Description
Using latest or omitting an image tag does not clearly pin the content to run. latest is a valid tag, but does not necessarily mean the newest or a verified image. Version tags can also change; an exact content pin requires a digest.
Potential impact
- An unexpected image change can alter application behavior.
- It can be harder to identify the running version or reproduce a deployment during an incident.
Remediation
- Choose a maintained, verified image version. When exact content must be reproduced, pin the actual image digest.
- Test patches and feature changes before updating the reference. Manage pinned versions so that security updates are not missed.
Examples
The existing examples compare nginx:latest and nginx:1.21. Version 1.21 is historical example content, not a deployment recommendation.
Before
yaml
apiVersion: v1
kind: Pod
metadata:
name: private-image-test
spec:
containers:
- name: app
image: nginx:latest
imagePullPolicy: Always
If the content behind latest changes, a subsequent start can pull a different image.
After
yaml
apiVersion: v1
kind: Pod
metadata:
name: private-image-test
spec:
containers:
- name: app
image: nginx:1.21
imagePullPolicy: Always
The version 1.21 is explicit, but the tag itself is not guaranteed to be immutable.