Driftdetector baseline management:

[root@dsm-ocbdlweb001 ~]# hostname -f
dsm-ocbdlweb001.srv.bmogc.net

#
# drifrtdetector daemon:
#
[root@dsm-ocbdlweb001 ~]# systemctl status driftdetector.service
[[green:●]] driftdetector.service - driftdetector, Ansible configuration drift detection
     Loaded: loaded (/etc/systemd/system/driftdetector.service; enabled; preset: disabled)
     Active: [[green:active (running)]] since Thu 2026-07-16 21:00:50 UTC; 6h ago
   Main PID: 45304 (driftdetector.s)
      Tasks: 2 (limit: 15343)
     Memory: 3.1M (limit: 10.0M peak: 10.0M)
        CPU: 24.614s
     CGroup: /system.slice/driftdetector.service
             ├─45304 /bin/bash /home/driftdetector/driftdetector.sh
             └─64636 /usr/bin/coreutils --coreutils-prog-shebang=sleep /usr/bin/sleep 300
Jul 17 03:11:21 dsm-ocbdlweb001.srv.bmogc.net sudo[64497]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=1000)
Jul 17 03:11:21 dsm-ocbdlweb001.srv.bmogc.net sudo[64497]: pam_unix(sudo:session): session closed for user root
Jul 17 03:11:21 dsm-ocbdlweb001.srv.bmogc.net sudo[64500]: driftdetector : PWD=/ ; USER=root ; 
COMMAND=/bin/stat -c '/etc/ld.so.conf.d/httpd-lib.conf: %F %U %G %a' /etc/ld.so.conf.>
Jul 17 03:11:21 dsm-ocbdlweb001.srv.bmogc.net sudo[64500]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=1000)
Jul 17 03:11:21 dsm-ocbdlweb001.srv.bmogc.net sudo[64500]: pam_unix(sudo:session): session closed for user root
Jul 17 03:11:21 dsm-ocbdlweb001.srv.bmogc.net sudo[64506]: driftdetector : PWD=/ ; USER=root ; COMMAND=/bin/sha256sum /home/driftdetector/driftdetector.sh /home/driftdetector/mq_co>
Jul 17 03:11:21 dsm-ocbdlweb001.srv.bmogc.net sudo[64506]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=1000)
Jul 17 03:11:21 dsm-ocbdlweb001.srv.bmogc.net sudo[64506]: pam_unix(sudo:session): session closed for user root

[root@dsm-ocbdlweb001 /]# ps -aux | grep [d]riftdetector
driftde+   13948  0.0  0.0   5252  3504 ?        Ss   04:16   0:00 /bin/bash /home/driftdetector/driftdetector.sh

#
# /var/log/driftdetector:
#
[root@dsm-ocbdlweb001 /]# ls -ld /var/log/driftdetector
drwxr-xr-x 2 driftdetector driftdetector 4096 Jul 17 04:16 /var/log/driftdetector
[root@dsm-ocbdlweb001 /]# ls -l /var/log/driftdetector
-rw-r--r-- 1 driftdetector driftdetector 3003 Jul 17 04:26 driftdetector.log

[root@dsm-ocbdlweb001 /]# tail -f /var/log/driftdetector/driftdetector.log
{"timestamp": "2026-07-17T04:17:00", "host": "dsm-ocbdlweb001.srv.bmogc.net", "logLevel": "INFO", "appName": "DSM", "appCatCode": "23093", 
"serviceName": "ansible", "additionalInfo": {"job_count_today": 1, "job_list": [{"tower_job_id": "dummyIDforLocalTest", "tower_user_name": 
"dummyUserforLocalTest", "ansible_check_mode": "False"}]}}
{ "timestamp":"2026-07-17T04:21:53.341+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"INFO", "appName":"DSM", "appCatCode":"23093", 
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"Total 8 objects checked: /home/driftdetector/driftdetector.sh /home/
driftdetector/mq_conf_snapshot.sh /home/driftdetector/was_conf_snapshot.sh /home/driftdetector/drift_state_manager.py /etc/systemd/system/
driftdetector.service /etc/logrotate.d/driftdetector /etc/sudoers.d/driftdetector /etc/ld.so.conf.d/httpd-lib.conf" }
{ "timestamp":"2026-07-17T04:21:53.342+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"INFO", "appName":"DSM", "appCatCode":"23093", 
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"No configuration drift detected" }
{ "timestamp":"2026-07-17T04:21:53.382+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"INFO", "appName":"DSM", "appCatCode":"23093", 
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"cac_collection/driftdetector version: v8.2.0-1" }
{ "timestamp":"2026-07-17T04:26:53.628+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"INFO", "appName":"DSM", "appCatCode":"23093", 
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"Total 8 objects checked: /home/driftdetector/driftdetector.sh /home/
driftdetector/mq_conf_snapshot.sh /home/driftdetector/was_conf_snapshot.sh /home/driftdetector/drift_state_manager.py /etc/systemd/system/
driftdetector.service /etc/logrotate.d/driftdetector /etc/sudoers.d/driftdetector /etc/ld.so.conf.d/httpd-lib.conf" }
{ "timestamp":"2026-07-17T04:26:53.630+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"INFO", "appName":"DSM", "appCatCode":"23093", 
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"No configuration drift detected" }
{ "timestamp":"2026-07-17T04:26:53.713+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"INFO", "appName":"DSM", "appCatCode":"23093", 
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"cac_collection/driftdetector version: v8.2.0-1" }
{ "timestamp":"2026-07-17T04:31:53.953+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"INFO", "appName":"DSM", "appCatCode":"23093", 
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"Total 8 objects checked: /home/driftdetector/driftdetector.sh /home/
driftdetector/mq_conf_snapshot.sh /home/driftdetector/was_conf_snapshot.sh /home/driftdetector/drift_state_manager.py /etc/systemd/system/
driftdetector.service /etc/logrotate.d/driftdetector /etc/sudoers.d/driftdetector /etc/ld.so.conf.d/httpd-lib.conf" }
{ "timestamp":"2026-07-17T04:31:53.955+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"INFO", "appName":"DSM", "appCatCode":"23093", 
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"No configuration drift detected" }
{ "timestamp":"2026-07-17T04:31:54.008+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"INFO", "appName":"DSM", "appCatCode":"23093", 
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"cac_collection/driftdetector version: v8.2.0-1" }
::
::
::

#
# /home/driftdetector:
#
[root@dsm-ocbdlweb001 /]# ls -ld /home/driftdetector
drwx------ 5 driftdetector driftdetector 4096 Jul 17 04:17 /home/driftdetector
[root@dsm-ocbdlweb001 /]# ls -l /home/driftdetector
-rwx------ 1 driftdetector driftdetector 19011 Jul 17 04:16 drift_state_manager.py
-rwx------ 1 driftdetector driftdetector 11801 Jul 17 04:16 driftdetector.sh
-rwx------ 1 driftdetector driftdetector  1077 Jul 17 04:17 managed_file_list
drw-r--r-- 2 driftdetector driftdetector  4096 Jul 17 03:52 managed_files
drwxr-xr-x 5 driftdetector driftdetector  4096 Jul 17 04:22 managed_files_bkup
drw-r--r-- 2 driftdetector driftdetector  4096 Jul 17 04:16 managed_vars
-rwx------ 1 driftdetector driftdetector  2801 Jul 17 04:16 mq_conf_snapshot.sh
-rwx------ 1 driftdetector driftdetector  2766 Jul 17 04:16 was_conf_snapshot.sh

[root@dsm-ocbdlweb001 /]# cat /home/driftdetector/managed_file_list
git commit: 90c3e3976e0185c0eda5aab39cd79c392d06f950
/home/driftdetector/driftdetector.sh 2fcdb2b242f577aa11dad7a74184c50c89c128d737574e17391b8e0df63a29e7 driftdetector driftdetector 0700 
/home/driftdetector/mq_conf_snapshot.sh 443903071acd947c16c6902f8ffdf1a3de516418f5e97bba4b19aeb8cf3756dd driftdetector driftdetector 0700 
/home/driftdetector/was_conf_snapshot.sh 9cdb485551c5086e090f31f382abfe3441c5e3437054fe1ae7d6056d18d22f44 driftdetector driftdetector 0700 
/home/driftdetector/drift_state_manager.py c3961656018e44535fe22c0af16cebb84f10c6c6e7a278a0678ce09c2e0bb5e6 driftdetector driftdetector 0700 
/etc/systemd/system/driftdetector.service d85f6cfb51dde5770f98e110c61d59e6e9824db0caebb4ba73e55a9de8a4db25 root root 0644 
/etc/logrotate.d/driftdetector afe59ff2da23c01508b7da627416f147ec5f78baec3e3aba5f36e7e649425b04 root root 0644 
/etc/sudoers.d/driftdetector 32a9d728adffe03b02e55b3e7553beb8fb89c3811d1970eb7362192e9efd9d16 root root 0644 
/etc/ld.so.conf.d/httpd-lib.conf 38ad47c1c3715ff8ca665e30bb4dba902c18b8a97960106216c53cbca42b1c88 ihsadmin wasgroup 0644

drift in /etc/ld.so.conf.d/httpd-lib.conf file mode change from 0644 to 0744:

#
# /etc/ld.so.conf.d/httpd-lib.conf:
#
[root@dsm-ocbdlweb001 /]# ls -ld /var/log/driftdetector
-rw-r--r-- 1 ihsadmin wasgroup 54 Jul 17 04:17 /etc/ld.so.conf.d/httpd-lib.conf                              ---file mode: 0644

#
# manually change the file mode to 0744 and check the driftdetector log for ERROR message:
#
[root@dsm-ocbdlweb001 /]# chmod 744 /etc/ld.so.conf.d/httpd-lib.conf

[root@dsm-ocbdlweb001 /]# ls -l /etc/ld.so.conf.d/httpd-lib.conf
-rwxr--r-- 1 ihsadmin wasgroup 54 Jul 17 04:17 /etc/ld.so.conf.d/httpd-lib.conf                              ---file mode: 0744

(....wait for 5 minutes for driftdetector to run and check the file mode change....)

[root@dsm-ocbdlweb001 /]# grep ERROR /var/log/driftdetector/driftdetector.log
{ "timestamp":"2026-07-17T04:36:54.307+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"ERROR", "appName":"DSM", "appCatCode":"23093", 
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"The following 1 object(s) changed! /etc/ld.so.conf.d/httpd-lib.conf" }
{ "timestamp":"2026-07-17T04:36:54.412+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"ERROR", "appName":"DSM", "appCatCode":"23093", 
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"Auditd Change Report || /etc/ld.so.conf.d/httpd-lib.conf" }
{ "timestamp":"2026-07-17T04:36:54.447+00:00", "host":"dsm-ocbdlweb001.srv.bmogc.net", "logLevel":"ERROR", "appName":"DSM", "appCatCode":"23093", 
"email":"undefined", "serviceName":"driftdetector", "additionalInfo":"cp: cannot stat '/var/log/audit/audit.log': No such file or directory\nrm: 
cannot remove '/home/driftdetector/latest_audit.log': No such file or directory" }
::
::

Sample playbook for driftdetector baseline manaegement:

[[blue:---]]
[[blue:- name: Drift baseline lifecycle]]
[[blue:  hosts: '{{ GROUP_LIMIT }}']]
[[blue:  become: true]]
[[blue:  gather_facts: false]]
[[blue:  collections:]]
[[blue:    - nacbsre.cac_collection]]
[[blue:]]
[[blue:  tasks:]]
[[blue:]]
[[blue:    - name: Fail if neither PATH_TO_MONITOR nor MONITOR_LIST is defined]]
[[blue:      ansible.builtin.fail:]]
[[blue:        msg: "You must provide either 'PATH_TO_MONITOR' or 'MONITOR_LIST'."]]
[[blue:      when: PATH_TO_MONITOR is not defined and MONITOR_LIST is not defined]]
[[blue:]]
[[blue:    - name: Manage drift baseline entry (single path)]]
[[blue:      nacbsre.cac_collection.driftdetector_baseline:]]
[[blue:        state: '{{ STATE | default("present") }}']]
[[blue:        path: '{{ PATH_TO_MONITOR }}']]
[[blue:        reason: '{{ CHANGE_REASON }}']]
[[blue:      when: PATH_TO_MONITOR is defined]]
[[blue:]]
[[blue:    - name: Manage drift baseline entries (list of paths)]]
[[blue:      nacbsre.cac_collection.driftdetector_baseline:]]
[[blue:        state: '{{ STATE | default("present") }}']]
[[blue:        path: '{{ item }}']]
[[blue:        reason: '{{ CHANGE_REASON }}']]
[[blue:      loop: '{{ MONITOR_LIST | default([]) }}']]
[[blue:      loop_control:]]
[[blue:        label: '{{ item }}']]

Run “single path” baseline update playbook:

[root@dsm-ocbdlweb001 /]# grep "httpd-lib.conf" /home/driftdetector/managed_file_list
/etc/ld.so.conf.d/httpd-lib.conf 38ad47c1c3715ff8ca665e30bb4dba902c18b8a97960106216c53cbca42b1c88 ihsadmin wasgroup [[red:0644]]

[root@dsm-ocbdlweb001 /]# ls -l /etc/ld.so.conf.d/httpd-lib.conf
-rwxr--r-- 1 ihsadmin wasgroup 54 Jul 17 04:17 /etc/ld.so.conf.d/httpd-lib.conf                              ---file mode: [[red:0744]]

[root@tower NACBSRE_sre_client_app_86039]# ansible-playbook driftdetector_baseline.yml -i inventories/sre_dev \
                                           [[yellow:-e "GROUP_LIMIT=dsm-ocbdlweb001.srv.bmogc.net"]]                     \
                                           [[yellow:-e "STATE=present"]]                                                 \
                                           [[yellow:-e "PATH_TO_MONITOR=/etc/ld.so.conf.d/httpd-lib.conf"]]              \
                                           [[yellow:-e "CHANGE_REASON=CHR009" -vvv -D]]
ansible-playbook [core 2.15.13]
  config file = /mnt/NACBSRE_sre_client_app_86039/ansible.cfg
  configured module search path = ['/root/.ansible/plugins/modules', '/usr/share/ansible/plugins/modules']
  ansible python module location = /usr/local/lib/python3.9/site-packages/ansible
  ansible collection location = /mnt/NACBSRE_sre_cac_86039:/root/.ansible/collections:/usr/share/ansible/collections
  executable location = /usr/local/bin/ansible-playbook
  python version = 3.9.25 (main, Jul 13 2026, 00:00:00) [GCC 11.5.0 20240719 (Red Hat 11.5.0-14)] (/usr/bin/python3)
  jinja version = 3.1.6
  libyaml = True
Using /mnt/NACBSRE_sre_client_app_86039/ansible.cfg as config file
host_list declined parsing /mnt/NACBSRE_sre_client_app_86039/inventories/sre_dev as it did not pass its verify_file() method
script declined parsing /mnt/NACBSRE_sre_client_app_86039/inventories/sre_dev as it did not pass its verify_file() method
auto declined parsing /mnt/NACBSRE_sre_client_app_86039/inventories/sre_dev as it did not pass its verify_file() method
Parsed /mnt/NACBSRE_sre_client_app_86039/inventories/sre_dev inventory source with ini plugin
Skipping callback 'default', as we already have a stdout callback.
Skipping callback 'minimal', as we already have a stdout callback.
Skipping callback 'oneline', as we already have a stdout callback.
PLAYBOOK: driftdetector_baseline.yml ***********************************************************************************************************
1 plays in driftdetector_baseline.yml
PLAY [Drift baseline lifecycle] ****************************************************************************************************************
TASK [Manage drift baseline entries (list of paths)] *******************************************************************************************
task path: /mnt/NACBSRE_sre_client_app_86039/driftdetector_baseline.yml:19
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o 
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o 
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' dsm-ocbdlweb001.srv.bmogc.net '/bin/sh 
-c '"'"'echo ~ && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'/root\n', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o 
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o 
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' dsm-ocbdlweb001.srv.bmogc.net '/bin/sh 
-c '"'"'( umask 77 && mkdir -p "` echo /root/.ansible/tmp `"&& mkdir "` echo /root/.ansible/tmp/ansible-tmp-1784269076.
9424615-3897-131164850853330 `" && echo ansible-tmp-1784269076.9424615-3897-131164850853330="` echo /root/.ansible/tmp/ansible-tmp-1784269076.
9424615-3897-131164850853330 `" ) && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'ansible-tmp-1784269076.9424615-3897-131164850853330=/root/.ansible/tmp/ansible-tmp-1784269076.
9424615-3897-131164850853330\n', b'')
Using module file /mnt/NACBSRE_sre_cac_86039/ansible_collections/nacbsre/cac_collection/plugins/modules/driftdetector_baseline.py
<dsm-ocbdlweb001.srv.bmogc.net> PUT /root/.ansible/tmp/ansible-local-38938c8oat7x/tmppz6hsfny TO /root/.ansible/tmp/ansible-tmp-1784269076.
9424615-3897-131164850853330/AnsiballZ_driftdetector_baseline.py
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC sftp -b - -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o 
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o 
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' '[dsm-ocbdlweb001.srv.bmogc.net]'
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'sftp> put /root/.ansible/tmp/ansible-local-38938c8oat7x/tmppz6hsfny /root/.ansible/tmp/
ansible-tmp-1784269076.9424615-3897-131164850853330/AnsiballZ_driftdetector_baseline.py\n', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o 
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o 
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' dsm-ocbdlweb001.srv.bmogc.net '/bin/sh 
-c '"'"'chmod u+x /root/.ansible/tmp/ansible-tmp-1784269076.9424615-3897-131164850853330/ /root/.ansible/tmp/ansible-tmp-1784269076.
9424615-3897-131164850853330/AnsiballZ_driftdetector_baseline.py && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o 
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o 
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' -tt dsm-ocbdlweb001.srv.bmogc.net '/bin/
sh -c '"'"'sudo -H -S -n  -u root /bin/sh -c '"'"'"'"'"'"'"'"'echo BECOME-SUCCESS-rqaityjvbnpdmnfjhzfyepyjkxkvndzo ; /usr/bin/python3 /root/.
ansible/tmp/ansible-tmp-1784269076.9424615-3897-131164850853330/AnsiballZ_driftdetector_baseline.py'"'"'"'"'"'"'"'"' && sleep 0'"'"''
Escalation succeeded
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'\r\n{"changed": true, "path": "/etc/ld.so.conf.d/httpd-lib.conf", "operation": "publish", "result": 
"changed", "reason": "CHR009", "uid": 1001, "gid": 1001, "owner": "ihsadmin", "group": "wasgroup", "mode": "0744", "state": "file", "size": 54, 
invocation": {"module_args": {"state": "present", "path": "/etc/ld.so.conf.d/httpd-lib.conf", "reason": "CHR009", "managed_file_list": "/home/
driftdetector/managed_file_list", "managed_file_list_owner": "driftdetector", "managed_file_list_group": "driftdetector",
"managed_file_list_mode": "0700", "active_check_cmd": null}}}\r\n', b'Shared connection to dsm-ocbdlweb001.srv.bmogc.net closed.\r\n')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o 
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o 
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' dsm-ocbdlweb001.srv.bmogc.net '/bin/sh
-c '"'"'rm -f -r /root/.ansible/tmp/ansible-tmp-1784269076.9424615-3897-131164850853330/ > /dev/null 2>&1 && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'', b'')
[[yellow:changed: [dsm-ocbdlweb001.srv.bmogc.net] => (item=/etc/ld.so.conf.d/httpd-lib.conf) => {]]
[[yellow:    "ansible_loop_var": "item",]]
[[yellow:    "changed": true,]]
[[yellow:    "gid": 1001,]]
[[yellow:    "group": "wasgroup",]]
[[yellow:    "invocation": {]]
[[yellow:        "module_args": {]]
[[yellow:            "active_check_cmd": null,]]
[[yellow:            "managed_file_list": "/home/driftdetector/managed_file_list",]]
[[yellow:            "managed_file_list_group": "driftdetector",]]
[[yellow:            "managed_file_list_mode": "0700",]]
[[yellow:            "managed_file_list_owner": "driftdetector",]]
[[yellow:            "path": "/etc/ld.so.conf.d/httpd-lib.conf",]]
[[yellow:            "reason": "CHR009",]]
[[yellow:            "state": "present"]]
[[yellow:        }]]
[[yellow:    },]]
[[yellow:    "item": "/etc/ld.so.conf.d/httpd-lib.conf",]]
[[yellow:    "mode": "0744",]]
[[yellow:    "operation": "publish",]]
[[yellow:    "owner": "ihsadmin",]]
[[yellow:    "path": "/etc/ld.so.conf.d/httpd-lib.conf",]]
[[yellow:    "reason": "CHR009",]]
[[yellow:    "result": "changed",]]
[[yellow:    "size": 54,]]
[[yellow:    "state": "file",]]
[[yellow:    "uid": 1001]]
[[yellow:}]]
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o 
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o 
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' dsm-ocbdlweb001.srv.bmogc.net '/bin/sh 
-c '"'"'echo ~ && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'/root\n', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o 
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o 
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' dsm-ocbdlweb001.srv.bmogc.net '/bin/sh 
-c '"'"'( umask 77 && mkdir -p "` echo /root/.ansible/tmp `"&& mkdir "` echo /root/.ansible/tmp/ansible-tmp-1784269077.
2732308-3897-262802571535240 `" && echo ansible-tmp-1784269077.2732308-3897-262802571535240="` echo /root/.ansible/tmp/ansible-tmp-1784269077.
2732308-3897-262802571535240 `" ) && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'ansible-tmp-1784269077.2732308-3897-262802571535240=/root/.ansible/tmp/ansible-tmp-1784269077.
2732308-3897-262802571535240\n', b'')
Using module file /mnt/NACBSRE_sre_cac_86039/ansible_collections/nacbsre/cac_collection/plugins/modules/driftdetector_baseline.py
<dsm-ocbdlweb001.srv.bmogc.net> PUT /root/.ansible/tmp/ansible-local-38938c8oat7x/tmpnu4rm_zt TO /root/.ansible/tmp/ansible-tmp-1784269077.
2732308-3897-262802571535240/AnsiballZ_driftdetector_baseline.py
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC sftp -b - -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o 
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o 
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' '[dsm-ocbdlweb001.srv.bmogc.net]'
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'sftp> put /root/.ansible/tmp/ansible-local-38938c8oat7x/tmpnu4rm_zt /root/.ansible/tmp/
ansible-tmp-1784269077.2732308-3897-262802571535240/AnsiballZ_driftdetector_baseline.py\n', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o 
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o 
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' dsm-ocbdlweb001.srv.bmogc.net '/bin/sh 
-c '"'"'chmod u+x /root/.ansible/tmp/ansible-tmp-1784269077.2732308-3897-262802571535240/ /root/.ansible/tmp/ansible-tmp-1784269077.
2732308-3897-262802571535240/AnsiballZ_driftdetector_baseline.py && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o 
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o 
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' -tt dsm-ocbdlweb001.srv.bmogc.net '/bin/
sh -c '"'"'sudo -H -S -n  -u root /bin/sh -c '"'"'"'"'"'"'"'"'echo BECOME-SUCCESS-bxmnpounsjcmfmyxoaygjjrurhmrqnze ; /usr/bin/python3 /root/.
ansible/tmp/ansible-tmp-1784269077.2732308-3897-262802571535240/AnsiballZ_driftdetector_baseline.py'"'"'"'"'"'"'"'"' && sleep 0'"'"''
Escalation succeeded
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'\r\n{"changed": false, "path": "/etc/systemd/system/driftdetector.service", "operation": "publish", 
"result": "unchanged", "reason": "CHR009", "uid": 0, "gid": 0, "owner": "root", "group": "root", "mode": "0644", "state": "file", "size": 303, 
"invocation": {"module_args": {"state": "present", "path": "/etc/systemd/system/driftdetector.service", "reason": "CHR009", "managed_file_list": 
"/home/driftdetector/managed_file_list", "managed_file_list_owner": "driftdetector", "managed_file_list_group": "driftdetector", 
"managed_file_list_mode": "0700", "active_check_cmd": null}}}\r\n', b'Shared connection to dsm-ocbdlweb001.srv.bmogc.net closed.\r\n')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o 
PreferredAuthentications=gssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o 
StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' dsm-ocbdlweb001.srv.bmogc.net '/bin/sh 
-c '"'"'rm -f -r /root/.ansible/tmp/ansible-tmp-1784269077.2732308-3897-262802571535240/ > /dev/null 2>&1 && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'', b'')
[[green:ok: [dsm-ocbdlweb001.srv.bmogc.net] => (item=/etc/systemd/system/driftdetector.service) => {]]
[[green:    "ansible_loop_var": "item",]]
[[green:    "changed": false,]]
[[green:    "gid": 0,]]
[[green:    "group": "root",]]
[[green:    "invocation": {]]
[[green:        "module_args": {]]
[[green:            "active_check_cmd": null,]]
[[green:            "managed_file_list": "/home/driftdetector/managed_file_list",]]
[[green:            "managed_file_list_group": "driftdetector",]]
[[green:            "managed_file_list_mode": "0700",]]
[[green:            "managed_file_list_owner": "driftdetector",]]
[[green:            "path": "/etc/systemd/system/driftdetector.service",]]
[[green:            "reason": "CHR009",]]
[[green:            "state": "present"]]
[[green:        }]]
[[green:    },]]
[[green:    "item": "/etc/systemd/system/driftdetector.service",]]
[[green:    "mode": "0644",]]
[[green:    "operation": "publish",]]
[[green:    "owner": "root",]]
[[green:    "path": "/etc/systemd/system/driftdetector.service",]]
[[green:    "reason": "CHR009",]]
[[green:    "result": "unchanged",]]
[[green:    "size": 303,]]
[[green:    "state": "file",]]
[[green:    "uid": 0]]
[[green:}]]
PLAY RECAP ************************************************************************************************************************************************
[[yellow:dsm-ocbdlweb001.srv.bmogc.net]] : [[green:ok=1]]    [[yellow:changed=1]]    unreachable=0    failed=0    skipped=0    rescued=0    ignored=0   

#
# update the baseline for the file mode change to 0744
#
[root@dsm-ocbdlweb001 /]# grep "httpd-lib.conf" /home/driftdetector/managed_file_list
/etc/ld.so.conf.d/httpd-lib.conf 38ad47c1c3715ff8ca665e30bb4dba902c18b8a97960106216c53cbca42b1c88 ihsadmin wasgroup [[red:0744]]

Run “multi paths” baseline update playbook:

[root@dsm-ocbdlweb001 /]# grep "httpd-lib.conf" /home/driftdetector/managed_file_list
/etc/ld.so.conf.d/httpd-lib.conf 38ad47c1c3715ff8ca665e30bb4dba902c18b8a97960106216c53cbca42b1c88 ihsadmin wasgroup [[red:0644]]

[root@dsm-ocbdlweb001 /]# ls -l /etc/ld.so.conf.d/httpd-lib.conf
-rwxr--r-- 1 ihsadmin wasgroup 54 Jul 17 04:17 /etc/ld.so.conf.d/httpd-lib.conf                              ---file mode: [[red:0744]]

[root@tower NACBSRE_sre_client_app_86039]# ansible-playbook driftdetector_baseline.yml -i inventories/sre_dev                                         \
                                           [[yellow:-e "GROUP_LIMIT=dsm-ocbdlweb001.srv.bmogc.net"]]                                                             \
                                           [[yellow:-e "STATE=present"]]                                                                                         \
                                           [[yellow:-e '{"MONITOR_LIST":["/etc/ld.so.conf.d/httpd-lib.conf","/etc/systemd/system/driftdetector.service"]}']]     \
                                           [[yellow:-e "CHANGE_REASON=CHR009" -vvv -D]]
ansible-playbook [core 2.15.13]
  config file = /mnt/NACBSRE_sre_client_app_86039/ansible.cfg
  configured module search path = ['/root/.ansible/plugins/modules', '/usr/share/ansible/plugins/modules']
  ansible python module location = /usr/local/lib/python3.9/site-packages/ansible
  ansible collection location = /mnt/NACBSRE_sre_cac_86039:/root/.ansible/collections:/usr/share/ansible/collections
  executable location = /usr/local/bin/ansible-playbook
  python version = 3.9.25 (main, Jul 13 2026, 00:00:00) [GCC 11.5.0 20240719 (Red Hat 11.5.0-14)] (/usr/bin/python3)
  jinja version = 3.1.6
  libyaml = True
Using /mnt/NACBSRE_sre_client_app_86039/ansible.cfg as config file
host_list declined parsing /mnt/NACBSRE_sre_client_app_86039/inventories/sre_dev as it did not pass its verify_file() method
script declined parsing /mnt/NACBSRE_sre_client_app_86039/inventories/sre_dev as it did not pass its verify_file() method
auto declined parsing /mnt/NACBSRE_sre_client_app_86039/inventories/sre_dev as it did not pass its verify_file() method
Parsed /mnt/NACBSRE_sre_client_app_86039/inventories/sre_dev inventory source with ini plugin
Skipping callback 'default', as we already have a stdout callback.
Skipping callback 'minimal', as we already have a stdout callback.
Skipping callback 'oneline', as we already have a stdout callback.
PLAYBOOK: driftdetector_baseline.yml **********************************************************************************************************************
1 plays in driftdetector_baseline.yml
PLAY [Drift baseline lifecycle] ***************************************************************************************************************************
TASK [Manage drift baseline entries (list of paths)] ******************************************************************************************************
task path: /mnt/NACBSRE_sre_client_app_86039/driftdetector_baseline.yml:19
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' 
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'echo ~ && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'/root\n', b"Warning: Permanently added 'dsm-ocbdlweb001.srv.bmogc.net' (ED25519) to the list of known hosts.\r\n")
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' 
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'( umask 77 && mkdir -p "` echo /root/.ansible/tmp `"&& mkdir "` echo /root/.ansible/tmp/ansible-tmp-1784270293.
5612578-3921-131022480570324 `" && echo ansible-tmp-1784270293.5612578-3921-131022480570324="` echo /root/.ansible/tmp/ansible-tmp-1784270293.5612578-3921-131022480570324 `" ) && sleep 
0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'ansible-tmp-1784270293.5612578-3921-131022480570324=/root/.ansible/tmp/ansible-tmp-1784270293.5612578-3921-131022480570324\n', b'')
Using module file /mnt/NACBSRE_sre_cac_86039/ansible_collections/nacbsre/cac_collection/plugins/modules/driftdetector_baseline.py
<dsm-ocbdlweb001.srv.bmogc.net> PUT /root/.ansible/tmp/ansible-local-3917bq2g2pmc/tmpeh7m9gpr TO /root/.ansible/tmp/ansible-tmp-1784270293.5612578-3921-131022480570324/
AnsiballZ_driftdetector_baseline.py
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC sftp -b - -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,
gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/
6bf14df888"' '[dsm-ocbdlweb001.srv.bmogc.net]'
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'sftp> put /root/.ansible/tmp/ansible-local-3917bq2g2pmc/tmpeh7m9gpr /root/.ansible/tmp/ansible-tmp-1784270293.5612578-3921-131022480570324/
AnsiballZ_driftdetector_baseline.py\n', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' 
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'chmod u+x /root/.ansible/tmp/ansible-tmp-1784270293.5612578-3921-131022480570324/ /root/.ansible/tmp/ansible-tmp-1784270293.
5612578-3921-131022480570324/AnsiballZ_driftdetector_baseline.py && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' -tt 
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'sudo -H -S -n  -u root /bin/sh -c '"'"'"'"'"'"'"'"'echo BECOME-SUCCESS-emmrkhorwrjbitllkgyomllvoltceswa ; /usr/bin/python3 /root/.ansible/
tmp/ansible-tmp-1784270293.5612578-3921-131022480570324/AnsiballZ_driftdetector_baseline.py'"'"'"'"'"'"'"'"' && sleep 0'"'"''
Escalation succeeded
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'\r\n{"changed": true, "path": "/etc/ld.so.conf.d/httpd-lib.conf", "operation": "publish", "result": "changed", "reason": "CHR009", "uid": 1001, 
"gid": 1001, "owner": "ihsadmin", "group": "wasgroup", "mode": "0744", "state": "file", "size": 54, "invocation": {"module_args": {"state": "present", "path": "/etc/ld.so.conf.d/
httpd-lib.conf", "reason": "CHR009", "managed_file_list": "/home/driftdetector/managed_file_list", "managed_file_list_owner": "driftdetector", "managed_file_list_group": 
"driftdetector", "managed_file_list_mode": "0700", "active_check_cmd": null}}}\r\n', b'Shared connection to dsm-ocbdlweb001.srv.bmogc.net closed.\r\n')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' 
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'rm -f -r /root/.ansible/tmp/ansible-tmp-1784270293.5612578-3921-131022480570324/ > /dev/null 2>&1 && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'', b'')
[[yellow:changed: [dsm-ocbdlweb001.srv.bmogc.net] => (item=/etc/ld.so.conf.d/httpd-lib.conf) => {]]
[[yellow:    "ansible_loop_var": "item",]]
[[yellow:    "changed": true,]]
[[yellow:    "gid": 1001,]]
[[yellow:    "group": "wasgroup",]]
[[yellow:    "invocation": {]]
[[yellow:        "module_args": {]]
[[yellow:            "active_check_cmd": null,]]
[[yellow:            "managed_file_list": "/home/driftdetector/managed_file_list",]]
[[yellow:            "managed_file_list_group": "driftdetector",]]
[[yellow:            "managed_file_list_mode": "0700",]]
[[yellow:            "managed_file_list_owner": "driftdetector",]]
[[yellow:            "path": "/etc/ld.so.conf.d/httpd-lib.conf",]]
[[yellow:            "reason": "CHR009",]]
[[yellow:            "state": "present"]]
[[yellow:        }]]
[[yellow:    },]]
[[yellow:    "item": "/etc/ld.so.conf.d/httpd-lib.conf",]]
[[yellow:    "mode": "0744",]]
[[yellow:    "operation": "publish",]]
[[yellow:    "owner": "ihsadmin",]]
[[yellow:    "path": "/etc/ld.so.conf.d/httpd-lib.conf",]]
[[yellow:    "reason": "CHR009",]]
[[yellow:    "result": "changed",]]
[[yellow:    "size": 54,]]
[[yellow:    "state": "file",]]
[[yellow:    "uid": 1001]]
[[yellow:}]]
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' 
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'echo ~ && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'/root\n', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' 
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'( umask 77 && mkdir -p "` echo /root/.ansible/tmp `"&& mkdir "` echo /root/.ansible/tmp/ansible-tmp-1784270293.
880835-3921-261444631085189 `" && echo ansible-tmp-1784270293.880835-3921-261444631085189="` echo /root/.ansible/tmp/ansible-tmp-1784270293.880835-3921-261444631085189 `" ) && sleep 
0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'ansible-tmp-1784270293.880835-3921-261444631085189=/root/.ansible/tmp/ansible-tmp-1784270293.880835-3921-261444631085189\n', b'')
Using module file /mnt/NACBSRE_sre_cac_86039/ansible_collections/nacbsre/cac_collection/plugins/modules/driftdetector_baseline.py
<dsm-ocbdlweb001.srv.bmogc.net> PUT /root/.ansible/tmp/ansible-local-3917bq2g2pmc/tmp003k1rd7 TO /root/.ansible/tmp/ansible-tmp-1784270293.880835-3921-261444631085189/
AnsiballZ_driftdetector_baseline.py
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC sftp -b - -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,
gssapi-keyex,hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/
6bf14df888"' '[dsm-ocbdlweb001.srv.bmogc.net]'
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'sftp> put /root/.ansible/tmp/ansible-local-3917bq2g2pmc/tmp003k1rd7 /root/.ansible/tmp/ansible-tmp-1784270293.880835-3921-261444631085189/
AnsiballZ_driftdetector_baseline.py\n', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' 
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'chmod u+x /root/.ansible/tmp/ansible-tmp-1784270293.880835-3921-261444631085189/ /root/.ansible/tmp/ansible-tmp-1784270293.
880835-3921-261444631085189/AnsiballZ_driftdetector_baseline.py && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'', b'')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' -tt 
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'sudo -H -S -n  -u root /bin/sh -c '"'"'"'"'"'"'"'"'echo BECOME-SUCCESS-mljlxpauklzdzjwzgomassyzafuxemfs ; /usr/bin/python3 /root/.ansible/
tmp/ansible-tmp-1784270293.880835-3921-261444631085189/AnsiballZ_driftdetector_baseline.py'"'"'"'"'"'"'"'"' && sleep 0'"'"''
Escalation succeeded
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'\r\n{"changed": false, "path": "/etc/systemd/system/driftdetector.service", "operation": "publish", "result": "unchanged", "reason": "CHR009", 
"uid": 0, "gid": 0, "owner": "root", "group": "root", "mode": "0644", "state": "file", "size": 303, "invocation": {"module_args": {"state": "present", "path": "/etc/systemd/system/
driftdetector.service", "reason": "CHR009", "managed_file_list": "/home/driftdetector/managed_file_list", "managed_file_list_owner": "driftdetector", "managed_file_list_group": 
"driftdetector", "managed_file_list_mode": "0700", "active_check_cmd": null}}}\r\n', b'Shared connection to dsm-ocbdlweb001.srv.bmogc.net closed.\r\n')
<dsm-ocbdlweb001.srv.bmogc.net> ESTABLISH SSH CONNECTION FOR USER: None
<dsm-ocbdlweb001.srv.bmogc.net> SSH: EXEC ssh -o ControlMaster=auto -o ControlPersist=600s -o KbdInteractiveAuthentication=no -o PreferredAuthentications=gssapi-with-mic,gssapi-keyex,
hostbased,publickey -o PasswordAuthentication=no -o ConnectTimeout=10 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o 'ControlPath="/root/.ansible/cp/6bf14df888"' 
dsm-ocbdlweb001.srv.bmogc.net '/bin/sh -c '"'"'rm -f -r /root/.ansible/tmp/ansible-tmp-1784270293.880835-3921-261444631085189/ > /dev/null 2>&1 && sleep 0'"'"''
<dsm-ocbdlweb001.srv.bmogc.net> (0, b'', b'')
[[green:ok: [dsm-ocbdlweb001.srv.bmogc.net] => (item=/etc/systemd/system/driftdetector.service) => {]]
[[green:    "ansible_loop_var": "item",]]
[[green:    "changed": false,]]
[[green:    "gid": 0,]]
[[green:    "group": "root",]]
[[green:    "invocation": {]]
[[green:        "module_args": {]]
[[green:            "active_check_cmd": null,]]
[[green:            "managed_file_list": "/home/driftdetector/managed_file_list",]]
[[green:            "managed_file_list_group": "driftdetector",]]
[[green:            "managed_file_list_mode": "0700",]]
[[green:            "managed_file_list_owner": "driftdetector",]]
[[green:            "path": "/etc/systemd/system/driftdetector.service",]]
[[green:            "reason": "CHR009",]]
[[green:            "state": "present"]]
[[green:        }]]
[[green:    },]]
[[green:    "item": "/etc/systemd/system/driftdetector.service",]]
[[green:    "mode": "0644",]]
[[green:    "operation": "publish",]]
[[green:    "owner": "root",]]
[[green:    "path": "/etc/systemd/system/driftdetector.service",]]
[[green:    "reason": "CHR009",]]
[[green:    "result": "unchanged",]]
[[green:    "size": 303,]]
[[green:    "state": "file",]]
[[green:    "uid": 0]]
[[green:}]]
PLAY RECAP ************************************************************************************************************************************************
[[yellow:dsm-ocbdlweb001.srv.bmogc.net]] : [[green:ok=1]]    [[yellow:changed=1]]    unreachable=0    failed=0    skipped=0    rescued=0    ignored=0   

To define MONITOR_LIST:

#
# 1. passing as --extra-vars (-e) via CLI in JSON format:
#
[root@tower NACBSRE_sre_client_app_86039]# ansible-playbook driftdetector_baseline.yml -i inventories/sre_dev \
                                           [[yellow:-e "GROUP_LIMIT=my_host_group"]]                                     \
                                           [[yellow:-e "STATE=present"]]                                                 \
                                           [[yellow:-e '{"MONITOR_LIST":["/etc/ssh/sshd_config","/etc/resolv.conf"]}']]  \
                                           [[yellow:-e "CHANGE_REASON=CHR009" -vvv -D]]

#
# not preferred, but can also be done in YAML format:
#
[root@tower NACBSRE_sre_client_app_86039]# ansible-playbook driftdetector_baseline.yml -i inventories/sre_dev \
                                           [[yellow:-e "GROUP_LIMIT=my_host_group"]]                                     \
                                           [[yellow:-e "STATE=present"]]                                                 \
                                           [[yellow:-e "MONITOR_LIST=['/etc/ssh/sshd_config', '/etc/resolv.conf']"]]
                                           [[yellow:-e "CHANGE_REASON=CHR009" -vvv -D]]

#
# 2. defining in host)vars or group_vars:
#
::
::
[[blue:MONITOR_LIST:]]
  [[blue:- /etc/ssh/sshd_config]]
  [[blue:- /etc/resolv.conf]]
  [[blue:- /etc/hosts]]
::
::

#
# 3. defining directly in an inventory File (INI format):
#
::
::
[[blue:[webservers]]]
[[blue:webserver1 MONITOR_LIST='["/var/www/html/index.html", "/etc/nginx/nginx.conf"]']]
[[blue:webserver2 MONITOR_LIST='["/var/www/html/index.html"]']]
::
::