Rollback Partial Image Layers on Cancel vs. Abandon Operation: Which Should Portainer Choose?
26K reputation · 15 Aug 2025, 12:16 UTC
Goal
Determine whether Portainer should automatically roll back partially completed operations—such as incomplete image layers pulled during a registry pull—when a user invokes the Cancel button, or whether it should leave those artifacts intact and rely on manual cleanup.
Constraints and Uncertainty
Portainer’s current cancellation flow sends a DELETE signal to the Docker engine and starts a 30‑second watchdog that forces the HTTP connection closed if the daemon does not acknowledge the cancel. When the watchdog expires, the task is marked failed but the Docker process may continue running, leaving pulled layers on disk. No rollback mechanism is implemented, and the trade‑off involves balancing immediate UI responsiveness against the risk of orphaned resources and disk consumption.
Should Portainer attempt to clean up those partial layers on cancel? If so, what safety checks are needed to avoid removing layers still in use by other containers? How would adding rollback logic interact with the existing timeout watchdog and affect overall reliability?