Description
When an image is specified only by tag, that tag can later refer to different contents. The same configuration may therefore deploy different images at different times, reducing reproducibility.
Pin the digest of a verified image to identify the intended contents. Digest pinning alone does not establish that an image is trustworthy or free of vulnerabilities.
Potential impact
- Unexpected image contents can be deployed from the same configuration.
- An unverified image can run, making security review and incident analysis harder.
Remediation
- Specify the actual repository path and a verified
@sha256:...digest. Check the image or image index for the required platform. - Verify image signatures, provenance and vulnerabilities. Review security updates and then update the pinned digest.
Examples
Set image_repository to the actual repository path and verified_image_digest to the 64 hexadecimal characters of the image’s verified SHA-256 digest. Use a maintained image.
Before
hcl
resource "kubernetes_pod" "example" {
metadata {
name = "terraform-example"
}
spec {
container {
image = "nginx:1.7.9"
name = "example"
}
}
}
After
hcl
resource "kubernetes_pod" "example" {
metadata {
name = "terraform-example"
}
spec {
container {
image = "${var.image_repository}@sha256:${var.verified_image_digest}"
name = "example"
}
}
}
Explanation:
- Before: Only an nginx tag is specified. The contents it references can change.
- After: The actual repository and verified digest are supplied to pin the image contents. Image security still needs separate review.