Review Kubernetes container image pull policy

Choose the pull policy for how tags change and cached images are used.

Description

With a mutable tag and imagePullPolicy set to IfNotPresent, a node can reuse its cached image. If that tag is moved to different content, nodes can run different images.

Always checks the tag’s digest with the registry when a container starts, but can reuse identical cached content. It does not automatically update running containers or establish image trust.

Potential impact

  • A cached older image may run instead of the intended patched image.
  • Nodes can behave differently depending on when a tag changed.

Remediation

  • Set imagePullPolicy: Always when mutable tags must be checked at container start. Verify registry access and behavior during registry failures.
  • For reproducible content, specify a verified digest and plan updates. Do not indiscriminately replace valid policies such as IfNotPresent for digest-pinned images.

Examples

The historical nginx:1.20.0 image is used to compare policies. Use a maintained, verified image for deployment.

Before

yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: deployment-with-image-pull-policy
spec:
  replicas: 3
  selector:
    matchLabels:
      app: nginx
  template:
    metadata:
      labels:
        app: nginx
    spec:
      containers:
        - name: nginx
          image: library/nginx:1.20.0
          imagePullPolicy: IfNotPresent

IfNotPresent reuses a local image when available and may not recheck a changed tag at startup.

After

yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: deployment-with-image-pull-policy
spec:
  replicas: 3
  selector:
    matchLabels:
      app: nginx
  template:
    metadata:
      labels:
        app: nginx
    spec:
      containers:
        - name: nginx
          image: library/nginx:1.20.0
          imagePullPolicy: Always

Always checks the tag with the registry at startup. A local image with the same digest can still be reused.

References