You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

停止父容器时如何解除子容器的Docker网络关联?Ansible部署问题

Solution to "error while removing network: network appnetwork has active endpoints" in Ansible-Docker Workflow

Let’s break down why you’re hitting this issue first: Your pre_tasks try to stop/remove the main containers (and their attached network) before the role tasks can stop the sub-project containers that are still using that same network. Since Ansible runs pre_tasks first, then roles, sub-containers are still active when the main container’s docker_compose: state=absent tries to delete the network—hence the error.

Here are two reliable fixes you can implement:

Fix 1: Stop Sub-Containers Before Main Containers (Dynamic Pre-Task)

Since you already have per-role stop logic, we can pull that into pre_tasks to run it before touching the main containers.

  1. Extract stop tasks into a reusable file for each role
    For each project role (e.g., app-admin), create a tasks/stop_container.yml file with just the stop logic:

    ---
    - name: Stop existing {{ name }} docker containers
      docker_compose:
        project_src: "{{ dockerComposeFileDestination }}"
        state: absent
    

    Move the stop task from main.yml into this new file, then include it back in main.yml if you still need it there:

    # app-admin/tasks/main.yml
    ---
    - include_tasks: stop_container.yml
    # rest of your existing tasks...
    
  2. Add a dynamic pre-task to stop sub-containers first
    In your main playbook’s pre_tasks, right before stopping the main containers, add this loop to stop all relevant sub-project containers:

    # Pre-tasks section in your main playbook
    - name: Stop active sub-project containers first
      include_tasks: "../roles/{{ item }}/tasks/stop_container.yml"
      loop: "{{ filteredProjectsList }}"
      when: item != 'all'  # Skip 'all' since we handle individual projects
      vars:
        name: "{{ item }}"
        dockerComposeFileDestination: "{{ lookup('vars', item + '_docker_path') }}"  # Match your role's var naming
    

    Note: Make sure role variables like dockerComposeFileDestination are accessible here—you might need to define them as global vars or pass them explicitly.

    Now the flow becomes:

    • Stop sub-project containers → removes their network endpoints
    • Stop main containers → network can be removed without errors

Fix 2: Mark the Network as External (Avoid Deleting It)

If you don’t need to delete the network when stopping main containers, mark it as external in both main and sub-project docker-compose files. This tells Docker Compose not to manage the network’s lifecycle.

  1. Create the network explicitly in Ansible
    Add this task to your pre_tasks (before starting any containers):

    - name: Ensure appnetwork exists
      docker_network:
        name: appnetwork
        state: present
    
  2. Update main container's docker-compose.yml
    Set the network as external so Compose won’t try to delete it when stopping:

    networks:
      appnetwork:
        external: true
    
  3. Keep sub-projects' docker-compose.yml as is
    You already set external: true here, so they’ll use the pre-created network without issues.

    With this setup, running docker_compose: state=absent on main containers only stops/removes the containers—not the network. Since the network isn’t being deleted, active endpoints from sub-containers won’t trigger an error.

Which Fix Should You Choose?

  • Use Fix 1 if you need full cleanup (including the network) every time you run the playbook.
  • Use Fix 2 if you want to keep the network persistent (faster subsequent runs, as you don’t recreate the network each time).

内容的提问来源于stack exchange,提问作者Bogdan Dubyk

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 09:12:30