Review Kubernetes image digest pinning

Specify the exact image content and manage reviewed updates.

Description

A container image tag can be moved to different content. Referencing a digest pins the intended image content and makes deployments easier to reproduce. A digest alone does not establish publisher trust or the absence of vulnerabilities.

Potential impact

  • The same tag can produce different running content across nodes or deployments.
  • An unreviewed tag change can enter a deployment.

Remediation

  • Obtain the actual digest of a verified image from a trusted registry and specify it in image. Check the target platform and registry access permissions.
  • Review image provenance and vulnerabilities, and update the digest when patches are needed. imagePullPolicy: Always alone does not pin tag content.

Examples

registry.example.com and the revised 64-character SHA256 value are illustrative placeholders. Replace them with the actual registry and the digest of a verified image.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: private-image-test
spec:
  containers:
    - name: uses-private-image
      image: registry.example.com/app
      imagePullPolicy: Always

A reference without a tag or digest uses the latest tag. Always does not pin its content.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: private-image-test
spec:
  containers:
    - name: uses-private-image
      image: registry.example.com/app@sha256:0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef
      imagePullPolicy: Always

This shows the format for specifying image content by SHA256 digest. The illustrative value cannot be used to retrieve the actual image.

References