Updating Docker Containers
What this article covers
- How container updates work.
- Pulling new images and recreating containers.
- Managing rollbacks and versions.
- Automating updates with Watchtower or scripts.
- Best practices for safe updates.
Introduction: Updating Docker containers
Docker containers run from images. When an image is updated, the container continues running the old version until you recreate it. A simple docker pull is not enough. A proper update workflow downloads the new image, stops the container, and restarts it with the fresh image. Regular updates bring security patches and new features, but you need to handle potential data loss and compatibility issues.
This article walks through updating containers safely and preparing for rollbacks.
Key terms
- Image: Template for a container.
- Tag: Version identifier for an image.
- Pull: Download a new image.
- Recreate: Create a container again with the current image.
- Rollback: Return to an earlier version.
- Downtime: Period when the service is unavailable.
- Backup: Save data before updating.
- Watchtower: Tool for automatic container updates.
Basics: pull and recreate
docker pull ollama/ollama:latest
docker stop ollama
docker rm ollama
docker run -d --name ollama -v ollama-data:/root/.ollama -p 11434:11434 ollama/ollama:latest
With Compose:
docker compose pull
docker compose up -d
docker compose up -d recreates containers if the image has changed.
Versions and tags
Use specific tags instead of latest:
image: ollama/ollama:0.3.12
This improves reproducibility and enables targeted rollbacks.
Backup before updating
Back up volumes before important updates:
docker run --rm -v ollama-data:/data -v $(pwd):/backup alpine \
tar -czf /backup/ollama-data-pre-update.tar.gz -C /data .
Update script
#!/bin/bash
set -e
SERVICE="ollama"
docker compose pull "$SERVICE"
docker compose up -d "$SERVICE"
docker image prune -f
Automated updates with Watchtower
Watchtower is a container that watches and updates other containers:
services:
watchtower:
image: containrrr/watchtower
volumes:
- /var/run/docker.sock:/var/run/docker.sock
environment:
- WATCHTOWER_POLL_INTERVAL=86400
- WATCHTOWER_CLEANUP=true
restart: unless-stopped
With WATCHTOWER_LABEL_ENABLE=true, only specific containers update:
services:
app:
labels:
- "com.centurylinklabs.watchtower.enable=true"
Rolling updates in Swarm
Docker Swarm rolls out updates without downtime:
docker service update --image mein-image:2.0 mein_service
Rollback
If the new image causes problems:
- Find the old image tag.
- Update your Compose file or run command.
- Recreate the container.
docker compose down
docker compose up -d
With a pinned tag:
image: ollama/ollama:0.3.10
Handling major updates
- Read the changelog.
- Watch for breaking changes.
- Use a test environment if possible.
- Back up before updating.
- Check health after the update.
Checking logs after an update
docker logs -f ollama
docker ps
Cleanup
Old images consume disk space:
docker image prune -f
This removes dangling images. Unused volumes remain but should be reviewed.
Tips
- Use fixed tags instead of
latestfor critical services. - Update regularly, but not excessively.
- Schedule update windows.
- Minimize downtime.
- Set up monitoring and alerts for update failures.
- Build backup strategy into your workflow.
Common pitfalls
- Using
latest: Uncontrolled updates. - No backup: Data loss from failed updates.
- Database schema changes: New versions break old data.
- No downtime planning: Service becomes unavailable.
- Accumulating old images: Disk fills up.
- Updating during use: Users experience interruptions.
Further reading
- BotServ.de Docker Compose
- BotServ.de Docker Backup
- BotServ.de Docker Volumes
- BotServ.de Docker Monitoring
FAQ: Docker updates
How often should I update containers? Regularly, but not for every minor change. Apply important security updates promptly.
Should I use latest?
Fine for homelabs, but use fixed tags for critical services.
What is Watchtower? A tool that automatically updates containers.
Can an update delete data? Only if volumes are not backed up or the new version is incompatible.
How do I roll back? Set the old image tag in your Compose file and restart.
Sources and further reading
- Docker Compose Update: https://docs.docker.com/compose/reference/up/
- Watchtower: https://github.com/containrrr/watchtower
- Docker Image Prune: https://docs.docker.com/engine/reference/commandline/image_prune/
Summary: Updating Docker containers
Docker updates are straightforward once you understand how pull, up -d, and recreate work together. For production services, fixed tags, backups, and clear rollback strategies should be standard. Tools like Watchtower automate updates, but demand extra attention for critical containers. Keep your stack secure and current by updating regularly, cleaning up old images, and protecting your volumes.


