Alternatively, one place where `:latest` would make sense is if they're your images, and you're relying on podman-auto-update to update a fleet of servers to start running the latest version of a service as soon as you push the new image.
Alternatively, one place where `:latest` would make sense is if they're your images, and you're relying on podman-auto-update to update a fleet of servers to start running the latest version of a service as soon as you push the new image.
Ansible / salt / puppet, etc would do this for you in a nicer way. Or maybe Nomad.
Or k8s + ArgoCD would do that from the fact of a commit to a git repo.
As you get progressively bigger, you can consider other options.
For my home servers which just run personal things (like a kanban board as a todo list) I just use watchtower[0]. This requires mounting the docker socket into this container, which is not ideal.
In a production environment, id expect pinning of the docker sha and setting docker tags as immutable. Some software projects exist to scan for updates and draft PRs automatically for changes (I can't remember the name of the software but it begins with R).
Renovate maybe? https://www.mend.io/free-developer-tools/renovate/
I use it for my home server and I love it because it takes care of Dockerfiles too and version changes are saved in git, which means that a rollback is just a matter of switching back to a previous commit and rebuilding your containers (in addition to restoring a backup of your Docker volumes).
OTOH a bog standard python server backend can probably keep running for quite a while on alpine:latest without issue because it's not very reliant on much in terms of strange package availability (maybe old python versions that get deprecated every once in a while).