Files
deploy_home/ansible/roles/podman/tasks/podman/podman-check.yml
T
Bastian de BylandClaude Opus 5 a9f51b77e1 fix(podman): pull a new image before removing the running container
podman-check deleted the old container as soon as the pinned image differed,
and the create task pulled afterwards. A tag that did not exist, or a registry
that was down, therefore left the service with no container at all. The pull
now happens first, so that failure stops the play with the old container still
running. localhost/ images are built and loaded by hand and are never pulled.

The pull is skipped when the container does not exist yet: there is nothing to
protect, and containers[0] is not there to compare against. Without that guard
the first deploy of any new service failed on the conditional -- rsvp was the
first to hit it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-13 23:14:46 -04:00

40 lines
1.4 KiB
YAML

---
- name: get container info
become: true
become_user: "{{ podman_user }}"
containers.podman.podman_container_info:
name: "{{ container_name }}"
register: container
- name: check
debug:
msg: "image '{{ container.containers[0]['ImageName'] }}' not equivalent to '{{ container_image }}'!"
when: container.containers[0]["ImageName"] != container_image
ignore_errors: true
# Pull the new image BEFORE the old container is removed, so a tag that does
# not exist (or a registry that is down) fails the play here and leaves the
# running container untouched. Locally built images (localhost/...) are never
# pulled - they must already be in the podman user's storage. A container that
# does not exist yet has nothing to protect (and no containers[0] to compare),
# so the length check comes first; `when` list items stop at the first false.
- name: pull new image before replacing container
become: true
become_user: "{{ podman_user }}"
containers.podman.podman_image:
name: "{{ container_image }}"
state: present
when:
- container.containers | length > 0
- container.containers[0]["ImageName"] != container_image
- not container_image.startswith("localhost/")
- name: delete container if necessary
become: true
become_user: "{{ podman_user }}"
containers.podman.podman_container:
name: "{{ container_name }}"
state: absent
when: container.containers[0]["ImageName"] != container_image
ignore_errors: true