Drift detected: production may not be serving the intended revision #19

Open
opened 2026-09-16 23:13:47 +00:00 by vendel.xi2ix.com · 31 comments

Opened by drift-check.yaml. Each occurrence is added as a COMMENT on this issue rather than as a new issue: this job runs hourly, and one issue per hour would be 24 a day and worse than silence. Read the newest comment for the current state.

Opened by drift-check.yaml. Each occurrence is added as a COMMENT on this issue rather than as a new issue: this job runs hourly, and one issue per hour would be 24 a day and worse than silence. Read the newest comment for the current state.
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/337
Event: workflow_dispatch
Commit: 8b250e8d1f
Branch/ref: main
Triggered by: vendel.xi2ix.com
Simulated (simulate_drift): true

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state fresh
Previous heartbeat timestamp 2026-09-16T23:03:27Z
Previous heartbeat age (s) 617

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

SIMULATION: the intended revision is overridden to 'simulated-drift-no-build-has-this-sha' (read from the cluster: '8b250e8d1f83fd5a383e105a1c0795c510e8bfbd'). The comparison is being driven deliberately; this is not a real reading.
  sampler| EXPECTED=2 (resolved from the live Deployment)
  sampler| instance pod=xi2ix-77964fbf4b-2q7vk sha=8b250e8d1f83fd5a383e105a1c0795c510e8bfbd expected=no
  sampler| instance pod=xi2ix-77964fbf4b-xjswg sha=8b250e8d1f83fd5a383e105a1c0795c510e8bfbd expected=no
  sampler| verdict=red reason=none_on_expected_sha observed=2 expected=2 matching=0 draws=4 unanswered=0 expected_sha=simulated-drift-no-build-has-this-sha
drift_check=drift reason=deployment_changed served=8b250e8d1f83fd5a383e105a1c0795c510e8bfbd declared=8b250e8d1f83fd5a383e105a1c0795c510e8bfbd intended=simulated-drift-no-build-has-this-sha instances=2 expected=2
DRIFT CHECK: THE DEPLOYMENT ITSELF WAS CHANGED. Every sampled instance serves 8b250e8d1f83fd5a383e105a1c0795c510e8bfbd and the Deployment declares that same revision 8b250e8d1f83fd5a383e105a1c0795c510e8bfbd -- but the last revision we INTENDED to ship was simulated-drift-no-build-has-this-sha. The two agree with each other and both disagree with our intention, which is the signature of a rollback (manual, or automatic via the 3-strike streak in scripts/rollback-streak.sh) rather than of a failed rollout. Check 'helm history xi2ix -n xi2ix' for a 'Rollback to <n>' record before doing anything else.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

The previous heartbeat in ConfigMap xi2ix-drift-last-run is 617s old (2026-09-16T23:03:27Z) -- within the two-hour threshold, so this detector has been running on schedule.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

Previous heartbeat: 2026-09-16T23:03:27Z (617s ago)
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/337 **Event:** workflow_dispatch **Commit:** 8b250e8d1f83fd5a383e105a1c0795c510e8bfbd **Branch/ref:** main **Triggered by:** vendel.xi2ix.com **Simulated (simulate_drift):** true ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | fresh | | Previous heartbeat timestamp | 2026-09-16T23:03:27Z | | Previous heartbeat age (s) | 617 | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` SIMULATION: the intended revision is overridden to 'simulated-drift-no-build-has-this-sha' (read from the cluster: '8b250e8d1f83fd5a383e105a1c0795c510e8bfbd'). The comparison is being driven deliberately; this is not a real reading. sampler| EXPECTED=2 (resolved from the live Deployment) sampler| instance pod=xi2ix-77964fbf4b-2q7vk sha=8b250e8d1f83fd5a383e105a1c0795c510e8bfbd expected=no sampler| instance pod=xi2ix-77964fbf4b-xjswg sha=8b250e8d1f83fd5a383e105a1c0795c510e8bfbd expected=no sampler| verdict=red reason=none_on_expected_sha observed=2 expected=2 matching=0 draws=4 unanswered=0 expected_sha=simulated-drift-no-build-has-this-sha drift_check=drift reason=deployment_changed served=8b250e8d1f83fd5a383e105a1c0795c510e8bfbd declared=8b250e8d1f83fd5a383e105a1c0795c510e8bfbd intended=simulated-drift-no-build-has-this-sha instances=2 expected=2 DRIFT CHECK: THE DEPLOYMENT ITSELF WAS CHANGED. Every sampled instance serves 8b250e8d1f83fd5a383e105a1c0795c510e8bfbd and the Deployment declares that same revision 8b250e8d1f83fd5a383e105a1c0795c510e8bfbd -- but the last revision we INTENDED to ship was simulated-drift-no-build-has-this-sha. The two agree with each other and both disagree with our intention, which is the signature of a rollback (manual, or automatic via the 3-strike streak in scripts/rollback-streak.sh) rather than of a failed rollout. Check 'helm history xi2ix -n xi2ix' for a 'Rollback to <n>' record before doing anything else. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` The previous heartbeat in ConfigMap xi2ix-drift-last-run is 617s old (2026-09-16T23:03:27Z) -- within the two-hour threshold, so this detector has been running on schedule. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` Previous heartbeat: 2026-09-16T23:03:27Z (617s ago) ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/338
Event: workflow_dispatch
Commit: 8b250e8d1f
Branch/ref: main
Triggered by: vendel.xi2ix.com
Simulated (simulate_drift): true

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state fresh
Previous heartbeat timestamp 2026-09-16T23:13:48Z
Previous heartbeat age (s) 30

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

SIMULATION: the intended revision is overridden to 'simulated-drift-no-build-has-this-sha' (read from the cluster: '8b250e8d1f83fd5a383e105a1c0795c510e8bfbd'). The comparison is being driven deliberately; this is not a real reading.
  sampler| EXPECTED=2 (resolved from the live Deployment)
  sampler| instance pod=xi2ix-77964fbf4b-xjswg sha=8b250e8d1f83fd5a383e105a1c0795c510e8bfbd expected=no
  sampler| instance pod=xi2ix-77964fbf4b-2q7vk sha=8b250e8d1f83fd5a383e105a1c0795c510e8bfbd expected=no
  sampler| verdict=red reason=none_on_expected_sha observed=2 expected=2 matching=0 draws=3 unanswered=0 expected_sha=simulated-drift-no-build-has-this-sha
drift_check=drift reason=deployment_changed served=8b250e8d1f83fd5a383e105a1c0795c510e8bfbd declared=8b250e8d1f83fd5a383e105a1c0795c510e8bfbd intended=simulated-drift-no-build-has-this-sha instances=2 expected=2
DRIFT CHECK: THE DEPLOYMENT ITSELF WAS CHANGED. Every sampled instance serves 8b250e8d1f83fd5a383e105a1c0795c510e8bfbd and the Deployment declares that same revision 8b250e8d1f83fd5a383e105a1c0795c510e8bfbd -- but the last revision we INTENDED to ship was simulated-drift-no-build-has-this-sha. The two agree with each other and both disagree with our intention, which is the signature of a rollback (manual, or automatic via the 3-strike streak in scripts/rollback-streak.sh) rather than of a failed rollout. Check 'helm history xi2ix -n xi2ix' for a 'Rollback to <n>' record before doing anything else.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

The previous heartbeat in ConfigMap xi2ix-drift-last-run is 30s old (2026-09-16T23:13:48Z) -- within the two-hour threshold, so this detector has been running on schedule.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

Previous heartbeat: 2026-09-16T23:13:48Z (30s ago)
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/338 **Event:** workflow_dispatch **Commit:** 8b250e8d1f83fd5a383e105a1c0795c510e8bfbd **Branch/ref:** main **Triggered by:** vendel.xi2ix.com **Simulated (simulate_drift):** true ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | fresh | | Previous heartbeat timestamp | 2026-09-16T23:13:48Z | | Previous heartbeat age (s) | 30 | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` SIMULATION: the intended revision is overridden to 'simulated-drift-no-build-has-this-sha' (read from the cluster: '8b250e8d1f83fd5a383e105a1c0795c510e8bfbd'). The comparison is being driven deliberately; this is not a real reading. sampler| EXPECTED=2 (resolved from the live Deployment) sampler| instance pod=xi2ix-77964fbf4b-xjswg sha=8b250e8d1f83fd5a383e105a1c0795c510e8bfbd expected=no sampler| instance pod=xi2ix-77964fbf4b-2q7vk sha=8b250e8d1f83fd5a383e105a1c0795c510e8bfbd expected=no sampler| verdict=red reason=none_on_expected_sha observed=2 expected=2 matching=0 draws=3 unanswered=0 expected_sha=simulated-drift-no-build-has-this-sha drift_check=drift reason=deployment_changed served=8b250e8d1f83fd5a383e105a1c0795c510e8bfbd declared=8b250e8d1f83fd5a383e105a1c0795c510e8bfbd intended=simulated-drift-no-build-has-this-sha instances=2 expected=2 DRIFT CHECK: THE DEPLOYMENT ITSELF WAS CHANGED. Every sampled instance serves 8b250e8d1f83fd5a383e105a1c0795c510e8bfbd and the Deployment declares that same revision 8b250e8d1f83fd5a383e105a1c0795c510e8bfbd -- but the last revision we INTENDED to ship was simulated-drift-no-build-has-this-sha. The two agree with each other and both disagree with our intention, which is the signature of a rollback (manual, or automatic via the 3-strike streak in scripts/rollback-streak.sh) rather than of a failed rollout. Check 'helm history xi2ix -n xi2ix' for a 'Rollback to <n>' record before doing anything else. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` The previous heartbeat in ConfigMap xi2ix-drift-last-run is 30s old (2026-09-16T23:13:48Z) -- within the two-hour threshold, so this detector has been running on schedule. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` Previous heartbeat: 2026-09-16T23:13:48Z (30s ago) ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/355
Event: workflow_dispatch
Commit: ee0eb9ff3d
Branch/ref: main
Triggered by: forgeadmin
Simulated (simulate_drift): false

What failed

The detector itself did not report drift (outcome: success). This run failed for another reason -- most likely the heartbeat-freshness assertion, which means this detector had previously stopped running for at least two hourly ticks.

Detector heartbeat

Field Value
Previous heartbeat state stale
Previous heartbeat timestamp 2026-09-17T09:19:37Z
Previous heartbeat age (s) 11088

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

  sampler| EXPECTED=2 (resolved from the live Deployment)
  sampler| instance pod=xi2ix-5859465b76-cqbj6 sha=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c expected=yes
  sampler| instance pod=xi2ix-5859465b76-psghb sha=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c expected=yes
  sampler| verdict=green reason=all_on_expected_sha observed=2 expected=2 matching=2 draws=2 unanswered=0 expected_sha=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c
drift_check=ok reason=in_agreement served=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c declared=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c intended=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c instances=2 expected=2
DRIFT CHECK: no drift. All 2 of 2 expected instances serve ee0eb9ff3da98195affb78ab4de3d1a0c590e52c, the Deployment declares ee0eb9ff3da98195affb78ab4de3d1a0c590e52c, and the last intended deploy recorded ee0eb9ff3da98195affb78ab4de3d1a0c590e52c -- three readings, taken independently, in agreement.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

::error::STALE HEARTBEAT: the last recorded run of this detector was 2026-09-17T09:19:37Z (11088s ago), which is more than two hours -- at least two hourly ticks were missed. For that window NOTHING was watching whether production still served the intended revision, and the absence produced no signal of any kind at the time. Failing the run so the gap is visible retroactively. NOTE THE LIMIT HONESTLY: this check lives INSIDE the workflow it is checking, so it can only ever report a gap that has already ENDED. A schedule that is still dead never reaches this line at all -- that case belongs to the independent weekly assertion in .forgejo/workflows/rollback-drill.yaml.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

Previous heartbeat: 2026-09-17T09:19:37Z (11088s ago)
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/355 **Event:** workflow_dispatch **Commit:** ee0eb9ff3da98195affb78ab4de3d1a0c590e52c **Branch/ref:** main **Triggered by:** forgeadmin **Simulated (simulate_drift):** false ### What failed The detector itself did not report drift (outcome: success). This run failed for another reason -- most likely the heartbeat-freshness assertion, which means this detector had previously stopped running for at least two hourly ticks. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | stale | | Previous heartbeat timestamp | 2026-09-17T09:19:37Z | | Previous heartbeat age (s) | 11088 | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` sampler| EXPECTED=2 (resolved from the live Deployment) sampler| instance pod=xi2ix-5859465b76-cqbj6 sha=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c expected=yes sampler| instance pod=xi2ix-5859465b76-psghb sha=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c expected=yes sampler| verdict=green reason=all_on_expected_sha observed=2 expected=2 matching=2 draws=2 unanswered=0 expected_sha=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c drift_check=ok reason=in_agreement served=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c declared=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c intended=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c instances=2 expected=2 DRIFT CHECK: no drift. All 2 of 2 expected instances serve ee0eb9ff3da98195affb78ab4de3d1a0c590e52c, the Deployment declares ee0eb9ff3da98195affb78ab4de3d1a0c590e52c, and the last intended deploy recorded ee0eb9ff3da98195affb78ab4de3d1a0c590e52c -- three readings, taken independently, in agreement. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` ::error::STALE HEARTBEAT: the last recorded run of this detector was 2026-09-17T09:19:37Z (11088s ago), which is more than two hours -- at least two hourly ticks were missed. For that window NOTHING was watching whether production still served the intended revision, and the absence produced no signal of any kind at the time. Failing the run so the gap is visible retroactively. NOTE THE LIMIT HONESTLY: this check lives INSIDE the workflow it is checking, so it can only ever report a gap that has already ENDED. A schedule that is still dead never reaches this line at all -- that case belongs to the independent weekly assertion in .forgejo/workflows/rollback-drill.yaml. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` Previous heartbeat: 2026-09-17T09:19:37Z (11088s ago) ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/359
Event: schedule
Commit: ee0eb9ff3d
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The detector itself did not report drift (outcome: success). This run failed for another reason -- most likely the heartbeat-freshness assertion, which means this detector had previously stopped running for at least two hourly ticks.

Detector heartbeat

Field Value
Previous heartbeat state stale
Previous heartbeat timestamp 2026-09-17T10:13:06Z
Previous heartbeat age (s) 13635

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

  sampler| EXPECTED=2 (resolved from the live Deployment)
  sampler| instance pod=xi2ix-5859465b76-cqbj6 sha=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c expected=yes
  sampler| instance pod=xi2ix-5859465b76-psghb sha=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c expected=yes
  sampler| verdict=green reason=all_on_expected_sha observed=2 expected=2 matching=2 draws=3 unanswered=0 expected_sha=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c
drift_check=ok reason=in_agreement served=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c declared=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c intended=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c instances=2 expected=2
DRIFT CHECK: no drift. All 2 of 2 expected instances serve ee0eb9ff3da98195affb78ab4de3d1a0c590e52c, the Deployment declares ee0eb9ff3da98195affb78ab4de3d1a0c590e52c, and the last intended deploy recorded ee0eb9ff3da98195affb78ab4de3d1a0c590e52c -- three readings, taken independently, in agreement.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

::error::STALE HEARTBEAT: the last recorded run of this detector was 2026-09-17T10:13:06Z (13635s ago), which is more than two hours -- at least two hourly ticks were missed. For that window NOTHING was watching whether production still served the intended revision, and the absence produced no signal of any kind at the time. Failing the run so the gap is visible retroactively. NOTE THE LIMIT HONESTLY: this check lives INSIDE the workflow it is checking, so it can only ever report a gap that has already ENDED. A schedule that is still dead never reaches this line at all -- that case belongs to the independent weekly assertion in .forgejo/workflows/rollback-drill.yaml.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

Previous heartbeat: 2026-09-17T10:13:06Z (13635s ago)
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/359 **Event:** schedule **Commit:** ee0eb9ff3da98195affb78ab4de3d1a0c590e52c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The detector itself did not report drift (outcome: success). This run failed for another reason -- most likely the heartbeat-freshness assertion, which means this detector had previously stopped running for at least two hourly ticks. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | stale | | Previous heartbeat timestamp | 2026-09-17T10:13:06Z | | Previous heartbeat age (s) | 13635 | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` sampler| EXPECTED=2 (resolved from the live Deployment) sampler| instance pod=xi2ix-5859465b76-cqbj6 sha=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c expected=yes sampler| instance pod=xi2ix-5859465b76-psghb sha=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c expected=yes sampler| verdict=green reason=all_on_expected_sha observed=2 expected=2 matching=2 draws=3 unanswered=0 expected_sha=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c drift_check=ok reason=in_agreement served=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c declared=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c intended=ee0eb9ff3da98195affb78ab4de3d1a0c590e52c instances=2 expected=2 DRIFT CHECK: no drift. All 2 of 2 expected instances serve ee0eb9ff3da98195affb78ab4de3d1a0c590e52c, the Deployment declares ee0eb9ff3da98195affb78ab4de3d1a0c590e52c, and the last intended deploy recorded ee0eb9ff3da98195affb78ab4de3d1a0c590e52c -- three readings, taken independently, in agreement. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` ::error::STALE HEARTBEAT: the last recorded run of this detector was 2026-09-17T10:13:06Z (13635s ago), which is more than two hours -- at least two hourly ticks were missed. For that window NOTHING was watching whether production still served the intended revision, and the absence produced no signal of any kind at the time. Failing the run so the gap is visible retroactively. NOTE THE LIMIT HONESTLY: this check lives INSIDE the workflow it is checking, so it can only ever report a gap that has already ENDED. A schedule that is still dead never reaches this line at all -- that case belongs to the independent weekly assertion in .forgejo/workflows/rollback-drill.yaml. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` Previous heartbeat: 2026-09-17T10:13:06Z (13635s ago) ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/430
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/430 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/431
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/431 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/432
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/432 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/433
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/433 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/434
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/434 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/435
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/435 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/436
Event: workflow_dispatch
Commit: f0c6722aa8
Branch/ref: main
Triggered by: vendel.xi2ix.com
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/436 **Event:** workflow_dispatch **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** vendel.xi2ix.com **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/437
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/437 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/438
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/438 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/439
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/439 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/440
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/440 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/441
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/441 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/442
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/442 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/443
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/443 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/444
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/444 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/445
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/445 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/446
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/446 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/447
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/447 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/448
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/448 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/449
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/449 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/450
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/450 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/451
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/451 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/452
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/452 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/453
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/453 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/456
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state absent
Previous heartbeat timestamp none
Previous heartbeat age (s) unknown

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown
DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one.
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/456 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | absent | | Previous heartbeat timestamp | none | | Previous heartbeat age (s) | unknown | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` drift_check=error reason=intended_unreadable served=none declared=none intended=none instances=0 expected=unknown DRIFT CHECK: could not read the intended revision from ConfigMap xi2ix-last-known-good in namespace xi2ix (got '<empty>'). NO drift conclusion is possible: with no intention to compare against, 'no drift' would be a claim with nothing behind it. Either no deploy has written the record yet, or the read was denied. If this is a Forbidden, it is an environment-management-owned RBAC gap (ConfigMaps ARE on the documented list) -- raise it via Forgejo Issue #1/#2, never work around it here. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` No previous heartbeat existed. Accepted WITHOUT failing: on a first run there is nothing to be stale. If this recurs on later runs, the always() heartbeat step is not writing, and that is a real defect. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` No previous heartbeat found in ConfigMap xi2ix-drift-last-run. On a FIRST run that is expected and is NOT a failure -- there is nothing yet to be stale. From the second run onward, an absent heartbeat means the final always() step never wrote one. ```
Author
Owner

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/531
Event: schedule
Commit: f0c6722aa8
Branch/ref: main
Triggered by: forgejo-actions
Simulated (simulate_drift): false

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state fresh
Previous heartbeat timestamp 2026-09-24T07:01:03Z
Previous heartbeat age (s) 3598

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

  sampler| deployed-identity: INPUT ERROR — EXPECTED resolution error: live {.spec.replicas} read '0', not a positive integer; refusing to fall back (no verdict emitted)
drift_check=error reason=sampler_no_verdict served=none declared=f0c6722aa8964f8764dca79b0dcc81e04a45b88c intended=f0c6722aa8964f8764dca79b0dcc81e04a45b88c instances=0 expected=unknown
DRIFT CHECK: the served-revision sampler (/workspace/vendel.xi2ix.com/xi2ix.com-website/scripts/deployed-identity.sh) produced no verdict line at all, so the number of instances it reached is unknown. Its output is reproduced above. This is reported as an ERROR rather than as drift precisely because nothing was learned about production -- treating an unusable sample as a finding about the fleet would be an invented reading.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

The previous heartbeat in ConfigMap xi2ix-drift-last-run is 3598s old (2026-09-24T07:01:03Z) -- within the two-hour threshold, so this detector has been running on schedule.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

Previous heartbeat: 2026-09-24T07:01:03Z (3598s ago)
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/531 **Event:** schedule **Commit:** f0c6722aa8964f8764dca79b0dcc81e04a45b88c **Branch/ref:** main **Triggered by:** forgejo-actions **Simulated (simulate_drift):** false ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | fresh | | Previous heartbeat timestamp | 2026-09-24T07:01:03Z | | Previous heartbeat age (s) | 3598 | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` sampler| deployed-identity: INPUT ERROR — EXPECTED resolution error: live {.spec.replicas} read '0', not a positive integer; refusing to fall back (no verdict emitted) drift_check=error reason=sampler_no_verdict served=none declared=f0c6722aa8964f8764dca79b0dcc81e04a45b88c intended=f0c6722aa8964f8764dca79b0dcc81e04a45b88c instances=0 expected=unknown DRIFT CHECK: the served-revision sampler (/workspace/vendel.xi2ix.com/xi2ix.com-website/scripts/deployed-identity.sh) produced no verdict line at all, so the number of instances it reached is unknown. Its output is reproduced above. This is reported as an ERROR rather than as drift precisely because nothing was learned about production -- treating an unusable sample as a finding about the fleet would be an invented reading. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` The previous heartbeat in ConfigMap xi2ix-drift-last-run is 3598s old (2026-09-24T07:01:03Z) -- within the two-hour threshold, so this detector has been running on schedule. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` Previous heartbeat: 2026-09-24T07:01:03Z (3598s ago) ```
Collaborator

Workflow: drift-check.yaml
Job: drift-check
Run: https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/669
Event: workflow_dispatch
Commit: a2f020f27c
Branch/ref: main
Triggered by: vendel.xi2ix.com
Simulated (simulate_drift): true

What failed

The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below.

Detector heartbeat

Field Value
Previous heartbeat state fresh
Previous heartbeat timestamp 2026-09-29T15:01:04Z
Previous heartbeat age (s) 704

Captured output (tail, per failing-eligible step)

/tmp/gsd-failhook-drift-check-drift-check-detector.log

SIMULATION: the intended revision is overridden to 'simulated-drift-no-build-has-this-sha' (read from the cluster: 'a2f020f27c35f13ad83008d795948f98d3ebea72'). The comparison is being driven deliberately; this is not a real reading.
  sampler| EXPECTED=2 (resolved from the live Deployment)
  sampler| instance pod=xi2ix-555759bd8b-2hbbc sha=a2f020f27c35f13ad83008d795948f98d3ebea72 expected=no
  sampler| instance pod=xi2ix-555759bd8b-72ckz sha=a2f020f27c35f13ad83008d795948f98d3ebea72 expected=no
  sampler| verdict=red reason=none_on_expected_sha observed=2 expected=2 matching=0 draws=3 unanswered=0 expected_sha=simulated-drift-no-build-has-this-sha
drift_check=drift reason=deployment_changed served=a2f020f27c35f13ad83008d795948f98d3ebea72 declared=a2f020f27c35f13ad83008d795948f98d3ebea72 intended=simulated-drift-no-build-has-this-sha instances=2 expected=2
DRIFT CHECK: THE DEPLOYMENT ITSELF WAS CHANGED. Every sampled instance serves a2f020f27c35f13ad83008d795948f98d3ebea72 and the Deployment declares that same revision a2f020f27c35f13ad83008d795948f98d3ebea72 -- but the last revision we INTENDED to ship was simulated-drift-no-build-has-this-sha. The two agree with each other and both disagree with our intention, which is the signature of a rollback (manual, or automatic via the 3-strike streak in scripts/rollback-streak.sh) rather than of a failed rollout. Check 'helm history xi2ix -n xi2ix' for a 'Rollback to <n>' record before doing anything else.

/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log

The previous heartbeat in ConfigMap xi2ix-drift-last-run is 704s old (2026-09-29T15:01:04Z) -- within the two-hour threshold, so this detector has been running on schedule.

/tmp/gsd-failhook-drift-check-drift-check-prev.log

Previous heartbeat: 2026-09-29T15:01:04Z (704s ago)
**Workflow:** drift-check.yaml **Job:** drift-check **Run:** https://forgejo.lab.xi2ix.de/vendel.xi2ix.com/xi2ix.com-website/actions/runs/669 **Event:** workflow_dispatch **Commit:** a2f020f27c35f13ad83008d795948f98d3ebea72 **Branch/ref:** main **Triggered by:** vendel.xi2ix.com **Simulated (simulate_drift):** true ### What failed The drift detector reported a finding. Production may not be serving the revision we intended to ship. The detector's own output, naming which of the three readings disagreed and what each said, is captured below. ### Detector heartbeat | Field | Value | | --- | --- | | Previous heartbeat state | fresh | | Previous heartbeat timestamp | 2026-09-29T15:01:04Z | | Previous heartbeat age (s) | 704 | ### Captured output (tail, per failing-eligible step) **/tmp/gsd-failhook-drift-check-drift-check-detector.log** ``` SIMULATION: the intended revision is overridden to 'simulated-drift-no-build-has-this-sha' (read from the cluster: 'a2f020f27c35f13ad83008d795948f98d3ebea72'). The comparison is being driven deliberately; this is not a real reading. sampler| EXPECTED=2 (resolved from the live Deployment) sampler| instance pod=xi2ix-555759bd8b-2hbbc sha=a2f020f27c35f13ad83008d795948f98d3ebea72 expected=no sampler| instance pod=xi2ix-555759bd8b-72ckz sha=a2f020f27c35f13ad83008d795948f98d3ebea72 expected=no sampler| verdict=red reason=none_on_expected_sha observed=2 expected=2 matching=0 draws=3 unanswered=0 expected_sha=simulated-drift-no-build-has-this-sha drift_check=drift reason=deployment_changed served=a2f020f27c35f13ad83008d795948f98d3ebea72 declared=a2f020f27c35f13ad83008d795948f98d3ebea72 intended=simulated-drift-no-build-has-this-sha instances=2 expected=2 DRIFT CHECK: THE DEPLOYMENT ITSELF WAS CHANGED. Every sampled instance serves a2f020f27c35f13ad83008d795948f98d3ebea72 and the Deployment declares that same revision a2f020f27c35f13ad83008d795948f98d3ebea72 -- but the last revision we INTENDED to ship was simulated-drift-no-build-has-this-sha. The two agree with each other and both disagree with our intention, which is the signature of a rollback (manual, or automatic via the 3-strike streak in scripts/rollback-streak.sh) rather than of a failed rollout. Check 'helm history xi2ix -n xi2ix' for a 'Rollback to <n>' record before doing anything else. ``` **/tmp/gsd-failhook-drift-check-drift-check-heartbeat-age.log** ``` The previous heartbeat in ConfigMap xi2ix-drift-last-run is 704s old (2026-09-29T15:01:04Z) -- within the two-hour threshold, so this detector has been running on schedule. ``` **/tmp/gsd-failhook-drift-check-drift-check-prev.log** ``` Previous heartbeat: 2026-09-29T15:01:04Z (704s ago) ```
Sign in to join this conversation.
No description provided.