Description
image_pull_policy = "IfNotPresent" can use an image cached on the node. Reusing a mutable tag can therefore run different contents according to each node’s cache.
Always resolves the image digest through the registry when a container starts and can reuse matching cached content. It does not automatically update running containers or download every layer again on each start.
Potential impact
- Mutable tags and caches can produce different deployments or delay security updates.
- A policy requiring registry access can prevent startup during registry outages or authentication failures.
Remediation
- Use
image_pull_policy = "Always"when the tag must be checked at startup. IfNotPresent can also be appropriate when a verified digest is pinned. - Verify image provenance and vulnerabilities, and manage digests, security updates and redeployment procedures. Check the effective pull policy and registry access permissions.
Examples
The existing busybox reference omits a tag and therefore uses latest. The examples compare pull policies without pinning image contents. Prepare a maintained, verified image and any required credentials.
Before
hcl
resource "kubernetes_pod" "busybox" {
metadata {
name = "busybox-tf"
}
spec {
container {
image = "busybox"
command = ["sleep", "3600"]
name = "busybox"
image_pull_policy = "IfNotPresent"
}
restart_policy = "Always"
}
}
After
hcl
resource "kubernetes_pod" "busybox" {
metadata {
name = "busybox-tf"
}
spec {
container {
image = "busybox"
command = ["sleep", "3600"]
name = "busybox"
image_pull_policy = "Always"
}
restart_policy = "Always"
}
}
Explanation:
- Before: The cached busybox image can be reused.
- After: The registry is consulted for the digest at container startup. Matching cached layers can still be reused.