I do updates automatically, as you did (before). I currently have Stage containers and nothing in Prod. But there is no harm associated with updating each container: some redundant network activity is possible if you have several containers based on the same image, but harmless otherwise.
Restoring the container amazes me as unnecessary time and requires a more complex process.
WRT time: The lap time is added to the time that needs to be updated, so in this sense it is βextraβ time. And if you have processes running your container, they need to be repeated.
The complexity of WRT: On the one hand, you just run updates with apt. On the other hand, you basically act as an integration server: the more steps, the more errors.
In addition, updates do not create a βgolden imageβ because it is easily reproduced.
And finally, since the kernel is never updated, you will never need to reboot the container.
Rondo
source share