You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Ansible在远程RHEL VM从二进制安装Docker CE启动失败求助

Troubleshooting Docker CE Binary Installation on RHEL via Ansible

Let's tackle this step by step—first fixing that directory ownership anomaly, then troubleshooting the Docker daemon startup failure, and finally refining your playbook to avoid these headaches in the future.

1. Fixing Docker Directory Ownership Issues

It sounds like when you extracted the Docker binary archive, the resulting docker directory ended up with incorrect user/group permissions (probably tied to the Ansible user you're running the playbook with, instead of root). Docker requires its core binaries and directories to be owned by root to function properly.

Add this task to your playbook right after the unarchive step to correct permissions recursively:

- name: Fix Docker directory and binary permissions
  ansible.builtin.file:
    path: /path/to/your/extracted/docker
    state: directory
    owner: root
    group: root
    mode: '0755'
    recurse: yes

Pro tip: You can avoid this extra step entirely by specifying owner and group directly in the unarchive module when extracting the binary package:

- name: Extract Docker binary archive to target directory
  ansible.builtin.unarchive:
    src: /path/to/local/docker-ce-binaries.tgz  # Or remote URL if pulling directly
    dest: /opt/docker  # Replace with your target path
    remote_src: no
    owner: root
    group: root
    creates: /opt/docker/docker

2. Troubleshooting Docker Daemon Startup Failure

Most startup failures after binary installs tie back to permissions, missing dependencies, or misconfigured systemd integration. Let's cover the most common fixes:

a. Ensure Binaries Are Executable

Even if ownership is correct, the Docker binaries might lack execute permissions. Add this task to enforce that:

- name: Verify Docker binaries have execute permissions
  ansible.builtin.file:
    path: "{{ item }}"
    mode: '0755'
    owner: root
    group: root
  loop:
    - /opt/docker/dockerd
    - /opt/docker/docker
    - /opt/docker/runc
    - /opt/docker/containerd

b. Install Required RHEL Dependencies

RHEL requires container-selinux for Docker to work with SELinux (which is enabled by default). Skip this only if you've disabled SELinux entirely:

- name: Install mandatory Docker dependencies on RHEL
  ansible.builtin.yum:
    name: container-selinux
    state: present
    update_cache: yes

c. Configure Systemd for Docker (If Using It)

If you're trying to start Docker via systemd (instead of running dockerd directly), you need a valid systemd unit file pointing to your custom binary path. Add this task to create it:

- name: Create Docker systemd service file
  ansible.builtin.copy:
    dest: /etc/systemd/system/docker.service
    content: |
      [Unit]
      Description=Docker Application Container Engine
      Documentation=https://docs.docker.com
      After=network-online.target firewalld.service
      Wants=network-online.target

      [Service]
      Type=notify
      ExecStart=/opt/docker/dockerd  # Match your binary path here
      ExecReload=/bin/kill -s HUP $MAINPID
      LimitNOFILE=infinity
      LimitNPROC=infinity
      TimeoutStartSec=0
      Restart=always
      StartLimitBurst=3
      StartLimitInterval=60s

      [Install]
      WantedBy=multi-user.target
  notify: Reload systemd and start Docker

Then add this handler to your playbook to apply the systemd changes:

handlers:
  - name: Reload systemd and start Docker
    ansible.builtin.systemd:
      name: docker
      daemon_reload: yes
      state: started
      enabled: yes

d. Manual Debugging (If All Else Fails)

If the playbook still fails, log into your RHEL VM and run these commands to get detailed error info:

  1. Run the daemon directly to see real-time errors:
    /opt/docker/dockerd --debug
    
  2. Check systemd logs if you're using the service:
    journalctl -u docker.service -f
    
  3. Verify SELinux isn't blocking Docker:
    sestatus
    # Temporarily set to permissive to test:
    setenforce 0
    

Even though you skipped setting the PATH by using full binary paths, adding it to the system environment will make future Docker commands (like docker run) easier to run without typing the full path:

- name: Add Docker binaries to system PATH
  ansible.builtin.lineinfile:
    path: /etc/profile.d/docker.sh
    line: 'export PATH=$PATH:/opt/docker'
    create: yes

内容的提问来源于stack exchange,提问作者silo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:38:15