Skip to content

Document image tags of OSISM services - #1099

Draft
ideaship wants to merge 1 commit into
osism-11-docsfrom
osism-service-image-tags
Draft

ideaship wants to merge 1 commit into
osism-11-docsfrom
osism-service-image-tags

Conversation

@ideaship

@ideaship ideaship commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

The services that osism-ansible deploys itself, rather than through
Kolla, now take their image tags from the OSISM release: the
osism/osism-ansible image ships the tags pinned in osism/release
inside its versions.yml
(https://github.com/osism/container-image-osism-ansible), and the
inventory reconciler places that file so it overrides the role and
osism/defaults defaults.

Add an "Image tags of OSISM services" section to the OpenStack
configuration guide listing, for every affected service, the
variable to set and the environment's images.yml to set it in
(kolla, monitoring, infrastructure or openstack), and note the
precedence trap: a file in inventory/group_vars/all/ loses to the
release value unless its name sorts after
100-versions-osism-kubernetes.yml, the last runner file (a flat
group_vars/all.yml is moved to 999-all.yml and wins). Explain that
NetBox is split by how it is applied: run.sh netbox on the manager
still reads environments/manager/images.yml, but osism apply netbox
runs in the infrastructure environment and takes its tags from the
release via versions.yml, overridable in
environments/infrastructure/images.yml.

openstackclient_version and cephclient_version are carried by
osism-ansible's versions.yml in a release build only. On the latest
track openstackclient_version comes from kolla-ansible's
versions.yml, and cephclient_version from ceph-ansible's, or from the
cephclient role default when no ceph-ansible container runs; the
section says so.

Add an entry to the OSISM 11 release notes listing the seven deployed
tag changes compared with OSISM 10 (adminer, dnsmasq,
opentelemetry-collector, phpmyadmin, scaphandre, step-ca, and NetBox's
Redis image under osism apply netbox). For the latest track it notes
that an air-gapped registry needs the new tags first and that
step-ca's PKI in /opt/stepca should be backed up before step-ca is
applied again. cgit, dnsdist, gNMIc, NetBox, pgautoupgrade,
PostgreSQL, Squid, Substation, Tempest and wazuh-proxy keep their
current tags.

Based on the OSISM 11 release notes it adds to:

Part of:

🤖 Generated with Claude Code

The services that osism-ansible deploys itself, rather than through
Kolla, now take their image tags from the OSISM release: the
osism/osism-ansible image ships the tags pinned in osism/release
inside its versions.yml
(https://github.com/osism/container-image-osism-ansible), and the
inventory reconciler places that file so it overrides the role and
osism/defaults defaults.

Add an "Image tags of OSISM services" section to the OpenStack
configuration guide listing, for every affected service, the
variable to set and the environment's images.yml to set it in
(kolla, monitoring, infrastructure or openstack), and note the
precedence trap: a file in inventory/group_vars/all/ loses to the
release value unless its name sorts after
100-versions-osism-kubernetes.yml, the last runner file (a flat
group_vars/all.yml is moved to 999-all.yml and wins). Explain that
NetBox is split by how it is applied: run.sh netbox on the manager
still reads environments/manager/images.yml, but osism apply netbox
runs in the infrastructure environment and takes its tags from the
release via versions.yml, overridable in
environments/infrastructure/images.yml.

openstackclient_version and cephclient_version are carried by
osism-ansible's versions.yml in a release build only. On the latest
track openstackclient_version comes from kolla-ansible's
versions.yml, and cephclient_version from ceph-ansible's, or from the
cephclient role default when no ceph-ansible container runs; the
section says so.

Add an entry to the OSISM 11 release notes listing the seven deployed
tag changes compared with OSISM 10 (adminer, dnsmasq,
opentelemetry-collector, phpmyadmin, scaphandre, step-ca, and NetBox's
Redis image under osism apply netbox). For the latest track it notes
that an air-gapped registry needs the new tags first and that
step-ca's PKI in /opt/stepca should be backed up before step-ca is
applied again. cgit, dnsdist, gNMIc, NetBox, pgautoupgrade,
PostgreSQL, Squid, Substation, Tempest and wazuh-proxy keep their
current tags.

Assisted-by: Claude:claude-sonnet-5
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Roger Luethi <luethi@osism.tech>
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

✅⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ ACTION actionlint 5 0 0 0.03s
✅ JSON jsonlint 4 0 0 0.06s
✅ JSON prettier 4 0 0 0.18s
✅ JSON v8r 4 0 0 7.64s
✅ MARKDOWN markdownlint 172 0 0 1.19s
✅ MARKDOWN markdown-table-formatter 172 0 0 0.24s
✅ REPOSITORY betterleaks yes no no 0.34s
✅ REPOSITORY checkov yes no no 11.77s
✅ REPOSITORY git_diff yes no no 0.03s
✅ REPOSITORY secretlint yes no no 0.82s
✅ REPOSITORY trufflehog yes no no 2.39s
✅ SPELL codespell 182 0 0 0.25s
⚠️ SPELL lychee 182 1 0 45.78s
✅ YAML prettier 6 0 0 0.18s
✅ YAML v8r 6 0 0 4.42s
✅ YAML yamllint 6 0 0 0.24s

Detailed Issues

⚠️ SPELL / lychee - 1 error
📝 Summary
---------------------
🔍 Total.........1178
🔗 Unique.........889
✅ Successful....1076
⏳ Timeouts.........0
🔀 Redirected.......9
👻 Excluded.......101
❓ Unknown..........0
🚫 Errors...........1
⛔ Unsupported......1

Errors in docs/guides/deploy-guide/metalbox.md
[404] https://github.com/osism/metalbox/blob/main/zuul/vars/container-images-openstack-2024.2.yml (at 83:101) | Rejected status code: 404 Not Found

Hint: Followed 9 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.1.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,JSON_JSONLINT,JSON_V8R,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_SECRETLINT,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,SPELL_CODESPELL,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@ideaship ideaship self-assigned this Oct 3, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: New

Development

Successfully merging this pull request may close these issues.

2 participants