Upgrade Air-Gapped using Docker Compose
A routine v6.x upgrade in an air-gapped Docker Compose deployment just needs the new image tags mirrored to your registry (or moved as a tarball) before you restart the stack. Unlike the major-version migration, there’s no new compose file, no new Dockerfile.anchore-db, and no rebuild required — you’re bumping versions on a running deployment, not standing up a new one. Your docker-compose.yaml stays as-is, provided you don’t touch the project name or database volume name.
Prepare the Images (low side)
Review the Release Notes for the target version to confirm which image tags actually changed.
enterprise/enterprise-uialways move together;redis(and, less often, the PostgreSQL/pg_croncombination baked intoanchore:db) can change independently, so don’t assume they’re unchanged from your last upgrade — diff the new referencedocker-compose.yamlandDockerfile.anchore-dbagainst what you last mirrored if you’re unsure.Pull the images that changed:
docker pull docker.io/anchore/enterprise:v6.1.1 docker pull docker.io/anchore/enterprise-ui:v6.1.0 docker pull docker.io/redis:7.4.6Only if
Dockerfile.anchore-dbchanged for this release, rebuild the database image:docker build -f Dockerfile.anchore-db -t anchore:db .This is uncommon for a routine upgrade — most releases don’t touch the database image at all. If it didn’t change, skip this step; there’s nothing new to move for
anchore-db.
Move the Images to the High Side
Choose one of the following, matching the equivalent step in the Air-Gapped Docker Compose deployment guide, for only the images that actually changed in step 2 (and step 3, if it applied):
- Private container registry (recommended) — re-tag, then push directly, or save/transfer/load/push, exactly as described in Option 1.
- Local image tarball — for hosts with no registry available, as described in Option 2.
Update Your Compose File
If this deployment was already deployed air-gapped, your docker-compose.yaml already points every image: line at your private registry or local image names — you only need to bump the tag on the lines that changed. The enterprise image is referenced by many services (api, catalog, component-catalog, queue, policy-engine, analyzer, reports, reports_worker, notifications, data-syncer, db-preflight), so update every occurrence:
api:
image: <registry>/anchore/enterprise:v6.1.1
Leave everything else in the file untouched — in particular, do not touch name: at the top of the file or the database volume name. Changing either causes Compose to stand up a new, empty deployment instead of upgrading this one.
Restart the Stack
Continue with the main Upgrade using Docker Compose procedure starting at Step 6: Restart the Anchore Enterprise Containers — monitoring the catalog logs and verifying the new version with anchorectl system status need no changes for an air-gapped host.