Skip to content

Image updates

Kaio tells you when a stack is running an image older than the one its tag now points to, including for moving tags like latest.

A stack row flagged with an update, its menu open on Check Updates and Update, and the event log below showing the update notice.
A stack whose registry digest moved: the row is starred, the menu offers Check Updates and Update, and the event log records the notice.

The server checks every stack on its own: once at startup, then every KAIO_UPDATE_CHECK_INTERVAL_HOURS hours (default 12). Nothing is pulled and nothing is applied, the result is only a flag on the stack, pushed live to the dashboard, the TUI and any CLI reading the API. Set the variable to 0 to disable the scheduled check and rely on manual ones.

Applying an update stays an explicit action, so a new latest never recreates your containers behind your back.

The update checker uses Skopeo to inspect the remote manifest without pulling anything:

  1. Read the local image’s digest.
  2. Ask the registry for the manifest digest behind the tag.
  3. Compare.

Digest comparison is what makes this accurate for latest and other moving tags: a version-string heuristic would miss a rebuilt latest, and a pull would cost bandwidth on every check.

Checks run in parallel and asynchronously, so a slow or unreachable registry never blocks the dashboard.

Local registries served over HTTP or with a self-signed certificate are supported natively, with automatic heuristic detection: a registry host that looks local (an IP with a port, for instance) is inspected without TLS verification.

A stack with an available update shows a discreet pulsing ★ indicator. In the CLI, update_available and outdated_images are reported per stack:

Terminal window
kaio-cli --json stack ls

Between two scheduled passes, ask for a check right away:

Interface How
Web ⋮ STACK → Check Updates
TUI c on the stack row
CLI kaio-cli stack check-update my-db
Terminal window
kaio-cli stack update my-db

This pulls the new images and recreates the containers (pull + up -d), equivalent to Update in the web menu or u in the TUI. It records a new version, so a bad update can be rolled back.

Kaio, built by Régis Gaidot