Skip to content
🎉 Launch sale:50% off everything over $22 — automatically applied at checkout· ends Aug 2Shop the sale →
DevOps AI ToolKit
Newsletter

Watchtower Docker Compose Example

Watchtower to automatically update running containers (read-only socket, scheduled).

The compose.yaml

name: watchtower
services:
  watchtower:
    image: containrrr/watchtower:latest
    command: --cleanup --schedule "0 0 4 * * *"
    restart: unless-stopped
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock
    logging:
      driver: json-file
      options:
        max-size: 10m
        max-file: '3'

Start it up

# Validate the configuration (does not start anything):
docker compose -f compose.yaml config

# Pull images and start in the background:
docker compose -f compose.yaml pull
docker compose -f compose.yaml up -d

# Check status and follow logs:
docker compose -f compose.yaml ps
docker compose -f compose.yaml logs -f

# Stop and remove (named volumes are kept):
docker compose -f compose.yaml down

Services

  • watchtowercontainrrr/watchtower:latest

Security notes

  • critical
    Docker socket mounted into a container
    Avoid mounting the socket. If unavoidable, use a read-only, filtered socket proxy that exposes only the endpoints needed.
  • warning
    No healthcheck
    Add a `healthcheck:` that probes a readiness endpoint or a CLI check for the service.
  • warning
    No memory limit
    Set a memory limit sized to the workload (e.g. `mem_limit: 512m`).
  • warning
    Service image uses `latest`
    Pin an explicit version tag (and ideally a digest) for every service image.

Open the template in the generator to apply one-click hardening.

Related templates

FAQ

How do I run this Watchtower Docker Compose file?

Save it as compose.yaml, then run `docker compose up -d`. Validate first with `docker compose config` and follow logs with `docker compose logs -f`.

Do I need a version field in the Watchtower Compose file?

No — modern Docker Compose does not require a top-level version field, and this example does not include one.

How do I customize this Watchtower template?

Open it in the free Docker Compose Generator to change images, ports, volumes, networks, environment variables, and health checks visually, then download your compose.yaml.

Independent educational example. "Docker" is a trademark of Docker, Inc. Review and adapt before using in production.