A system administrator is troubleshooting a container that fails to start with the error: 'Error: cannot start container: listen tcp4 :80: bind: address already in use'. The container is intended to serve HTTP traffic on port 80. What is the most appropriate first step to resolve this issue?
Trap 1: Add --force to the podman run command
The `--force` flag is not a valid option for `podman run`; it is used with `podman rm` or `podman stop` to forcefully terminate a running or stopped container without waiting for graceful shutdown. Even if you attempted to pass it, it would be rejected by Podman's CLI parser, and it would not address the underlying port conflict. To fix the error, you must either stop the process already bound to port 80 or map the container to a different host port, such as `-p 8080:80`.
Trap 2: Add --replace to the podman run command
The `--replace` option tells Podman to remove any existing container with the same name before creating the new one, so it only resolves name collisions, not port conflicts. If port 80 is already occupied, the new container will still fail to bind regardless of whether `--replace` is present, because the conflict is with an external process or another container's port forward. It is therefore the wrong tool for this scenario.
Trap 3: Use --net=host to bypass the port mapping
With `--net=host`, the container shares the host's network namespace and binds directly to host interfaces, bypassing the need for `-p` port mappings entirely. However, this does not grant any special ability to re-bind an already-occupied port: if a host process is listening on port 80, the container's service will encounter the same 'address already in use' error. The only way to avoid the conflict is to free the port or change the port that the container's service uses.
- A
Add --force to the podman run command
Why it fails: The `--force` flag is not a valid option for `podman run`; it is used with `podman rm` or `podman stop` to forcefully terminate a running or stopped container without waiting for graceful shutdown. Even if you attempted to pass it, it would be rejected by Podman's CLI parser, and it would not address the underlying port conflict. To fix the error, you must either stop the process already bound to port 80 or map the container to a different host port, such as `-p 8080:80`.
- B
Check which process is using port 80 and either stop that process or use a different host port
Start by identifying which process holds port 80 with `ss -tlnp` or `lsof -i :80`; the output shows the process ID and name. You can then stop that service with `systemctl stop` or `kill` if it is no longer needed, or simply run the container with a different host port mapping like `-p 8080:80` to avoid the conflict. This is the standard, correct approach because it either frees the required resource or selects an unused port.
- C
Add --replace to the podman run command
Why it fails: The `--replace` option tells Podman to remove any existing container with the same name before creating the new one, so it only resolves name collisions, not port conflicts. If port 80 is already occupied, the new container will still fail to bind regardless of whether `--replace` is present, because the conflict is with an external process or another container's port forward. It is therefore the wrong tool for this scenario.
- D
Use --net=host to bypass the port mapping
Why it fails: With `--net=host`, the container shares the host's network namespace and binds directly to host interfaces, bypassing the need for `-p` port mappings entirely. However, this does not grant any special ability to re-bind an already-occupied port: if a host process is listening on port 80, the container's service will encounter the same 'address already in use' error. The only way to avoid the conflict is to free the port or change the port that the container's service uses.