Review container image pull policies

Choose a pull policy that matches image identification and registry availability requirements.

Description

image_pull_policy = "IfNotPresent" can use an image cached on the node. Reusing a mutable tag can therefore run different contents according to each node’s cache.

Always resolves the image digest through the registry when a container starts and can reuse matching cached content. It does not automatically update running containers or download every layer again on each start.

Potential impact

  • Mutable tags and caches can produce different deployments or delay security updates.
  • A policy requiring registry access can prevent startup during registry outages or authentication failures.

Remediation

  • Use image_pull_policy = "Always" when the tag must be checked at startup. IfNotPresent can also be appropriate when a verified digest is pinned.
  • Verify image provenance and vulnerabilities, and manage digests, security updates and redeployment procedures. Check the effective pull policy and registry access permissions.

Examples

The existing busybox reference omits a tag and therefore uses latest. The examples compare pull policies without pinning image contents. Prepare a maintained, verified image and any required credentials.

Before

hcl
resource "kubernetes_pod" "busybox" {
  metadata {
    name = "busybox-tf"
  }

  spec {
    container {
      image             = "busybox"
      command           = ["sleep", "3600"]
      name              = "busybox"
      image_pull_policy = "IfNotPresent"
    }

    restart_policy = "Always"
  }
}

After

hcl
resource "kubernetes_pod" "busybox" {
  metadata {
    name = "busybox-tf"
  }

  spec {
    container {
      image             = "busybox"
      command           = ["sleep", "3600"]
      name              = "busybox"
      image_pull_policy = "Always"
    }

    restart_policy = "Always"
  }
}

Explanation:

  • Before: The cached busybox image can be reused.
  • After: The registry is consulted for the digest at container startup. Matching cached layers can still be reused.

References