New to Kestra?
Use blueprints to kickstart your first workflows.
Scans Kubernetes container image references for mutable tags and unpinned digests, alerting DevSecOps teams to secure supply chain pipelines.
In production Kubernetes and container environments, referencing images by mutable tags such as :latest, :staging, or unpinned semantic versions poses a severe supply chain security and deployment reliability risk.
When container registries allow tags to be overwritten, upstream image rebuilds or unauthorized registry pushes automatically alter the code executed inside running Kubernetes pods upon pod restart, replica scaling, or node migration. This violates the core software supply chain security principle of immutability and compromises auditability across production environments.
This blueprint provides an automated DevSecOps governance sentinel. It audits container image references across your container workloads, flags mutable tags and unpinned digests, and dispatches detailed Slack security alerts with remediation guidance.
daily_image_audit trigger (io.kestra.plugin.core.trigger.Schedule) initiates the audit every morning at 07:00 UTC.audit_image_tags task (io.kestra.plugin.scripts.python.Script) executes a Python parser within a Docker container to check each image URI against strict immutability standards (checking for :latest, branch-like tags, and mandatory @sha256: digest hashes).check_for_violations task (io.kestra.plugin.core.flow.If) branches based on whether any image violations were detected.send_slack_immutability_alert (io.kestra.plugin.slack.notifications.SlackIncomingWebhook) sends a formatted alert detailing the offending images and required fixes.export_audit_manifest task (io.kestra.plugin.core.debug.Return) emits a JSON manifest for automated compliance reporting.flowchart TD
A[Schedule: Daily 07:00 UTC] --> B[audit_image_tags: Python Image Parser]
B --> C{Violations Detected?}
C -- Yes --> D[send_slack_immutability_alert: Slack Webhook]
C -- No --> E[log_compliant_status: Log]
D --> F[export_audit_manifest: Return JSON]
E --> F
| Name | Type | Default | Description |
|---|---|---|---|
container_images_list |
STRING | registry.company.com/... |
Comma-separated list of container image URIs to verify. |
disallow_latest_tag |
BOOLEAN | true |
Whether to flag :latest and omitted tags as violations. |
require_sha256_digest |
BOOLEAN | false |
When true, enforces cryptographic @sha256: digest hashes. |
slack_channel |
STRING | #security-alerts |
Slack channel destination for security notifications. |
{{ outputs.audit_image_tags.vars.has_violations }}: Boolean flag indicating if mutable image tags were detected.{{ outputs.audit_image_tags.vars.violations_count }}: Total number of non-compliant container image references.{{ outputs.audit_image_tags.vars.top_violating_image }}: First non-compliant container image URI.{{ outputs.audit_image_tags.outputFiles['image_immutability_report.json'] }}: Complete JSON diagnostic report.SLACK_WEBHOOK_URL: Slack Incoming Webhook endpoint URL.SLACK_WEBHOOK_URL in your Kestra namespace secrets.container_images_list or dynamically pipe them from your CI/CD pipeline.repo:tag@sha256:... include both a human-readable tag and an immutable digest. The auditor correctly recognizes these as pinned.registry.internal:5000/app:v1) are correctly handled by the regex parser without confusing the port colon with a tag colon.kubectl get pods -A -o jsonpath via io.kestra.plugin.kubernetes.pods to dynamically audit all running cluster pods in real time.