Receptor binary is unpinned (:devel), unused for container groups, and version-skewed vs the AWX controller #2

Closed
opened 2026-09-19 12:23:49 +00:00 by daniel · 1 comment
Owner

Summary

Containerfile:65 copies the receptor binary from the mutable quay.io/ansible/receptor:devel tag:

COPY --from=quay.io/ansible/receptor:devel /usr/bin/receptor /usr/bin/receptor

This pulls an arbitrary pre-release build. In the current image it is receptor 1.6.8+git58f9101, while the AWX controller that dispatches these jobs ships receptor 1.4.8+d7fe592.

Why it matters

For AWX container-group jobs (the normal path) the pod runs:

args = ['ansible-runner', 'worker', '--private-data-dir=/runner']

i.e. the entry process is ansible-runner worker, not receptor (awx/main/utils/execution_environments.py). So the copied binary is unused in that topology — it just adds a ~73 MB layer:

<missing>  ...  COPY /usr/bin/receptor /usr/bin/receptor  # buildkit   73.4MB

If the image is ever used as an execution node, the version skew against the controller (1.6.8 vs 1.4.8) becomes a real compatibility risk.

Suggested fix

Pick one:

  1. Drop the COPY line (and the corresponding "receptor" claim in README.md) since container groups do not need it. Keep receptorctl from requirements.txt.
  2. If receptor is genuinely needed, pin it to the version the target AWX ships, e.g. quay.io/ansible/receptor:1.4.8, and add a version check to the smoke test.

Do not track a mutable :devel tag.

Verification

$ podman run --rm <ee> receptor --version
1.6.8+git58f9101

$ kubectl -n awx exec <awx-task-pod> -c awx-ee -- receptor --version
1.4.8+d7fe592
## Summary `Containerfile:65` copies the receptor binary from the mutable `quay.io/ansible/receptor:devel` tag: ``` COPY --from=quay.io/ansible/receptor:devel /usr/bin/receptor /usr/bin/receptor ``` This pulls an arbitrary pre-release build. In the current image it is `receptor 1.6.8+git58f9101`, while the AWX controller that dispatches these jobs ships `receptor 1.4.8+d7fe592`. ## Why it matters For AWX container-group jobs (the normal path) the pod runs: ``` args = ['ansible-runner', 'worker', '--private-data-dir=/runner'] ``` i.e. the entry process is `ansible-runner worker`, not `receptor` (`awx/main/utils/execution_environments.py`). So the copied binary is unused in that topology — it just adds a ~73 MB layer: ``` <missing> ... COPY /usr/bin/receptor /usr/bin/receptor # buildkit 73.4MB ``` If the image is ever used as an execution node, the version skew against the controller (1.6.8 vs 1.4.8) becomes a real compatibility risk. ## Suggested fix Pick one: 1. Drop the `COPY` line (and the corresponding "receptor" claim in `README.md`) since container groups do not need it. Keep `receptorctl` from `requirements.txt`. 2. If receptor is genuinely needed, pin it to the version the target AWX ships, e.g. `quay.io/ansible/receptor:1.4.8`, and add a version check to the smoke test. Do not track a mutable `:devel` tag. ## Verification ``` $ podman run --rm <ee> receptor --version 1.6.8+git58f9101 $ kubectl -n awx exec <awx-task-pod> -c awx-ee -- receptor --version 1.4.8+d7fe592 ```
Author
Owner

Moved to beads: work-c3n

Moved to beads: `work-c3n`
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
daniel/awx-debian-ee#2
No description provided.