The goal of this project is to provide an up-to-date version of Ansible and agru that people can run in a (Docker) container.
This project was created for spantaleev/matrix-docker-ansible-deploy (see Using Ansible via Docker).
If you need to build it yourself, instead of using the ghcr.io/devture/ansible image that we publish to the GitHub Container Registry.
docker build -t ghcr.io/devture/ansible:latest -f Dockerfile .Releases are tagged automatically as <ansible version>-<release> (e.g. 14.0.0-r0-0), where <ansible version> is the exact version of Alpine's ansible package in the image.
A push to main always refreshes the latest tag. It also creates a new release if the Dockerfile changed since the previous release of the same Ansible version. A weekly scheduled run releases new ansible packages that Alpine starts offering, and does nothing otherwise.
Prefer a tagged release over latest, so that tools like Renovate can keep it up to date for you.
If you can connect to the remote server using SSH, use the following command:
cd /some/ansible-project
docker run \
-it \
--rm \
-w /work \
--mount type=bind,src=`pwd`,dst=/work \
--mount type=bind,src=$HOME/.ssh/id_ed25519,dst=/root/.ssh/id_ed25519,ro \
--entrypoint=/bin/sh \
ghcr.io/devture/ansible:latestYou can execute ansible-playbook commands as per normal now.
If you'd like to run Ansible in a container on the server, and then target that same server from inside the container, use this:
cd /some/ansible-project
docker run \
-it \
--rm \
--privileged \
--pid=host \
-w /work \
--mount type=bind,src=`pwd`,dst=/work \
--entrypoint=/bin/sh \
ghcr.io/devture/ansible:latestWhen invoking the ansible-playbook commands, ensure that:
-
you either add
--connection=community.docker.nsenterto the command (e.g.ansible-playbook --connection=community.docker.nsenter ...) -
or that you've set
ansible_connection=community.docker.nsenterfor each host that needs it in your Ansiblehostsfile
Since Ansible 2.21, forked workers lose the controlling terminal, so SSH cannot prompt you (neither to confirm an unknown host key, nor for the passphrase of an SSH key).
This image therefore sets StrictHostKeyChecking accept-new: keys of previously unknown hosts are accepted automatically and a changed host key still fails loudly. To verify host keys yourself, mount your own known_hosts file (--mount type=bind,src=$HOME/.ssh/known_hosts,dst=/root/.ssh/known_hosts,ro).
For a passphrase-protected SSH key, use an ssh-agent instead of mounting the key: --mount type=bind,src=$SSH_AUTH_SOCK,dst=/ssh-agent --env SSH_AUTH_SOCK=/ssh-agent.