AlwaysPullImages admission plugin not enabled

Review image pull policy and registry authentication to control reuse of private images on shared nodes.

Description

The AlwaysPullImages admission plugin sets the image pull policy of new Pods to Always. This helps reduce the risk of users reusing private images left on a shared node without having access to the registry.

Always does not download every image layer again or guarantee that an image is current and approved. Cached content with the same digest can be reused. Apply image approval, signature verification and vulnerability management separately.

Potential impact

  • A shared node's cache can allow reuse of private images without the required registry access.
  • Pull policy alone does not establish an image's origin or safety.

Remediation

  • Review shared-cluster requirements and include AlwaysPullImages in --enable-admission-plugins where needed.
  • Supply the registry credentials required by each workload and assess how registry outages affect Pod startup.
  • Apply separate supply-chain controls, including approved images and digests and signature verification.

Examples

These excerpts compare API server arguments. Match the image to the actual cluster version and supply the remaining control-plane configuration separately. This plugin does not require a separate admission configuration file.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: registry.k8s.io/kube-apiserver:v1.34.0
      command: ["kube-apiserver"]
      args: ["--disable-admission-plugins=AlwaysPullImages"]

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: registry.k8s.io/kube-apiserver:v1.34.0
      command: ["kube-apiserver"]
      args:
        ["--enable-admission-plugins=AlwaysPullImages"]

Explanation:

  • Before: Disables AlwaysPullImages. Actual reuse also depends on each Pod's pull policy.
  • After: Applies the Always policy to new Pods. It does not replace image approval or security verification.

References