General description

The replace-docker-networks.yml playbook is used to change the Docker networks on an already installed NAICE. If you need to change the Docker subnets and reinstall NAICE, refer to the section Reinstallation of NAICE with changed Docker networks. The replace-docker-networks.yml playbook works by copying the updated docker-compose files to the specified hosts and then restarting the NAICE containers.

Changing the networks requires stopping the containers, so while the replace-docker-networks.yml playbook is running, the NAICE services will be temporarily unavailable.

If Peeper Client is used as part of NAICE, manually stop Peeper Client before changing the Docker subnets. To do this, navigate to the client installation folder <NAICE installation folder>/peeper (default: /etc/docker-naice/peeper) and stop it using the command:

sudo ./setup.sh -u

Changing Docker networks

Change the values in the group_vars/networks.yml file to the new network parameters.

Example contents of the group_vars/networks.yml file with default values:

---
# Variables for configuring the Docker network
docker_network_unmasked:
  subnet: "172.18.0.0/20"
  ip_range: "172.18.8.0/21"
  gateway: "172.18.0.1"

docker_network_external:
  subnet: "172.20.0.0/20"
  ip_range: "172.20.8.0/21"
  gateway: "172.20.0.1"

docker_network_internal:
  subnet: "172.21.0.0/20"
  ip_range: "172.21.8.0/21"
  gateway: "172.21.0.1"

Before changing the networks, make sure that the new subnets do not overlap with the existing ones in your infrastructure.

If Peeper Client was previously installed as part of NAICE, manually stop Peeper Client before changing the Docker subnets. To do this, navigate to the client installation folder <NAICE installation directory>/peeper (default: /etc/docker-naice/peeper) and stop it using the command:

cd /etc/docker-naice/peeper
sudo bash ./setup.sh -u

Run the replace-docker-networks.yml playbook to change the Docker networks:

ansible-playbook replace-docker-networks.yml -i inventory/<your-hosts-file>.yml

Preinstalled inventory files:

  • hosts.yml — for stand-alone installation
  • hosts-cluster.yml — for cluster installation with VRRP
  • hosts-geo.yml — for cluster installation without VRRP

Before running the playbook, make sure to specify the correct host addresses in the required file.

After the playbook completes, verify the configuration on the hosts where NAICE is installed:

docker network inspect external
docker network inspect internal
docker network inspect naice-network-unmasked
When using a high-availability configuration, the external network parameters must be identical in the docker-compose.yml and docker-compose.repmgr.yml files.

Reinstallation of NAICE with changed Docker networks

For single-host installation

Stop the containers using the following command:

cd /etc/docker-naice
sudo docker compose down

Delete the Docker networks using the command:

sudo docker network prune

Confirm the deletion:

WARNING! This will remove all custom networks not used by at least one container.
Are you sure you want to continue? [y/N] y

Check that the external, internal, and naice-network-unmasked networks are absent from the command output:

docker network ls

Then perform the installation in accordance with the instructions in v1.2_3.4 Installation using Ansible playbooks (stand-alone).

For installation with high availability

Stop the containers on the nodes running the NAICE services:

cd /etc/docker-naice
docker compose -f docker-compose.yml down

Stop the containers on the PostgreSQL nodes using the command:

cd /etc/docker-naice
docker compose -f docker-compose.repmgr.yml down

Delete the Docker networks on all nodes using the command:

docker network prune

Confirm the deletion:

WARNING! This will remove all custom networks not used by at least one container.
Are you sure you want to continue? [y/N] y

Check that the external, internal, and naice-network-unmasked networks are absent from the command output:

docker network ls

Then perform the installation in accordance with the instructions in v1.2_3.5 High-availability installation (using VRRP) or v1.2_3.6 High-availability installation (without VRRP).