gitpulsGitHub soon

Server · 2 min read

Why is Docker CE not updated by unattended-upgrades?

unattended-upgrades only installs packages from the origins listed in its configuration, and on Debian those are the distribution’s own archive and its security archive. Docker CE comes from Docker’s own repository with the origin Docker, so unattended-upgrades never touches it; on our VPS a dry run on 9 October 2026 marked that repository “not allowed”.

Which origins are allowed by default?

Debian and Debian security, nothing else. The Debian wiki says “the default configuration auto-installs security updates, but not new features” (Debian Wiki, UnattendedUpgrades, checked 9 October 2026), and other origins have to be added to Unattended-Upgrade::Origins-Pattern.

On our VPS (Debian 13, unattended-upgrades 2.12), a dry run on 9 October 2026 at 18:51 named three allowed patterns, all of them origin=Debian, and marked five package lists “not allowed” with pin -32768: Docker’s, two from Tailscale and two from trixie-updates. The last two surprise most people: the line for ${distro_codename}-updates is commented out in the shipped 50unattended-upgrades. You can check your own machine without installing anything:

apt-cache policy docker-ce
sudo unattended-upgrade --dry-run --debug 2>&1 | grep -E 'Allowed origins|Marking not allowed'

apt-cache policy shows Docker’s repository as o=Docker,a=trixie,l=Docker CE,c=stable; that is the line a pattern would have to match. Note that the dry run writes its output to /var/log/unattended-upgrades/unattended-upgrades.log as well.

Should Docker CE update itself?

Not on a server with running containers, in our view. Docker’s documentation describes an upgrade as a manual step: “To upgrade Docker Engine, follow step 2 of the installation instructions, choosing the new version you want to install” (Docker Docs, install on Debian, checked 9 October 2026). An upgrade of the engine restarts the daemon, and with it every container that is not set to restart.

We update Docker CE by hand and then check containers, tags and firewall. Since installation on 21 August 2026, docker-ce was upgraded four times on our VPS, from 29.7.2 to 29.9.0, the last time on 9 October 2026 (from the dpkg log). In the same period unattended-upgrades installed Debian packages on its own twice, on 1 and 2 October 2026, among them OpenSSL. Adding "origin=Docker,label=Docker CE"; to the patterns would make Docker CE update itself too; we have decided against it.

How do I see pending updates without apt update?

With apt list --upgradable, which reads the package lists already on the machine. On Debian the timer apt-daily.timer refreshes them once a day; on our VPS it last ran on 9 October 2026 at 10:12, and the Docker list was dated 00:13 that day.

At 18:51 the command listed 0 upgradable packages, and apt-cache policy docker-ce showed the installed version 29.9.0 as the candidate. A version that is newer than the list’s last refresh does not show up here; when that matters, check how old the lists are before trusting an empty answer.

How this text was written

This article was drafted with an AI assistant from our own measurements and the sources linked above, which were checked on 9 October 2026. The numbers come from the method page; nothing was estimated.