Description
With a mutable tag and imagePullPolicy set to IfNotPresent, a node can reuse its cached image. If that tag is moved to different content, nodes can run different images.
Always checks the tag’s digest with the registry when a container starts, but can reuse identical cached content. It does not automatically update running containers or establish image trust.
Potential impact
- A cached older image may run instead of the intended patched image.
- Nodes can behave differently depending on when a tag changed.
Remediation
- Set imagePullPolicy: Always when mutable tags must be checked at container start. Verify registry access and behavior during registry failures.
- For reproducible content, specify a verified digest and plan updates. Do not indiscriminately replace valid policies such as IfNotPresent for digest-pinned images.
Examples
The historical nginx:1.20.0 image is used to compare policies. Use a maintained, verified image for deployment.
Before
yaml
apiVersion: apps/v1
kind: Deployment
metadata:
name: deployment-with-image-pull-policy
spec:
replicas: 3
selector:
matchLabels:
app: nginx
template:
metadata:
labels:
app: nginx
spec:
containers:
- name: nginx
image: library/nginx:1.20.0
imagePullPolicy: IfNotPresent
IfNotPresent reuses a local image when available and may not recheck a changed tag at startup.
After
yaml
apiVersion: apps/v1
kind: Deployment
metadata:
name: deployment-with-image-pull-policy
spec:
replicas: 3
selector:
matchLabels:
app: nginx
template:
metadata:
labels:
app: nginx
spec:
containers:
- name: nginx
image: library/nginx:1.20.0
imagePullPolicy: Always
Always checks the tag with the registry at startup. A local image with the same digest can still be reused.