Q: A junior engineer executed `docker system prune -a --volumes -f` on a staging server to free up disk space, accidentally deleting production-mirror database volumes and wiping uncommitted test databases. On other CI nodes, unmaintained Docker hosts frequently run out of disk space due to hundreds of gigabytes of dangling images and BuildKit cache layers. You must design an automated, safe maintenance strategy that prunes stale resources using age filters without risking persistent volumes.
Design and automate recurring Docker host cleanup workflows. Use `docker system prune`, filters (`until`), BuildKit garbage collection, and safeguard stateful named volumes against accidental deletion.
Want to master this scenario in a live sandbox? KodeKloud's Docker Certified Associate (DCA) Hands-On Lab Course covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Analyze the Scope and Risks of Prune Subcommands
Understand command scopes: `docker image prune` removes dangling (`
<!-- Prune Command Danger Levels -->
SAFE: docker image prune (Removes dangling layers only)
CONTROLLED: docker system prune --filter "until=168h" (Removes stopped containers & untagged images > 7 days old)
DANGEROUS: docker system prune -a (Removes ALL images not actively running!)
CATASTROPHIC: docker system prune -a --volumes (Destroys all unused persistent volumes!)
Implement Age-Filtered Maintenance with --filter until
Always qualify automated pruning scripts with the `until` filter (e.g., `until=72h` or `until=168h`), ensuring that recently stopped containers and recently downloaded base images are preserved for developer cache.
# Prune stopped containers older than 3 days
docker container prune --filter "until=72h" -f
# Prune unused images created more than 7 days ago (without touching volumes)
docker image prune -a --filter "until=168h" -f
Configure Built-in BuildKit Garbage Collection in daemon.json
Rather than relying on manual cron jobs, configure BuildKit's native garbage collector in `/etc/docker/daemon.json` to enforce strict disk storage ceilings.
cat <<EOF | sudo tee /etc/docker/daemon.json
{
"builder": {
"gc": {
"enabled": true,
"defaultKeepStorage": "20GB",
"policy": [
{"keepBytes": 10737418240, "all": false},
{"keepBytes": 21474836480, "all": true}
]
}
}
}
EOF
Deploy Automated systemd Timer for Routine Host Hygiene
Create a hardened systemd service and timer running weekly that safely trims orphaned build layers and dangling images while strictly excluding `--volumes`.
# /etc/systemd/system/docker-prune.service
[Unit]
Description=Safe Docker Host Prune
[Service]
Type=Oneshot
ExecStart=/usr/bin/docker system prune -f --filter "until=168h"
- W
- e
- p
- r
- e
- v
- e
- n
- t
- e
- d
- d
- i
- s
- k
- e
- x
- h
- a
- u
- s
- t
- i
- o
- n
- a
- c
- r
- o
- s
- s
- 2
- 0
- 0
- b
- u
- i
- l
- d
- n
- o
- d
- e
- s
- w
- h
- i
- l
- e
- e
- l
- i
- m
- i
- n
- a
- t
- i
- n
- g
- a
- c
- c
- i
- d
- e
- n
- t
- a
- l
- d
- a
- t
- a
- l
- o
- s
- s
- b
- y
- d
- e
- p
- l
- o
- y
- i
- n
- g
- a
- s
- t
- r
- i
- c
- t
- p
- r
- u
- n
- i
- n
- g
- p
- o
- l
- i
- c
- y
- .
- W
- e
- b
- a
- n
- n
- e
- d
- t
- h
- e
- `
- -
- -
- v
- o
- l
- u
- m
- e
- s
- `
- f
- l
- a
- g
- i
- n
- s
- c
- r
- i
- p
- t
- s
- ,
- e
- n
- a
- b
- l
- e
- d
- B
- u
- i
- l
- d
- K
- i
- t
- '
- s
- n
- a
- t
- i
- v
- e
- 2
- 0
- G
- B
- g
- a
- r
- b
- a
- g
- e
- c
- o
- l
- l
- e
- c
- t
- i
- o
- n
- i
- n
- `
- d
- a
- e
- m
- o
- n
- .
- j
- s
- o
- n
- `
- ,
- a
- n
- d
- d
- e
- p
- l
- o
- y
- e
- d
- w
- e
- e
- k
- l
- y
- s
- y
- s
- t
- e
- m
- d
- t
- i
- m
- e
- r
- s
- t
- h
- a
- t
- p
- r
- u
- n
- e
- d
- a
- n
- g
- l
- i
- n
- g
- i
- m
- a
- g
- e
- s
- o
- l
- d
- e
- r
- t
- h
- a
- n
- 7
- d
- a
- y
- s
- u
- s
- i
- n
- g
- t
- h
- e
- `
- u
- n
- t
- i
- l
- `
- f
- i
- l
- t
- e
- r
- .