Review container image digest pinning

Pin a verified image digest and maintain a security-update process.

Description

When an image is specified only by tag, that tag can later refer to different contents. The same configuration may therefore deploy different images at different times, reducing reproducibility.

Pin the digest of a verified image to identify the intended contents. Digest pinning alone does not establish that an image is trustworthy or free of vulnerabilities.

Potential impact

  • Unexpected image contents can be deployed from the same configuration.
  • An unverified image can run, making security review and incident analysis harder.

Remediation

  • Specify the actual repository path and a verified @sha256:... digest. Check the image or image index for the required platform.
  • Verify image signatures, provenance and vulnerabilities. Review security updates and then update the pinned digest.

Examples

Set image_repository to the actual repository path and verified_image_digest to the 64 hexadecimal characters of the image’s verified SHA-256 digest. Use a maintained image.

Before

hcl
resource "kubernetes_pod" "example" {
  metadata {
    name = "terraform-example"
  }

  spec {
    container {
      image = "nginx:1.7.9"
      name  = "example"
    }
  }
}

After

hcl
resource "kubernetes_pod" "example" {
  metadata {
    name = "terraform-example"
  }

  spec {
    container {
      image = "${var.image_repository}@sha256:${var.verified_image_digest}"
      name  = "example"
    }
  }
}

Explanation:

  • Before: Only an nginx tag is specified. The contents it references can change.
  • After: The actual repository and verified digest are supplied to pin the image contents. Image security still needs separate review.

References