From a9f51b77e131a26ec973185c93a6acdb8adb5151 Mon Sep 17 00:00:00 2001 From: Bastian de Byl Date: Sun, 13 Sep 2026 23:14:46 -0400 Subject: [PATCH] fix(podman): pull a new image before removing the running container podman-check deleted the old container as soon as the pinned image differed, and the create task pulled afterwards. A tag that did not exist, or a registry that was down, therefore left the service with no container at all. The pull now happens first, so that failure stops the play with the old container still running. localhost/ images are built and loaded by hand and are never pulled. The pull is skipped when the container does not exist yet: there is nothing to protect, and containers[0] is not there to compare against. Without that guard the first deploy of any new service failed on the conditional -- rsvp was the first to hit it. Co-Authored-By: Claude Opus 5 --- .../podman/tasks/podman/podman-check.yml | 19 ++++++++++++++++++- 1 file changed, 18 insertions(+), 1 deletion(-) diff --git a/ansible/roles/podman/tasks/podman/podman-check.yml b/ansible/roles/podman/tasks/podman/podman-check.yml index d1a8985..ad366f8 100644 --- a/ansible/roles/podman/tasks/podman/podman-check.yml +++ b/ansible/roles/podman/tasks/podman/podman-check.yml @@ -12,6 +12,23 @@ when: container.containers[0]["ImageName"] != container_image ignore_errors: true +# Pull the new image BEFORE the old container is removed, so a tag that does +# not exist (or a registry that is down) fails the play here and leaves the +# running container untouched. Locally built images (localhost/...) are never +# pulled - they must already be in the podman user's storage. A container that +# does not exist yet has nothing to protect (and no containers[0] to compare), +# so the length check comes first; `when` list items stop at the first false. +- name: pull new image before replacing container + become: true + become_user: "{{ podman_user }}" + containers.podman.podman_image: + name: "{{ container_image }}" + state: present + when: + - container.containers | length > 0 + - container.containers[0]["ImageName"] != container_image + - not container_image.startswith("localhost/") + - name: delete container if necessary become: true become_user: "{{ podman_user }}" @@ -19,4 +36,4 @@ name: "{{ container_name }}" state: absent when: container.containers[0]["ImageName"] != container_image - ignore_errors: true \ No newline at end of file + ignore_errors: true