Execution Environment from docs doesn't install Python in container

Hi all!

I tried to set up an Execution Environment following the official articles Setting up your environment and Building your first Execution Environment, but the builder command fails (not all lines shown):

ansible-builder build --tag postgresql_ee --container-runtime docker
...
 > [base 5/6] RUN /output/scripts/pip_install /usr/bin/python3:
0.169 + PYCMD=/usr/bin/python3
0.169 + '[' -z /usr/bin/python3 ']'
0.169 + '[' '!' -x /usr/bin/python3 ']'
0.169 + echo '/usr/bin/python3 is not an executable'
0.169 + exit 1
0.169 /usr/bin/python3 is not an executable
------
Dockerfile:26
--------------------
  24 |     COPY _build/scripts/entrypoint /opt/builder/bin/entrypoint
  25 |     RUN $PKGMGR install $PYPKG -y ; if [ -z $PKGMGR_PRESERVE_CACHE ]; then $PKGMGR clean all; fi
  26 | >>> RUN /output/scripts/pip_install $PYCMD
  27 |     RUN $PYCMD -m pip install --no-cache-dir $ANSIBLE_INSTALL_REFS
...

I am using a Python virtual environment, from this official procedure, because my attempt to use Pip failed:

pip install ansible-navigator
error: externally-managed-environment
...
    If you wish to install a non-Debian-packaged Python package,
    create a virtual environment using python3 -m venv path/to/venv.
...

The Dockerfile context/Dockerfile installs Python and the Execution Environment file execution-environment.yml lists Python as a dependency. But, somehow, the process runs /output/scripts/pip_install /usr/bin/python3 without Python installed. I also inserted a rpm -qa | grep python and a find / -type f -name 'python*' -exec ls -l '{}' \+ in pip_install script, and confirmed there’s no Python in the container.

Questions:

  1. What can be going wrong?
  2. Is there any log or option to see full output? ansible-builder only show last 20 lines of output, so I don’t know if there’s any earlier error.

My setup

  • OS: Ubuntu 24.04.2 LTS
  • Running on: WSL 2.7.13.0
  • Docker version: 29.1.3
  • docker-compose version: 1.29.2
  • Python venv version: 3.12.3
  • Non-privileged user, included in docker group

I installed Podman (version 4.9.3) and ran again, getting some new warnings. Can this lack of multiple capabilities prevent Python installation?

ansible-builder build --tag postgresql_ee
File context/_build/scripts/pip_install had modifications and will be rewritten
Running command:
  podman build -f context/Containerfile -t postgresql_ee context
...showing last 20 lines of output...
--> 94015b39d9b9
[1/4] STEP 15/16: RUN /output/scripts/pip_install $PYCMD
time="2026-09-07T18:11:23-03:00" level=warning msg="can't raise ambient capability CAP_CHOWN: operation not permitted"
time="2026-09-07T18:11:23-03:00" level=warning msg="can't raise ambient capability CAP_DAC_OVERRIDE: operation not permitted"
time="2026-09-07T18:11:23-03:00" level=warning msg="can't raise ambient capability CAP_FOWNER: operation not permitted"
time="2026-09-07T18:11:23-03:00" level=warning msg="can't raise ambient capability CAP_FSETID: operation not permitted"
time="2026-09-07T18:11:23-03:00" level=warning msg="can't raise ambient capability CAP_KILL: operation not permitted"
time="2026-09-07T18:11:23-03:00" level=warning msg="can't raise ambient capability CAP_NET_BIND_SERVICE: operation not permitted"
time="2026-09-07T18:11:23-03:00" level=warning msg="can't raise ambient capability CAP_SETFCAP: operation not permitted"
time="2026-09-07T18:11:23-03:00" level=warning msg="can't raise ambient capability CAP_SETGID: operation not permitted"
time="2026-09-07T18:11:23-03:00" level=warning msg="can't raise ambient capability CAP_SETPCAP: operation not permitted"
time="2026-09-07T18:11:23-03:00" level=warning msg="can't raise ambient capability CAP_SETUID: operation not permitted"
time="2026-09-07T18:11:23-03:00" level=warning msg="can't raise ambient capability CAP_SYS_CHROOT: operation not permitted"
+ PYCMD=/usr/bin/python3
+ '[' -z /usr/bin/python3 ']'
+ '[' '!' -x /usr/bin/python3 ']'
/usr/bin/python3 is not an executable
+ echo '/usr/bin/python3 is not an executable'
+ exit 1
Error: building at STEP "RUN /output/scripts/pip_install $PYCMD": while running runtime: exit status 1

An error occurred (rc=1), see output line(s) above for details.

The host venv shouldn’t affect the EE build—the Python interpreter must be installed inside the base image. I’d first check the generated Dockerfile and confirm that $PKGMGR install $PYPKG actually succeeds before pip_install runs.

Hello,
my build environment is quite different (rhel / podman), but a few things come to my mind :

Good. Since ansible-build only prints last 20 lines of output, I’ll have to find a way to see this step output. I’ll try to edit the Dockerfile to skip further steps.
Do you know of a way to see more output?

The docs point to registry.fedoraproject.org/fedora:42

Nice. Will try that.

Nice too. The docs point to python3, which matches the error messages I could see. I’ll try setting it to 3.12, which is what I have in that station.

The error is inside the docker container, your local Python environment is completely separate from that. So running ansible_builder in a venv does not affect how python is running inside the docker container.

Did you accidentally remove the'python_interpreter: package_system: python3 lines from the execution_environment.yaml? That step should install python3.

Thanks, @johan , this did help. I changed the python_interpreter settings to python310 and, in one station, it worked. In another one, dnf failed repo certificates (output available thanks to -v3):

Failed to download metadata (metalink: "https://mirrors.fedoraproject.org/metalink?repo=updates-released-f42&arch=x86_64") for repository "updates": Cannot prepare internal mirrorlist: Curl error (60): SSL peer certificate or SSH remote key was not OK for https://mirrors.fedoraproject.org/metalink?repo=updates-released-f42&arch=x86_64 [SSL certificate problem: unable to get local issuer certificate]

This certificate should be installed in the container image, correct? Should ansible-builder update needed certificates before trying to install things via dnf, or can it be a problem from the base image itself?

I can’t find a difference between the stations so one works and the other doesn’t. Maybe a different podman version, but I can hardly think of how this would change curl error…

No, the first attempts were with execution_environment.yaml just copied from instructions. The problem is indeed Python installation failure, but the cause is still obscure.

I tried the example and it works fine for me, so nothing outside of those docs should be needed.

Do you have a proxy in your environment? Since the commands run in a container, they wouldn’t inherit any proxy configurations. A proxy is the only common issue I can think of that would cause that curl error, when I’ve verified the instructions work here.

Hi, @sivel !

Does it mean that a proxy can have its own certificate chain, which should be installed in the container, before running anything internet related?

What do you get if you browse on your builder machine without proxy?

If there’s a proxy in your environment, see How to use proxy while creating Execution Environments in disconnected Ansible Automation Platform 2.x setup ? - Red Hat Customer Portal

---
version: 3
additional_build_steps:
  prepend_base:
    - RUN pip3 config --global set global.trusted-host "pypi.org files.pythonhosted.org pypi.python.org"
    - RUN pip3 config --user set global.proxy "http://proxy.example.com"
  prepend_builder:
    - ENV http_proxy=proxy.example.com
    - ENV HTTP_PROXY=proxy.example.com
    - ENV https_proxy=proxy.example.com
    - ENV HTTPS_PROXY=proxy.example.com

* To add http/s proxy permanently to the resulted image (not only during the image build) :

additional_build_steps:
  append_final:
    - ENV http_proxy=proxy.example.com
    - ENV HTTP_PROXY=proxy.example.com
    - ENV https_proxy=proxy.example.com
    - ENV HTTPS_PROXY=proxy.example.com

Hi, @ildjarn !

It just works.
I’m testing in 2 different machines: my personal notebook, with direct internet access, and my workstation, with fixed proxy settings - I don’t have permission to change them. I think I got the correct proxy URL and will experiment more.

I got this:

/bin/sh: line 1: pip3: command not found

Checking the resulting ContainerFile (for the Podman flavour), I see this command ends up before Python installation. I messed around a bit with execution-environment.yml, but I really don’t know enough what I’m doing, and just got different errors.
I’ll start over without the pip3 commands when I can get back to this machine.

After all, it seems the proxy is indeed the culprit here.