector_baseline.yml
PLAY [Drift baseline lifecycle] ****************************************************************************************************************
TASK [Manage drift baseline entries (list of paths)] *******************************************************************************************
task path: /mnt/NACBSRE_sre_client_app_86039/driftdetector_baseline.yml:19
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' dsm-ocbdlweb001.srv.bmogc.net '/bin/sh
-c '"'"'echo ~ && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'/root\n', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' dsm-ocbdlweb001.srv.bmogc.net '/bin/sh
-c '"'"'( umask 77 && mkdir -p "` echo /root/.ansible/tmp `"&& mkdir "` echo /root/.ansible/tmp/ansible-tmp-1784269076.
9424615-3897-131164850853330 `" && echo ansible-tmp-1784269076.9424615-3897-131164850853330="` echo /root/.ansible/tmp/ansible-tmp-1784269076.
9424615-3897-131164850853330 `" ) && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'ansible-tmp-1784269076.9424615-3897-131164850853330=/root/.ansible/tmp/ansible-tmp-1784269076.
9424615-3897-131164850853330\n', b'')
Using module file /mnt/NACBSRE_sre_cac_86039/ansible_collections/nacbsre/cac_collection/plugins/modules/driftdetector_baseline.py
<dsm-ocbdlweb001.srv.bmogc.net> PUT /root/.ansible/tmp/ansible-local-38938c8oat7x/tmppz6hsfny TO /root/.ansible/tmp/ansible-tmp-1784269076.
9424615-3897-131164850853330/AnsiballZ_driftdetector_baseline.py
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC sftp -b - -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' '[dsm-ocbdlweb001.srv.bmogc.net]'
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'sftp> put /root/.ansible/tmp/ansible-local-38938c8oat7x/tmppz6hsfny /root/.ansible/tmp/
ansible-tmp-1784269076.9424615-3897-131164850853330/AnsiballZ_driftdetector_baseline.py\n', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' dsm-ocbdlweb001.srv.bmogc.net '/bin/sh
-c '"'"'chmod u+x /root/.ansible/tmp/ansible-tmp-1784269076.9424615-3897-131164850853330/ /root/.ansible/tmp/ansible-tmp-1784269076.
9424615-3897-131164850853330/AnsiballZ_driftdetector_baseline.py && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' -tt dsm-ocbdlweb001.srv.bmogc.net '/bin/
sh -c '"'"'sudo -H -S -n -u root /bin/sh -c '"'"'"'"'"'"'"'"'echo BECOME-SUCCESS-rqaityjvbnpdmnfjhzfyepyjkxkvndzo ; /usr/bin/python3 /root/.
ansible/tmp/ansible-tmp-1784269076.9424615-3897-131164850853330/AnsiballZ_driftdetector_baseline.py'"'"'"'"'"'"'"'"' && sleep 0'"'"''
Escalation succeeded
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'\r\n{"changed": true, "path": "/etc/ld.so.conf.d/httpd-lib.conf", "operation": "publish", "result":
"changed", "reason": "CHR009", "uid": 1001, "gid": 1001, "owner": "ihsadmin", "group": "wasgroup", "mode": "0744", "state": "file", "size": 54,
invocation": {"module_args": {"state": "present", "path": "/etc/ld.so.conf.d/httpd-lib.conf", "reason": "CHR009", "managed_file_list": "/home/
driftdetector/managed_file_list", "managed_file_list_owner": "driftdetector", "managed_file_list_group": "driftdetector",
"managed_file_list_mode": "0700", "active_check_cmd": null}}}\r\n', b'Shared connection to dsm-ocbdlweb001.srv.bmogc.net closed.\r\n')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' dsm-ocbdlweb001.srv.bmogc.net '/bin/sh
-c '"'"'rm -f -r /root/.ansible/tmp/ansible-tmp-1784269076.9424615-3897-131164850853330/ > /dev/null 2>&1 && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'', b'')
[[yellow:changed: [dsm-ocbdlweb001.srv.bmogc.net] => (item=/etc/ld.so.conf.d/httpd-lib.conf) => {]]
[[yellow: "ansible_loop_var": "item",]]
[[yellow: "changed": true,]]
[[yellow: "gid": 1001,]]
[[yellow: "group": "wasgroup",]]
[[yellow: "invocation": {]]
[[yellow: "module_args": {]]
[[yellow: "active_check_cmd": null,]]
[[yellow: "managed_file_list": "/home/driftdetector/managed_file_list",]]
[[yellow: "managed_file_list_group": "driftdetector",]]
[[yellow: "managed_file_list_mode": "0700",]]
[[yellow: "managed_file_list_owner": "driftdetector",]]
[[yellow: "path": "/etc/ld.so.conf.d/httpd-lib.conf",]]
[[yellow: "reason": "CHR009",]]
[[yellow: "state": "present"]]
[[yellow: }]]
[[yellow: },]]
[[yellow: "item": "/etc/ld.so.conf.d/httpd-lib.conf",]]
[[yellow: "mode": "0744",]]
[[yellow: "operation": "publish",]]
[[yellow: "owner": "ihsadmin",]]
[[yellow: "path": "/etc/ld.so.conf.d/httpd-lib.conf",]]
[[yellow: "reason": "CHR009",]]
[[yellow: "result": "changed",]]
[[yellow: "size": 54,]]
[[yellow: "state": "file",]]
[[yellow: "uid": 1001]]
[[yellow:}]]
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' dsm-ocbdlweb001.srv.bmogc.net '/bin/sh
-c '"'"'echo ~ && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'/root\n', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' dsm-ocbdlweb001.srv.bmogc.net '/bin/sh
-c '"'"'( umask 77 && mkdir -p "` echo /root/.ansible/tmp `"&& mkdir "` echo /root/.ansible/tmp/ansible-tmp-1784269077.
2732308-3897-262802571535240 `" && echo ansible-tmp-1784269077.2732308-3897-262802571535240="` echo /root/.ansible/tmp/ansible-tmp-1784269077.
2732308-3897-262802571535240 `" ) && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'ansible-tmp-1784269077.2732308-3897-262802571535240=/root/.ansible/tmp/ansible-tmp-1784269077.
2732308-3897-262802571535240\n', b'')
Using module file /mnt/NACBSRE_sre_cac_86039/ansible_collections/nacbsre/cac_collection/plugins/modules/driftdetector_baseline.py
<dsm-ocbdlweb001.srv.bmogc.net> PUT /root/.ansible/tmp/ansible-local-38938c8oat7x/tmpnu4rm_zt TO /root/.ansible/tmp/ansible-tmp-1784269077.
2732308-3897-262802571535240/AnsiballZ_driftdetector_baseline.py
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC sftp -b - -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' '[dsm-ocbdlweb001.srv.bmogc.net]'
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'sftp> put /root/.ansible/tmp/ansible-local-38938c8oat7x/tmpnu4rm_zt /root/.ansible/tmp/
ansible-tmp-1784269077.2732308-3897-262802571535240/AnsiballZ_driftdetector_baseline.py\n', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' dsm-ocbdlweb001.srv.bmogc.net '/bin/sh
-c '"'"'chmod u+x /root/.ansible/tmp/ansible-tmp-1784269077.2732308-3897-262802571535240/ /root/.ansible/tmp/ansible-tmp-1784269077.
2732308-3897-262802571535240/AnsiballZ_driftdetector_baseline.py && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' -tt dsm-ocbdlweb001.srv.bmogc.net '/bin/
sh -c '"'"'sudo -H -S -n -u root /bin/sh -c '"'"'"'"'"'"'"'"'echo BECOME-SUCCESS-bxmnpounsjcmfmyxoaygjjrurhmrqnze ; /usr/bin/python3 /root/.
ansible/tmp/ansible-tmp-1784269077.2732308-3897-262802571535240/AnsiballZ_driftdetector_baseline.py'"'"'"'"'"'"'"'"' && sleep 0'"'"''
Escalation succeeded
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'\r\n{"changed": false, "path": "/etc/systemd/system/driftdetector.service", "operation": "publish",
"result": "unchanged", "reason": "CHR009", "uid": 0, "gid": 0, "owner": "root", "group": "root", "mode": "0644", "state": "file", "size": 303,
"invocation": {"module_args": {"state": "present", "path": "/etc/systemd/system/driftdetector.service", "reason": "CHR009", "managed_file_list":
"/home/driftdetector/managed_file_list", "managed_file_list_owner": "driftdetector", "managed_file_list_group": "driftdetector",
"managed_file_list_mode": "0700", "active_check_cmd": null}}}\r\n', b'Shared connection to dsm-ocbdlweb001.srv.bmogc.net closed.\r\n')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' dsm-ocbdlweb001.srv.bmogc.net '/bin/sh
-c '"'"'rm -f -r /root/.ansible/tmp/ansible-tmp-1784269077.2732308-3897-262802571535240/ > /dev/null 2>&1 && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'', b'')
[[green:ok: [dsm-ocbdlweb001.srv.bmogc.net] => (item=/etc/systemd/system/driftdetector.service) => {]]
[[green: "ansible_loop_var": "item",]]
[[green: "changed": false,]]
[[green: "gid": 0,]]
[[green: "group": "root",]]
[[green: "invocation": {]]
[[green: "module_args": {]]
[[green: "active_check_cmd": null,]]
[[green: "managed_file_list": "/home/driftdetector/managed_file_list",]]
[[green: "managed_file_list_group": "driftdetector",]]
[[green: "managed_file_list_mode": "0700",]]
[[green: "managed_file_list_owner": "driftdetector",]]
[[green: "path": "/etc/systemd/system/driftdetector.service",]]
[[green: "reason": "CHR009",]]
[[green: "state": "present"]]
[[green: }]]
[[green: },]]
[[green: "item": "/etc/systemd/system/driftdetector.service",]]
[[green: "mode": "0644",]]
[[green: "operation": "publish",]]
[[green: "owner": "root",]]
[[green: "path": "/etc/systemd/system/driftdetector.service",]]
[[green: "reason": "CHR009",]]
[[green: "result": "unchanged",]]
[[green: "size": 303,]]
[[green: "state": "file",]]
[[green: "uid": 0]]
[[green:}]]
PLAY RECAP ************************************************************************************************************************************************
[[yellow:dsm-ocbdlweb001.srv.bmogc.net]] : [[green:ok=1]] [[yellow:changed=1]] unreachable=0 failed=0 skipped=0 rescued=0 ignored=0
#
# update the baseline for the file mode change to 0744
#
[root@dsm-ocbdlweb001 /]# grep "httpd-lib.conf" /home/driftdetector/managed_file_list
/etc/ld.so.conf.d/httpd-lib.conf 38ad47c1c3715ff8ca665e30bb4dba902c18b8a97960106216c53cbca42b1c88 ihsadmin wasgroup [[red:0744]]
Run “multi paths” baseline update playbook:
[root@dsm-ocbdlweb001 /]# grep "httpd-lib.conf" /home/driftdetector/managed_file_list
/etc/ld.so.conf.d/httpd-lib.conf 38ad47c1c3715ff8ca665e30bb4dba902c18b8a97960106216c53cbca42b1c88 ihsadmin wasgroup [[red:0644]]
[root@dsm-ocbdlweb001 /]# ls -l /etc/ld.so.conf.d/httpd-lib.conf
-rwxr--r-- 1 ihsadmin wasgroup 54 Jul 17 04:17 /etc/ld.so.conf.d/httpd-lib.conf ---file mode: [[red:0744]]
[root@tower NACBSRE_sre_client_app_86039]# ansible-playbook driftdetector_baseline.yml -i inventories/sre_dev \
[[yellow:-e "GROUP_LIMIT=dsm-ocbdlweb001.srv.bmogc.net"]] \
[[yellow:-e "STATE=present"]] \
[[yellow:-e '{"MONITOR_LIST":["/etc/ld.so.conf.d/httpd-lib.conf","/etc/systemd/system/driftdetector.service"]}']] \
[[yellow:-e "CHANGE_REASON=CHR009" -vvv -D]]
ansible-playbook [core 2.15.13]
config file = /mnt/NACBSRE_sre_client_app_86039/ansible.cfg
configured module search path = ['/root/.ansible/plugins/modules', '/usr/share/ansible/plugins/modules']
ansible python module location = /usr/local/lib/python3.9/site-packages/ansible
ansible collection location = /mnt/NACBSRE_sre_cac_86039:/root/.ansible/collections:/usr/share/ansible/collections
executable location = /usr/local/bin/ansible-playbook
python version = 3.9.25 (main, Jul 13 2026, 00:00:00) [GCC 11.5.0 20240719 (Red Hat 11.5.0-14)] (/usr/bin/python3)
jinja version = 3.1.6
libyaml = True
Using /mnt/NACBSRE_sre_client_app_86039/ansible.cfg as config file
host_list declined parsing /mnt/NACBSRE_sre_client_app_86039/inventories/sre_dev as it did not pass its verify_file() method
script declined parsing /mnt/NACBSRE_sre_client_app_86039/inventories/sre_dev as it did not pass its verify_file() method
auto declined parsing /mnt/NACBSRE_sre_client_app_86039/inventories/sre_dev as it did not pass its verify_file() method
Parsed /mnt/NACBSRE_sre_client_app_86039/inventories/sre_dev inventory source with ini plugin
Skipping callback 'default', as we already have a stdout callback.
Skipping callback 'minimal', as we already have a stdout callback.
Skipping callback 'oneline', as we already have a stdout callback.
PLAYBOOK: driftdetector_baseline.yml **********************************************************************************************************************
1 plays in driftdetector_baseline.yml
PLAY [Drift baseline lifecycle] ***************************************************************************************************************************
TASK [Manage drift baseline entries (list of paths)] ******************************************************************************************************
task path: /mnt/NACBSRE_sre_client_app_86039/driftdetector_baseline.yml:19
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"'
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'echo ~ && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'/root\n', b"Warning: Permanently added 'dsm-ocbdlweb001.srv.bmogc.net' (ED25519) to the list of known hosts.\r\n")
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"'
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'( umask 77 && mkdir -p "` echo /root/.ansible/tmp `"&& mkdir "` echo /root/.ansible/tmp/ansible-tmp-1784270293.
5612578-3921-131022480570324 `" && echo ansible-tmp-1784270293.5612578-3921-131022480570324="` echo /root/.ansible/tmp/ansible-tmp-1784270293.5612578-3921-131022480570324 `" ) && sleep
0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'ansible-tmp-1784270293.5612578-3921-131022480570324=/root/.ansible/tmp/ansible-tmp-1784270293.5612578-3921-131022480570324\n', b'')
Using module file /mnt/NACBSRE_sre_cac_86039/ansible_collections/nacbsre/cac_collection/plugins/modules/driftdetector_baseline.py
<dsm-ocbdlweb001.srv.bmogc.net> PUT /root/.ansible/tmp/ansible-local-3917bq2g2pmc/tmpeh7m9gpr TO /root/.ansible/tmp/ansible-tmp-1784270293.5612578-3921-131022480570324/
AnsiballZ_driftdetector_baseline.py
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC sftp -b - -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,
gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/
6bf14df888"' '[dsm-ocbdlweb001.srv.bmogc.net]'
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'sftp> put /root/.ansible/tmp/ansible-local-3917bq2g2pmc/tmpeh7m9gpr /root/.ansible/tmp/ansible-tmp-1784270293.5612578-3921-131022480570324/
AnsiballZ_driftdetector_baseline.py\n', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"'
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'chmod u+x /root/.ansible/tmp/ansible-tmp-1784270293.5612578-3921-131022480570324/ /root/.ansible/tmp/ansible-tmp-1784270293.
5612578-3921-131022480570324/AnsiballZ_driftdetector_baseline.py && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' -tt
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'sudo -H -S -n -u root /bin/sh -c '"'"'"'"'"'"'"'"'echo BECOME-SUCCESS-emmrkhorwrjbitllkgyomllvoltceswa ; /usr/bin/python3 /root/.ansible/
tmp/ansible-tmp-1784270293.5612578-3921-131022480570324/AnsiballZ_driftdetector_baseline.py'"'"'"'"'"'"'"'"' && sleep 0'"'"''
Escalation succeeded
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'\r\n{"changed": true, "path": "/etc/ld.so.conf.d/httpd-lib.conf", "operation": "publish", "result": "changed", "reason": "CHR009", "uid": 1001,
"gid": 1001, "owner": "ihsadmin", "group": "wasgroup", "mode": "0744", "state": "file", "size": 54, "invocation": {"module_args": {"state": "present", "path": "/etc/ld.so.conf.d/
httpd-lib.conf", "reason": "CHR009", "managed_file_list": "/home/driftdetector/managed_file_list", "managed_file_list_owner": "driftdetector", "managed_file_list_group":
"driftdetector", "managed_file_list_mode": "0700", "active_check_cmd": null}}}\r\n', b'Shared connection to dsm-ocbdlweb001.srv.bmogc.net closed.\r\n')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"'
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'rm -f -r /root/.ansible/tmp/ansible-tmp-1784270293.5612578-3921-131022480570324/ > /dev/null 2>&1 && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'', b'')
[[yellow:changed: [dsm-ocbdlweb001.srv.bmogc.net] => (item=/etc/ld.so.conf.d/httpd-lib.conf) => {]]
[[yellow: "ansible_loop_var": "item",]]
[[yellow: "changed": true,]]
[[yellow: "gid": 1001,]]
[[yellow: "group": "wasgroup",]]
[[yellow: "invocation": {]]
[[yellow: "module_args": {]]
[[yellow: "active_check_cmd": null,]]
[[yellow: "managed_file_list": "/home/driftdetector/managed_file_list",]]
[[yellow: "managed_file_list_group": "driftdetector",]]
[[yellow: "managed_file_list_mode": "0700",]]
[[yellow: "managed_file_list_owner": "driftdetector",]]
[[yellow: "path": "/etc/ld.so.conf.d/httpd-lib.conf",]]
[[yellow: "reason": "CHR009",]]
[[yellow: "state": "present"]]
[[yellow: }]]
[[yellow: },]]
[[yellow: "item": "/etc/ld.so.conf.d/httpd-lib.conf",]]
[[yellow: "mode": "0744",]]
[[yellow: "operation": "publish",]]
[[yellow: "owner": "ihsadmin",]]
[[yellow: "path": "/etc/ld.so.conf.d/httpd-lib.conf",]]
[[yellow: "reason": "CHR009",]]
[[yellow: "result": "changed",]]
[[yellow: "size": 54,]]
[[yellow: "state": "file",]]
[[yellow: "uid": 1001]]
[[yellow:}]]
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"'
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'echo ~ && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'/root\n', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"'
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'( umask 77 && mkdir -p "` echo /root/.ansible/tmp `"&& mkdir "` echo /root/.ansible/tmp/ansible-tmp-1784270293.
880835-3921-261444631085189 `" && echo ansible-tmp-1784270293.880835-3921-261444631085189="` echo /root/.ansible/tmp/ansible-tmp-1784270293.880835-3921-261444631085189 `" ) && sleep
0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'ansible-tmp-1784270293.880835-3921-261444631085189=/root/.ansible/tmp/ansible-tmp-1784270293.880835-3921-261444631085189\n', b'')
Using module file /mnt/NACBSRE_sre_cac_86039/ansible_collections/nacbsre/cac_collection/plugins/modules/driftdetector_baseline.py
<dsm-ocbdlweb001.srv.bmogc.net> PUT /root/.ansible/tmp/ansible-local-3917bq2g2pmc/tmp003k1rd7 TO /root/.ansible/tmp/ansible-tmp-1784270293.880835-3921-261444631085189/
AnsiballZ_driftdetector_baseline.py
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC sftp -b - -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,
gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/
6bf14df888"' '[dsm-ocbdlweb001.srv.bmogc.net]'
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'sftp> put /root/.ansible/tmp/ansible-local-3917bq2g2pmc/tmp003k1rd7 /root/.ansible/tmp/ansible-tmp-1784270293.880835-3921-261444631085189/
AnsiballZ_driftdetector_baseline.py\n', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"'
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'chmod u+x /root/.ansible/tmp/ansible-tmp-1784270293.880835-3921-261444631085189/ /root/.ansible/tmp/ansible-tmp-1784270293.
880835-3921-261444631085189/AnsiballZ_driftdetector_baseline.py && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' -tt
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'sudo -H -S -n -u root /bin/sh -c '"'"'"'"'"'"'"'"'echo BECOME-SUCCESS-mljlxpauklzdzjwzgomassyzafuxemfs ; /usr/bin/python3 /root/.ansible/
tmp/ansible-tmp-1784270293.880835-3921-261444631085189/AnsiballZ_driftdetector_baseline.py'"'"'"'"'"'"'"'"' && sleep 0'"'"''
Escalation succeeded
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'\r\n{"changed": false, "path": "/etc/systemd/system/driftdetector.service", "operation": "publish", "result": "unchanged", "reason": "CHR009",
"uid": 0, "gid": 0, "owner": "root", "group": "root", "mode": "0644", "state": "file", "size": 303, "invocation": {"module_args": {"state": "present", "path": "/etc/systemd/system/
driftdetector.service", "reason": "CHR009", "managed_file_list": "/home/driftdetector/managed_file_list", "managed_file_list_owner": "driftdetector", "managed_file_list_group":
"driftdetector", "managed_file_list_mode": "0700", "active_check_cmd": null}}}\r\n', b'Shared connection to dsm-ocbdlweb001.srv.bmogc.net closed.\r\n')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"'
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'rm -f -r /root/.ansible/tmp/ansible-tmp-1784270293.880835-3921-261444631085189/ > /dev/null 2>&1 && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'', b'')
[[green:ok: [dsm-ocbdlweb001.srv.bmogc.net] => (item=/etc/systemd/system/driftdetector.service) => {]]
[[green: "ansible_loop_var": "item",]]
[[green: "changed": false,]]
[[green: "gid": 0,]]
[[green: "group": "root",]]
[[green: "invocation": {]]
[[green: "module_args": {]]
[[green: "active_check_cmd": null,]]
[[green: "managed_file_list": "/home/driftdetector/managed_file_list",]]
[[green: "managed_file_list_group": "driftdetector",]]
[[green: "managed_file_list_mode": "0700",]]
[[green: "managed_file_list_owner": "driftdetector",]]
[[green: "path": "/etc/systemd/system/driftdetector.service",]]
[[green: "reason": "CHR009",]]
[[green: "state": "present"]]
[[green: }]]
[[green: },]]
[[green: "item": "/etc/systemd/system/driftdetector.service",]]
[[green: "mode": "0644",]]
[[green: "operation": "publish",]]
[[green: "owner": "root",]]
[[green: "path": "/etc/systemd/system/driftdetector.service",]]
[[green: "reason": "CHR009",]]
[[green: "result": "unchanged",]]
[[green: "size": 303,]]
[[green: "state": "file",]]
[[green: "uid": 0]]
[[green:}]]
PLAY RECAP ************************************************************************************************************************************************
[[yellow:dsm-ocbdlweb001.srv.bmogc.net]] : [[green:ok=1]] [[yellow:changed=1]] unreachable=0 failed=0 skipped=0 rescued=0 ignored=0
To define MONITOR_LIST:
#
# 1. passing as --extra-vars (-e) via CLI in JSON format:
#
[root@tower NACBSRE_sre_client_app_86039]# ansible-playbook driftdetector_baseline.yml -i inventories/sre_dev \
[[yellow:-e "GROUP_LIMIT=my_host_group"]] \
[[yellow:-e "STATE=present"]] \
[[yellow:-e '{"MONITOR_LIST":["/etc/ssh/sshd_config","/etc/resolv.conf"]}']] \
[[yellow:-e "CHANGE_REASON=CHR009" -vvv -D]]
#
# not preferred, but can also be done in YAML format:
#
[root@tower NACBSRE_sre_client_app_86039]# ansible-playbook driftdetector_baseline.yml -i inventories/sre_dev \
[[yellow:-e "GROUP_LIMIT=my_host_group"]] \
[[yellow:-e "STATE=present"]] \
[[yellow:-e "MONITOR_LIST=['/etc/ssh/sshd_config', '/etc/resolv.conf']"]]
[[yellow:-e "CHANGE_REASON=CHR009" -vvv -D]]
#
# 2. defining in host)vars or group_vars:
#
::
::
[[blue:MONITOR_LIST:]]
[[blue:- /etc/ssh/sshd_config]]
[[blue:- /etc/resolv.conf]]
[[blue:- /etc/hosts]]
::
::
#
# 3. defining directly in an inventory File (INI format):
#
::
::
[[blue:[webservers]]]
[[blue:webserver1 MONITOR_LIST='["/var/www/html/index.html", "/etc/nginx/nginx.conf"]']]
[[blue:webserver2 MONITOR_LIST='["/var/www/html/index.html"]']]
::
::