diff --git a/ansible/roles/podman/tasks/podman/podman-check.yml b/ansible/roles/podman/tasks/podman/podman-check.yml index d1a8985..ad366f8 100644 --- a/ansible/roles/podman/tasks/podman/podman-check.yml +++ b/ansible/roles/podman/tasks/podman/podman-check.yml @@ -12,6 +12,23 @@ when: container.containers[0]["ImageName"] != container_image ignore_errors: true +# Pull the new image BEFORE the old container is removed, so a tag that does +# not exist (or a registry that is down) fails the play here and leaves the +# running container untouched. Locally built images (localhost/...) are never +# pulled - they must already be in the podman user's storage. A container that +# does not exist yet has nothing to protect (and no containers[0] to compare), +# so the length check comes first; `when` list items stop at the first false. +- name: pull new image before replacing container + become: true + become_user: "{{ podman_user }}" + containers.podman.podman_image: + name: "{{ container_image }}" + state: present + when: + - container.containers | length > 0 + - container.containers[0]["ImageName"] != container_image + - not container_image.startswith("localhost/") + - name: delete container if necessary become: true become_user: "{{ podman_user }}" @@ -19,4 +36,4 @@ name: "{{ container_name }}" state: absent when: container.containers[0]["ImageName"] != container_image - ignore_errors: true \ No newline at end of file + ignore_errors: true