Description
A container image tag can be moved to different content. Referencing a digest pins the intended image content and makes deployments easier to reproduce. A digest alone does not establish publisher trust or the absence of vulnerabilities.
Potential impact
- The same tag can produce different running content across nodes or deployments.
- An unreviewed tag change can enter a deployment.
Remediation
- Obtain the actual digest of a verified image from a trusted registry and specify it in image. Check the target platform and registry access permissions.
- Review image provenance and vulnerabilities, and update the digest when patches are needed. imagePullPolicy: Always alone does not pin tag content.
Examples
registry.example.com and the revised 64-character SHA256 value are illustrative placeholders. Replace them with the actual registry and the digest of a verified image.
Before
yaml
apiVersion: v1
kind: Pod
metadata:
name: private-image-test
spec:
containers:
- name: uses-private-image
image: registry.example.com/app
imagePullPolicy: Always
A reference without a tag or digest uses the latest tag. Always does not pin its content.
After
yaml
apiVersion: v1
kind: Pod
metadata:
name: private-image-test
spec:
containers:
- name: uses-private-image
image: registry.example.com/app@sha256:0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef
imagePullPolicy: Always
This shows the format for specifying image content by SHA256 digest. The illustrative value cannot be used to retrieve the actual image.