Review container image references

Specify a verified image reference that can actually be pulled.

Description

An empty image reference or an incorrect repository can prevent a container from starting. Mutable tags can later point to different contents, so manage the repository, version and intended image contents explicitly.

The standalone string latest is interpreted as an image repository name, not a tag specification. It differs from a reference such as image:latest. Version tags are not inherently immutable either; use a verified digest to pin exact contents.

Potential impact

  • Image-pull failures can prevent deployment or recovery.
  • Unexpected image contents can make operational tracking and security verification harder.

Remediation

  • Specify the actual registry and repository with a verified tag or digest in image. Check platform compatibility and access permissions.
  • Use a digest to pin exact contents and review updates separately. The presence of a tag does not establish image safety.

Examples

The existing examples are preserved. The before latest value is a repository name; the after nginx:1.7.9 is an old version-tag example, not a recommended image for current deployment.

Before

hcl
resource "kubernetes_pod" "example" {
  metadata {
    name = "terraform-example"
  }

  spec {
    container {
      image = "latest"
      name  = "example"
    }
  }
}

After

hcl
resource "kubernetes_pod" "example" {
  metadata {
    name = "terraform-example"
  }

  spec {
    container {
      image = "nginx:1.7.9"
      name  = "example"
    }
  }
}

Explanation:

  • Before: The reference names a repository called latest. Confirm that the intended image exists and is accessible.
  • After: The nginx repository and a version tag are explicit. This does not guarantee immutable contents or image safety.

References