Watchtower Docker Compose Example
Watchtower to automatically update running containers (read-only socket, scheduled).
The compose.yaml
name: watchtower
services:
watchtower:
image: containrrr/watchtower:latest
command: --cleanup --schedule "0 0 4 * * *"
restart: unless-stopped
volumes:
- /var/run/docker.sock:/var/run/docker.sock
logging:
driver: json-file
options:
max-size: 10m
max-file: '3'
Start it up
# Validate the configuration (does not start anything):
docker compose -f compose.yaml config
# Pull images and start in the background:
docker compose -f compose.yaml pull
docker compose -f compose.yaml up -d
# Check status and follow logs:
docker compose -f compose.yaml ps
docker compose -f compose.yaml logs -f
# Stop and remove (named volumes are kept):
docker compose -f compose.yaml down
Services
- watchtower — containrrr/watchtower:latest
Security notes
- criticalDocker socket mounted into a containerAvoid mounting the socket. If unavoidable, use a read-only, filtered socket proxy that exposes only the endpoints needed.
- warningNo healthcheckAdd a `healthcheck:` that probes a readiness endpoint or a CLI check for the service.
- warningNo memory limitSet a memory limit sized to the workload (e.g. `mem_limit: 512m`).
- warningService image uses `latest`Pin an explicit version tag (and ideally a digest) for every service image.
Open the template in the generator to apply one-click hardening.
Related templates
FAQ
How do I run this Watchtower Docker Compose file?
Save it as compose.yaml, then run `docker compose up -d`. Validate first with `docker compose config` and follow logs with `docker compose logs -f`.
Do I need a version field in the Watchtower Compose file?
No — modern Docker Compose does not require a top-level version field, and this example does not include one.
How do I customize this Watchtower template?
Open it in the free Docker Compose Generator to change images, ports, volumes, networks, environment variables, and health checks visually, then download your compose.yaml.
Independent educational example. "Docker" is a trademark of Docker, Inc. Review and adapt before using in production.