Image updates
Kaio tells you when a stack is running an image older than the one its
tag now points to, including for moving tags like latest.

Automatic checks
Section titled “Automatic checks”The server checks every stack on its own: once at startup, then every
KAIO_UPDATE_CHECK_INTERVAL_HOURS hours (default 12). Nothing is
pulled and nothing is applied, the result is only a flag on the stack, pushed
live to the dashboard, the TUI and any CLI reading the API. Set the variable to
0 to disable the scheduled check and rely on manual ones.
Applying an update stays an explicit action, so a new latest never recreates
your containers behind your back.
How detection works
Section titled “How detection works”The update checker uses Skopeo to inspect the remote manifest without pulling anything:
- Read the local image’s digest.
- Ask the registry for the manifest digest behind the tag.
- Compare.
Digest comparison is what makes this accurate for latest and other moving
tags: a version-string heuristic would miss a rebuilt latest, and a pull
would cost bandwidth on every check.
Checks run in parallel and asynchronously, so a slow or unreachable registry never blocks the dashboard.
Local and insecure registries
Section titled “Local and insecure registries”Local registries served over HTTP or with a self-signed certificate are supported natively, with automatic heuristic detection: a registry host that looks local (an IP with a port, for instance) is inspected without TLS verification.
Seeing the result
Section titled “Seeing the result”A stack with an available update shows a discreet pulsing ★ indicator. In
the CLI, update_available and outdated_images are reported per stack:
kaio-cli --json stack lsTriggering a check by hand
Section titled “Triggering a check by hand”Between two scheduled passes, ask for a check right away:
| Interface | How |
|---|---|
| Web | ⋮ STACK → Check Updates |
| TUI | c on the stack row |
| CLI | kaio-cli stack check-update my-db |
Applying an update
Section titled “Applying an update”kaio-cli stack update my-dbThis pulls the new images and recreates the containers (pull + up -d),
equivalent to Update in the web menu or u in the TUI. It records a new
version, so a bad update can be rolled
back.
Kaio, built by Régis Gaidot