A container always runs exactly the state of its image that we have checked. It is never replaced on its own - you decide when to update. There are two cases:
- New state of the same version - for example security updates for
mariadb:11orwordpress:7-apache. The name (tag) stays the same, the content is new. - New version - for example from
wordpress:7-apachetowordpress:8-apache. You enter a different tag.
Before: create a snapshot
Before every update, create a snapshot of the container's volumes in the Backup & snapshot tab (Backup and snapshot). If the new version does not start or changes your data unexpectedly, restore the previous state.
New state of the same version
For every version you use, we fetch the current state once a week and check it for security. If a newer checked state is available, the container page shows the notice New checked state available, and the list of your containers shows Update available. Your container takes over the new state as soon as it is recreated:
- Open the container page.
- Click Update in the notice (or Recreate in the settings) and confirm the security prompt.
- The container is recreated with the most recently checked state and the same configuration. It is briefly unavailable, the data in the volumes is kept.
When you save container settings, for example change a variable, it is also recreated and uses the most recently checked state.
Installing a new version
- Open the container page and its Settings.
- Under Version and resources, enter the new version in Version (tag). If there is a checked version with fewer security findings, we suggest it directly below as recommended.
- Confirm licence and check result of the new version and click Save.
- If the version is new, we check it first. The container waits until then and starts by itself with the new version.
If the check reports critical or high findings, the container only starts once you confirm the risk. Critical findings in images from official sources often only affect bundled helper programs, not the application itself (Security in Container Hosting). The Security check card on the container page recommends a better checked version - with Prepare update you take it over into the settings.
Databases and large version jumps
- Major versions of databases often change the data format. MariaDB upgrades its data on start if the variable
MARIADB_AUTO_UPGRADE=1is set (Environment variables and secrets). PostgreSQL does not start with data of an older major version - here you back up the data beforehand with an export and import it into the new version. - Do not skip major versions - applications such as Nextcloud can only be upgraded version by version.
- Use fixed versions such as
11instead oflatest. Security updates then come automatically with “Recreate”, and you choose a new major version deliberately.
After the update
Check in the container's Logs tab whether the application started cleanly, and open your web address. If something does not work, enter the previous version in the settings again and restore the snapshot if necessary (Finding and fixing errors).