停止父容器时如何解除子容器的Docker网络关联?Ansible部署问题
Let’s break down why you’re hitting this issue first: Your pre_tasks try to stop/remove the main containers (and their attached network) before the role tasks can stop the sub-project containers that are still using that same network. Since Ansible runs pre_tasks first, then roles, sub-containers are still active when the main container’s docker_compose: state=absent tries to delete the network—hence the error.
Here are two reliable fixes you can implement:
Fix 1: Stop Sub-Containers Before Main Containers (Dynamic Pre-Task)
Since you already have per-role stop logic, we can pull that into pre_tasks to run it before touching the main containers.
Extract stop tasks into a reusable file for each role
For each project role (e.g.,app-admin), create atasks/stop_container.ymlfile with just the stop logic:--- - name: Stop existing {{ name }} docker containers docker_compose: project_src: "{{ dockerComposeFileDestination }}" state: absentMove the stop task from
main.ymlinto this new file, then include it back inmain.ymlif you still need it there:# app-admin/tasks/main.yml --- - include_tasks: stop_container.yml # rest of your existing tasks...Add a dynamic pre-task to stop sub-containers first
In your main playbook’s pre_tasks, right before stopping the main containers, add this loop to stop all relevant sub-project containers:# Pre-tasks section in your main playbook - name: Stop active sub-project containers first include_tasks: "../roles/{{ item }}/tasks/stop_container.yml" loop: "{{ filteredProjectsList }}" when: item != 'all' # Skip 'all' since we handle individual projects vars: name: "{{ item }}" dockerComposeFileDestination: "{{ lookup('vars', item + '_docker_path') }}" # Match your role's var namingNote: Make sure role variables like
dockerComposeFileDestinationare accessible here—you might need to define them as global vars or pass them explicitly.Now the flow becomes:
- Stop sub-project containers → removes their network endpoints
- Stop main containers → network can be removed without errors
Fix 2: Mark the Network as External (Avoid Deleting It)
If you don’t need to delete the network when stopping main containers, mark it as external in both main and sub-project docker-compose files. This tells Docker Compose not to manage the network’s lifecycle.
Create the network explicitly in Ansible
Add this task to your pre_tasks (before starting any containers):- name: Ensure appnetwork exists docker_network: name: appnetwork state: presentUpdate main container's docker-compose.yml
Set the network as external so Compose won’t try to delete it when stopping:networks: appnetwork: external: trueKeep sub-projects' docker-compose.yml as is
You already setexternal: truehere, so they’ll use the pre-created network without issues.With this setup, running
docker_compose: state=absenton main containers only stops/removes the containers—not the network. Since the network isn’t being deleted, active endpoints from sub-containers won’t trigger an error.
Which Fix Should You Choose?
- Use Fix 1 if you need full cleanup (including the network) every time you run the playbook.
- Use Fix 2 if you want to keep the network persistent (faster subsequent runs, as you don’t recreate the network each time).
内容的提问来源于stack exchange,提问作者Bogdan Dubyk

