The playbook runs a full distribution upgrade as part of fresh install. If accidentally run against a production host (e.g., a Prod server mistakenly in the target group), it can upgrade the OS while services are running.
Fix
Add a safety guard that aborts if Docker containers are already running:
- name:Abort if containers are already runningansible.builtin.shell:docker compose ps -qargs:chdir:~/dockerregister:runningfailed_when:running.stdout != ""ignore_errors:false
Or split the dist-upgrade step into its own dedicated playbook.
File:playbooks/fresh_install.yml
## Problem
The playbook runs a full distribution upgrade as part of fresh install. If accidentally run against a production host (e.g., a Prod server mistakenly in the target group), it can upgrade the OS while services are running.
## Fix
Add a safety guard that aborts if Docker containers are already running:
```yaml
- name: Abort if containers are already running
ansible.builtin.shell: docker compose ps -q
args:
chdir: ~/docker
register: running
failed_when: running.stdout != ""
ignore_errors: false
```
Or split the dist-upgrade step into its own dedicated playbook.
**File:** `playbooks/fresh_install.yml`
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Problem
The playbook runs a full distribution upgrade as part of fresh install. If accidentally run against a production host (e.g., a Prod server mistakenly in the target group), it can upgrade the OS while services are running.
Fix
Add a safety guard that aborts if Docker containers are already running:
Or split the dist-upgrade step into its own dedicated playbook.
File:
playbooks/fresh_install.yml