unable to control swarm ingress network with ansible

Viewed 302

I'm deploying Docker swarm with ansible and I would like to ensure the ingress network has been created. In that aim, I configured the following task :

 - name: Ensure ingress network exists
   docker_network:
     state: present
     name: ingress
     driver: overlay
     driver_options:
       ingress: true

And I'm getting the following error :

An exception occurred during task execution. To see the full traceback, use -vvv. The error was: docker.errors.NotFound: 404 Client Error for http+docker://localhost/v1.41/networks/ingress/disconnect: Not Found ("No such container: ingress-endpoint")
fatal: [swarm-srv-1]: FAILED! => {"changed": false, "msg": "An unexpected docker error occurred: 404 Client Error for http+docker://localhost/v1.41/networks/ingress/disconnect: Not Found (\"No such container: ingress-endpoint\")"}

I've tried to add some arguments likes :

     scope: swarm
     force: yes

But no changes... I've also tried to delete the ingress with ansible (state: absent), but I always get the same error.

Note that I don't face any issue when trying to delete a recreate the ingress network manually on the swarm :

docker network rm ingress

I don't know how to resolve that issue...Any help would be appreciated. Thanks !

Here are some informations that may help...

 # docker version
 Version:           20.10.6
 API version:       1.41
 Go version:        go1.13.15
 Git commit:        370c289
 Built:             Fri Apr  9 22:47:35 2021
 OS/Arch:           linux/amd64



# docker inspect ingress
[
    {
        "Name": "ingress",
        "Id": "yb2tkhep8vtaj9q7w3mssc9lx",
        "Created": "2021-05-19T05:53:27.524446929-04:00",
        "Scope": "swarm",
        "Driver": "overlay",
        "EnableIPv6": false,
        "IPAM": {
            "Driver": "default",
            "Options": null,
            "Config": [
                {
                    "Subnet": "10.0.0.0/24",
                    "Gateway": "10.0.0.1"
                }
            ]
        },
        "Internal": false,
        "Attachable": false,
        "Ingress": true,
        "ConfigFrom": {
            "Network": ""
        },
        "ConfigOnly": false,
        "Containers": {
            "ingress-sbox": {
                "Name": "ingress-endpoint",
                "EndpointID": "dfdc0f123d21a196c7a815c7e0a886924d0799ae5f3be2d38b64d527ed4620b1",
                "MacAddress": "02:42:0a:00:00:02",
                "IPv4Address": "10.0.0.2/24",
                "IPv6Address": ""
            }
        },
        "Options": {
            "com.docker.network.driver.overlay.vxlanid_list": "4096"
        },
        "Labels": {},
        "Peers": [
            {
                "Name": "8f8932d6f99f",
                "IP": "(ip address here)"
            },
            {
                "Name": "28b9ca95dcf0",
                "IP": "(ip address here)"
            },
            {
                "Name": "f7c48c8af2f5",
                "IP": "(ip address here)"
            }
        ]
    }
]
1 Answers

I had the exact same issue when trying to customize the IP range of the ingress network. It looks like the docker_network module does not support modification of swarm specific networks: there is a open Github issue for this.

I went for the ugly workaround of removing the network by executing it through a shell (docker network rm ingress command) and adding it again. When adding it with the docker_network module, I found that adding also seems not be working (fails to set the ingress property of the network). So I ended up doing both remove- and create operation through a shell command.

Since the removal will trigger a confirmation dialogue:

WARNING! Before removing the routing-mesh network, make sure all the nodes in your swarm run the same docker engine version. Otherwise, removal may not be effective and functionality of newly create ingress networks will be impaired.
Are you sure you want to continue? [y/N]

I used the expect module to confirm the dialogue:

- name: remove default ingress network
  ansible.builtin.expect:
      command: docker network rm ingress
      responses:
        "[y/N]": "y"

- name: create customized ingress network
  shell: "docker network create --ingress --subnet {{ docker_ingress_network }} --driver overlay ingress"

It is not perfect but it works.

There was one last problem I experienced: when running it on an existing swarm I ended up having network issues on the node where I did run this (somehow the docker_gwbridge network on that node could not handle the change). The fix for this was to fully remove the node and re-join the swarm (regenerates the docker_gwbridge).

Related