Review Kubernetes container image version selection

Choose a verified image version and manage changes deliberately.

Description

Using latest or omitting an image tag does not clearly pin the content to run. latest is a valid tag, but does not necessarily mean the newest or a verified image. Version tags can also change; an exact content pin requires a digest.

Potential impact

  • An unexpected image change can alter application behavior.
  • It can be harder to identify the running version or reproduce a deployment during an incident.

Remediation

  • Choose a maintained, verified image version. When exact content must be reproduced, pin the actual image digest.
  • Test patches and feature changes before updating the reference. Manage pinned versions so that security updates are not missed.

Examples

The existing examples compare nginx:latest and nginx:1.21. Version 1.21 is historical example content, not a deployment recommendation.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: private-image-test
spec:
  containers:
    - name: app
      image: nginx:latest
      imagePullPolicy: Always

If the content behind latest changes, a subsequent start can pull a different image.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: private-image-test
spec:
  containers:
    - name: app
      image: nginx:1.21
      imagePullPolicy: Always

The version 1.21 is explicit, but the tag itself is not guaranteed to be immutable.

References