October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk9 min

Keeping Your Whole Docker Stack Safely Up to Date

Updating a Docker Compose stack safely means handling three things separately: the image references in your configuration, the containers running from them, and the data they hold. A reviewed update workflow keeps those under control.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The safe way to keep a whole Docker stack current is to treat it as a reviewed change, not a background event. Pulling a newer image does not change what your Compose file refers to, and recreating a container can destroy data that existed only in its writable layer. A controlled workflow separates three things: the image references in your configuration, the containers running from them, and the data they hold. You decide when each one changes.

Why updating a stack is more than pulling images

A Compose file describes a project: a set of services that can be built, pulled, and started together. Each service points to an image reference, or to a local build, and each running container is an instance created from that configuration. Three layers are involved, and an update can touch any of them.

  • The configuration. The image: line in compose.yaml (or docker-compose.yml) is the source of truth for which image a service uses. Downloading a newer image leaves this line untouched.
  • The images on the host. Pulling stores new image layers locally. Running containers keep using the image they were created from until they are recreated.
  • The containers and their data. Recreating a container gives it a fresh writable layer. Anything written there that was not stored in a volume or bind mount is gone with the old container.

Because these layers are separate, a stack can look up to date on disk while its containers still run old images, or it can be recreated from a configuration that quietly resolves to something different than you reviewed. The rest of this article works through each layer.

Tags, digests, and what each one guarantees

An image tag such as alpine:3.21 is a name that can be re-pointed. Docker’s build documentation notes that a tag like this can resolve to a newer patch image later, which is usually what you want for security fixes and occasionally not what you want for reproducibility. Docker’s Compose trust guidance states it directly: “Tags are mutable.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
UGREEN NAS DH2300 2-Bay for Beginners & Personal Users, Phone Backup
  • Entry-level NAS Personal Storage:UGREEN NAS DH2300 is your first and best NAS made easy. It is designed for beginners who want a simple, private way to store videos, photos and personal files, which is intuitive for users moving from cloud storage or external drives and move away from scattered date across devices. This entry-level NAS 2-bay perfect for personal entertainment, photo storage, and easy data backup (doesn't support Docker or virtual machines).
  • Set Your Devices Free, Expand Your Digital World: This unified storage hub supports massive capacity up to 64TB.*Storage drives not included. Stop Deleting, Start Storing. You can store 22 million 3MB images, or 2 million 30MB songs, or 43K 1.5GB movies or 67 million 1MB documents! UGREEN NAS is a better way to free up storage across all your devices such as phones, computers, tablets and also does automatic backups across devices regardless of the operating system—Window, iOS, Android or macOS.
  • The Smarter Long-term Way to Store: Unlike cloud storage with recurring monthly fees, a UGREEN NAS enclosure requires only a one-time purchase for long-term use. For example, you only need to pay $459.98 for a NAS, while for cloud storage, you need to pay $719.88 per year, $2,159.64 for 3 years, $3,599.40 for 5 years. You will save $6,738.82 over 10 years with UGREEN NAS! *NAS cost based on DH2300 + 12TB HDD; cloud cost based on 12TB plan (e.g. $59.99/month).
  • Blazing Speed, Minimal Power: Equipped with a high-performance processor, 1GbE port, and 4GB RAM on Board, this NAS handles multiple tasks with ease. File transfers reach up to 125MB/s—a 1GB file takes only 8 seconds. Don't let slow clouds hold you back; they often need over 100 seconds for the same task. The difference is clear.
  • Let AI Better Organize Your Memories: UGREEN NAS uses AI to tag faces, locations, texts, and objects—so you can effortlessly find any photo by searching for who or what's in it in seconds. It also automatically finds and deletes similar or duplicate photo, backs up live photos and allows you to share them with your friends or family with just one tap. Everything stays effortlessly organized, powered by intelligent tagging and recognition.

A digest identifies the exact image content. Pinning a digest fixes the image you run, but it also means you will not receive fixes until someone updates the digest deliberately. In Docker’s Compose trust guidance, the consequence is stated as: “Treat any update to a pinned digest as a code change.”

Approach Example reference What it guarantees What it costs you
Mutable tag image: postgres:16 Receives patch releases when the tag is re-pulled The same configuration can run different contents over time; a tag can be overwritten
Tag plus digest image: postgres:16@sha256:<digest> Runs the exact reviewed content, while the tag stays readable Every security fix requires a digest change you review and merge
Local build build: . Image content depends on your Dockerfile and its base images Base image updates still arrive through tags or digests, so the same question applies

Neither approach is automatically correct. Teams that need reproducible deployments usually pin digests and update them through review. Teams that accept routine patch updates may keep tags and accept that a re-pull can change contents. The point is to choose on purpose and to know which one a given service uses. To find out, run docker compose config from the project directory. It prints the resolved configuration, which shows the image references Compose will use and any interpolated values.

Protect data before you replace containers

Recreating containers is the normal way Compose applies a new image, and it is also where data loss happens. Docker’s getting-started material for Compose states that docker compose down removes containers and the data stored in their writable layers, and it warns that production containers are regularly replaced. Expect replacement as a routine event, and make sure no important state lives only in a container.

Rank #2
Sale
UGREEN NAS DXP2800 2-Bay for Advanced Home Users, Remote Workers & Creators
  • 【Advanced Home Data & Media Hub】For advanced home users who need phone backup, file storage, and centralized data management. Centralize family photos, 4K videos, movies, computer backups, and personal files in one place while running multiple apps for home entertainment and everyday data management. Suitable for households with growing digital libraries and multiple NAS use cases.
  • 【Built for Creators, Media Servers & Advanced Apps】Powered by the Intel N100 Quad-Core CPU, 8GB DDR5 RAM, 2.5GbE networking, and dual M.2 NVMe slots, DXP2800 handles large files and heavier workloads with ease. Run Docker, virtual machines, and media server applications compatible with Plex—ideal for content creators, tech enthusiasts, and advanced home users managing 4K videos, RAW photos, personal media libraries, and multiple NAS apps.
  • 【Up to 80TB for Growing Digital Libraries】 Supports up to 80TB of storage using two HDD bays and two M.2 NVMe SSD slots for family photos, movies, RAW photos, 4K videos, work files, and device backups. AI photo management supports recognition of people, objects, scenes, and locations, album organization, and duplicate photo detection. HDDs and SSDs are not included.
  • 【AI-powered Home Surveillance】Turn DXP2800 into a centralized home surveillance hub by connecting compatible network cameras and storing recordings locally on your NAS. AI-powered features include Face Recognition, People Detection, and Pet Detection, helping advanced home users review important events more efficiently while managing home surveillance and personal data in one place.
  • 【One data Center Across Your Devices】Keep files from desktops, laptops, phones, tablets, and other devices together instead of scattered across cloud accounts and external drives. Access, back up, organize, and share data across Windows, macOS, Android, iOS, web browsers, and compatible smart TVs—ideal for creators and advanced home users working across multiple devices.

Check each service against these questions:

  • Do databases write to a named volume or a bind mount, not to a path inside the container? Named volumes survive docker compose down unless you add -v, which also removes them.
  • Do uploads, generated files, caches you cannot regenerate, or configuration edited inside the container persist outside it?
  • Is there a backup taken from the running service, not only from the configuration, that you have tested by restoring it?

Back up before every update that recreates a stateful service. For databases, use the engine’s own dump or snapshot tool rather than copying files from a running data directory. Store the backup on separate storage, such as an external drive or off-host location, so that a failure on the Docker host does not take the backup with it. A backup you have never restored is an assumption, not a recovery plan.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A controlled manual update workflow

For a stack managed by hand on one host, this sequence keeps each change visible. The commands assume you run them from the directory that holds the Compose file.

  1. Inventory the project. Run docker compose ps to list services and containers, and docker compose config to see the resolved image references. Mark each service as a mutable tag, a digest pin, or a local build.
  2. Review the configuration. Read the file for unfamiliar privileges: host mounts, network_mode: host, devices, privileged: true, and which image each service runs. Docker’s Compose trust guidance notes that a Compose file can control these interactions with the host, so treat changes to them as security-relevant.
  3. Record the current state. Note the image references and, where available, the digests of running images. Keep the current configuration file in version control or a dated copy so you can restore the previous reviewed reference.
  4. Back up stateful services. Complete the backups described above and confirm they are readable.
  5. Update the references. Edit the tag or digest in the configuration deliberately, or accept a tag re-pull for services where that is your policy. Then run docker compose pull to download the images the project declares.
  6. Apply the change. Run docker compose up -d. Compose recreates only the services whose configuration or image changed, and leaves the rest running.
  7. Verify. Run docker compose ps to confirm container states and health, docker compose logs --tail=100 <service> to check for startup errors, and then test the application itself: log in, run a query, exercise a critical path. A container that starts is not the same as a service that works.
  8. Roll back if needed. Restore the previous reviewed image reference, run docker compose pull and docker compose up -d again, and restore data from the backup only if the change altered it. Compose does not roll back a failed update for you.

These steps reflect how Compose handles project lifecycle and image references. They do not guarantee that every stack is free of downtime. A service with a long startup, a schema migration, or a single instance behind no load balancer will be interrupted during recreation. Schedule the change in a window that fits your service, and check each project’s build behavior and dependencies before running the commands unattended.

Rank #3
Sale
UGREEN NAS DH4300 Plus 4-Bay for Beginners, Home Users & Remote Workers
  • Entry-level NAS Home Storage: The UGREEN NAS DH4300 Plus is an entry-level 4-bay NAS that's ideal for home media and vast private storage you can access from anywhere and also supports Docker but not virtual machines. You can record, store, share happy moment with your families and friends, which is intuitive for users moving from cloud storage, or external drives to create your own private cloud, access files from any device.
  • Smart Photo Backup & AI Album: Automatically back up photos and videos from your phone in real time and keep growing family memories organized with AI-powered photo albums. Semantic search, custom learning, and recognition of people, objects, pets, and similar photos help you quickly find the moments you want. Duplicate photo removal also helps keep your library organized—ideal for families and users with large photo collections.
  • User-Friendly App & Easy Setup: Connect quickly via NFC, set up simply and share files fast on Windows, macOS, Android, iOS, web browsers, and smart TVs. You can access data remotely from any of your mixed devices. What's more, UGREEN NAS enclosure comes with beginner-friendly user manual and video instructions to ensure you can easily take full advantage of its features.
  • More Cost-effective Storage Solution: Unlike cloud storage with recurring monthly fees, A UGREEN NAS enclosure requires only a one-time purchase for long-term use. For example, you only need to pay $629.99 for a NAS, while for cloud storage, you need to pay $719.88 per year, $1,439.76 for 2 years, $2,159.64 for 3 years, $7,198.80 for 10 years. You will save $6,568.81 over 10 years with UGREEN NAS! *NAS cost based on DH4300 Plus + 12TB HDD; cloud cost based on 12TB plan (e.g. $59.99/month).
  • Your Data, You Control:No third-party clouds, no hidden access, UGREEN NAS provides a more secure and private data storage solution. It stores data locally on your private hard drives and does automatic backups. Thus, you can keep full control over it. The advanced encryption is TRUSTe certified in the United States and is awarded the first (and only) ETSI EN 303 645 certification mark for NAS products by TÜV SÜD Group.

Reviewed update pull requests for Git-managed stacks

If the Compose files live in a Git repository and are deployed from it, the cleanest automation is one that proposes changes rather than applying them. Renovate and Dependabot both open pull requests that bump image tags or digests in your files. Renovate documents support for Docker and Compose image updates. Docker’s build best practices describe Dependabot scheduled pull requests for base image tags and digests.

The workflow is:

  • The bot opens a pull request with the changed image reference and a diff you can read.
  • Your continuous integration builds the images and runs tests where the project supports them.
  • A person reviews release notes for the changed image, especially for major versions and databases.
  • You merge and deploy using the manual steps above, or your existing deployment pipeline.

This keeps reproducibility and change control intact. Digests are updated in the same review as code, and the rollback path is a Git revert. The limit is that a pull request is only as good as the checks behind it. A bump that builds and passes a smoke test can still fail under production data, so the verification step does not go away.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Watchtower and unattended container replacement

Watchtower is a different kind of tool. It polls image registries for changed image digests and replaces running containers when it finds a new one. Its quickstart describes a default poll interval of every 24 hours and container replacement when an updated digest is detected. Those defaults are documented for the version and page reviewed, so check the current documentation before relying on them.

Rank #4
BUFFALO LinkStation 210 2TB 1-Bay NAS Network Attached Storage with HDD Hard Drives Included NAS Storage that Works as Home Cloud or Network Storage Device for Home
  • Value NAS with RAID for centralized storage and backup for all your devices. Check out the LS 700 for enhanced features, cloud capabilities, macOS 26, and up to 7x faster performance than the LS 200.
  • Connect the LinkStation to your router and enjoy shared network storage for your devices. The NAS is compatible with Windows and macOS*, and Buffalo's US-based support is on-hand 24/7 for installation walkthroughs. *Only for macOS 15 (Sequoia) and earlier. For macOS 26, check out our LS 700 series.
  • Subscription-Free Personal Cloud – Store, back up, and manage all your videos, music, and photos and access them anytime without paying any monthly fees.
  • Storage Purpose-Built for Data Security – A NAS designed to keep your data safe, the LS200 features a closed system to reduce vulnerabilities from 3rd party apps and SSL encryption for secure file transfers.
  • Back Up Multiple Computers & Devices – NAS Navigator management utility and PC backup software included. NAS Navigator 2 for macOS 15 and earlier. You can set up automated backups of data on your computers.

Watchtower’s documented operation requires access to the Docker socket, typically by mounting /var/run/docker.sock into its own container. Access to that socket is effectively root-level control of the Docker host, so anything that can compromise Watchtower can control every container on the machine. Before adopting it, consider:

  • Privilege. The socket mount gives the tool control over every container on the host, not only the ones you intend to update.
  • Replacement is not testing. Watchtower recreates containers. It does not check that the application still works, run migrations, or back up data first.
  • Data in writable layers. Recreation discards anything that existed only in the old container’s writable layer, on a schedule you may not be watching.
  • Tags. Automatic replacement on a mutable tag can move a service to new contents without any review.
  • Maintenance. Confirm that the project is actively maintained and compatible with your Docker Engine version before you deploy it, rather than assuming a past recommendation still holds.

Watchtower can suit low-stakes, stateless services on a host you control, where a failed update is cheap to reverse. It is a poor fit for stateful services, shared hosts, or any stack where an update needs a pre-change backup or a verification step.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choosing an approach

The three approaches differ on four axes: how much review happens before a change, how reproducible the result is, how well the approach fits your deployment model, and how much privilege and failure impact it carries.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Synology DS225+ Private Cloud Media Server - Stream, Back Up Photos & Share Files, Intel CPU for Hardware Transcoding (2-Bay Diskless NAS)
  • Your Personal Streaming Server - Build your own Netflix-style media library and stream 4K movies, shows and photos to any device without monthly fees
  • Create Your Own Cloud - Store your entire photo, video and music collection; access from anywhere with fast 282 MB/s transfer speeds
  • Creator-Grade Backup Solution - Protect your irreplaceable content with automated backups to cloud services, external drives and remote NAS
  • Multi-Layered Data Protection - Combine RAID redundancy, automated backups and snapshot technology to prevent data loss from any cause
  • Smart Home Surveillance - Support up to 30 IP cameras with AI detection, instant alerts and secure remote monitoring
Approach Review and change control Reproducibility Operational fit Privilege and failure impact
Manual Compose updates Full, if you review each change before running it High when digests are pinned; lower with mutable tags Single host or small number of projects managed by hand No socket access required; failures are visible at the time you run the change
Renovate or Dependabot pull requests Human-reviewed pull request before merge High; digests and tags change through versioned commits Git-managed stacks with a deployment pipeline Bots act on repository changes, not on running containers; deployment still needs a controlled step
Watchtower automation Minimal; replacement happens when a new digest is detected Lower with mutable tags; a pinned digest will not change Stateless services on hosts where unattended replacement is acceptable Docker socket access; unreviewed replacement, possible data loss from writable layers, and no built-in application testing

A common and defensible combination is pinned digests in Git, Renovate or Dependabot proposing the bumps, and manual or pipeline-driven application of changes after checks pass. Watchtower is best kept out of stacks that hold state you cannot recreate.

Docker Engine and Docker Desktop are a separate maintenance track

Updating images and updating Docker itself are different tasks. Image updates change what your containers run. Engine or Desktop updates change the software that runs the containers, and they depend on your operating system and installation method. Docker publishes security announcements for its products. Read the announcement that matches the exact product and versions you run, because there is no single version recommendation covering every combination of Engine, Desktop, operating system, and distribution.

Treat a Docker Engine update as a host change: confirm it against your distribution’s packaging, schedule it with the same backup and verification steps, and do not combine it with an image update in the same change window, so that any regression can be traced to one of the two.

Keeping the process repeatable

A safe update routine is mostly the same every time. Write the inventory, backup, pull, apply, verify, and rollback steps into a short runbook kept next to the Compose files, and record which services use tags and which use digests. Review it when you add a service or change a volume. The steps above are a starting framework rather than a universal production policy; adjust the sequence to your service’s startup time, migration needs, and tolerance for interruption.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The aim is a stack you can update on a schedule you chose, with every image reference change visible in review, and with a known way back when an update goes wrong.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.