Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Stack Update

BSecurity

Check for and apply Docker image updates to the media stack safely, with a settings snapshot first and rollback if something breaks. Use only when the user explicitly asks to check for updates, update services, or roll back an update.

2 stars
0 votes
0 copies
2 views
Added 10/1/2026
devopspythonbashdockergitapidatabase

Works with

cliapi

Security Analysis

B75/100
criticalSends environment variables or credentials to an external URL
criticalDownloads and executes remote scripts — classic supply chain attack

Pro shows the line behind each finding and how to fix it

Scanned 10/1/2026

$npx -y skills add bugrauluyurt/homelab-media-stack --skill stack-update --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Stack Update?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Stack Update
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/bugrauluyurt-stack-update/badge)](https://www.skillsdirectory.com/skills/bugrauluyurt-stack-update)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: stack-update
description: Check for and apply Docker image updates to the media stack safely, with a settings snapshot first and rollback if something breaks. Use only when the user explicitly asks to check for updates, update services, or roll back an update.
---

# Updating the stack

This changes the running system. Checking is safe. **Applying an update or a
rollback needs the user's explicit yes, every time.** Before running anything,
show what will change (which services, which images).

```bash
STACK=${MEDIA_STACK_DIR:-$(git rev-parse --show-toplevel 2>/dev/null)}; [ -x "$STACK/scripts/stack-health" ] || STACK=~/homelab-media-stack
```

## 1. See what's available (safe)

```bash
"$STACK/scripts/stack-update-check"      # about 1-2 minutes; also refreshes the list stack-health shows
```

It lists `update available: <image>  <old> -> <new>`. When the first number of
the version changes (a major release), say so: those are the updates that
break things. A daily timer runs it at 06:00 and pushes new updates to the
user's phone through ntfy, with major releases flagged `MAJOR`.

## 2. Apply (only after the user says yes)

```bash
"$STACK/scripts/stack-update"                  # every service with an update
"$STACK/scripts/stack-update jellyfin sonarr"  # or named services
```

It does four things in order:
1. Takes a restic snapshot tagged `pre-update`. If that fails, it stops and updates nothing.
2. Keeps the current images as `<image>:rollback-<date>`.
3. Pulls and recreates only those services. qBittorrent and slskd follow gluetun automatically.
4. Runs `stack-health`. After a Jellyfin update, the health check also confirms that every
plugin is still Active; a plugin built for an older Jellyfin shows up as a FAIL.

Jellyfin updates are the risky ones: Jellyfin 12 once broke logins in four other
apps at once. Mention that when Jellyfin is in the list, and check that nothing is
playing first:

```bash
K=$(sed -nE "s/^JELLYFIN_API_KEY=(['\"]?)(.*)\1$/\2/p" "$STACK/.env")
curl -s -H "Authorization: MediaBrowser Token=\"$K\"" http://127.0.0.1:8096/Sessions | python3 -c 'import json,sys;print([s.get("Client") for s in json.load(sys.stdin) if s.get("NowPlayingItem")] or "nothing playing")'
```

## 3. Roll back (only after the user says yes)

```bash
"$STACK/scripts/stack-update" --rollback <service>               # previous image AND its settings
"$STACK/scripts/stack-update" --rollback <service> --image-only  # previous image, current settings
```

The default restores settings, because updates often migrate the app's database
and the older version can't read a migrated one. It discards anything changed in
that app since the update, so say so before running it. Only use `--image-only`
when you know the update didn't change the database.

## After
Report what was updated, the stack-health summary, and the rollback command.

Attribution

bugrauluyurtbugrauluyurt
View sourceSee grades on GitHubMore from bugrauluyurt →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Terraform Module Library

Build reusable Terraform modules for AWS, Azure, and GCP infrastructure following infrastructure-as-code best practices. Use when creating infrastructure modules, standardizing cloud provisioning, or implementing reusable IaC components.

401991 votes

sematext-otel

Wire a service's OpenTelemetry output to Sematext Cloud. Walks through region, App-type, instrumentation flow (managed OTLP endpoint vs Sematext Agent), and signal selection (traces/metrics/logs), then produces the exact env-var block and points at a runnable reference example in this repo. Invoke when instrumenting a new app for Sematext.

01 votes

Deployment Patterns

Deployment workflows, CI/CD pipeline patterns, Docker containerization, health checks, rollback strategies, and production readiness checklists for web applications. Use when setting up deployment infrastructure or planning releases.

2699140 votes

Babysit

Watch a pull request or review cycle until it is ready to merge. Use when asked to babysit, monitor, or keep checking PR comments, reviews, and CI until all actionable issues are resolved.

968770 votes

V7 Roster

Interact with the Paperclip control plane API for task coordination and governance. Use when checking assignments, updating issue status, posting comments, delegating work, managing routines, or calling Paperclip API endpoints.

953190 votes
View all in devops →