Schedule icon
Script icon
Docker icon
If icon
SlackIncomingWebhook icon
Log icon
Return icon

Docker Registry Image Tag Immutability Guard

Scans Kubernetes container image references for mutable tags and unpinned digests, alerting DevSecOps teams to secure supply chain pipelines.

Categories
CloudInfrastructure

In production Kubernetes and container environments, referencing images by mutable tags such as :latest, :staging, or unpinned semantic versions poses a severe supply chain security and deployment reliability risk.

When container registries allow tags to be overwritten, upstream image rebuilds or unauthorized registry pushes automatically alter the code executed inside running Kubernetes pods upon pod restart, replica scaling, or node migration. This violates the core software supply chain security principle of immutability and compromises auditability across production environments.

This blueprint provides an automated DevSecOps governance sentinel. It audits container image references across your container workloads, flags mutable tags and unpinned digests, and dispatches detailed Slack security alerts with remediation guidance.

How it works

  1. Scheduled Daily Execution: The daily_image_audit trigger (io.kestra.plugin.core.trigger.Schedule) initiates the audit every morning at 07:00 UTC.
  2. Python Tag & Digest Verification: The audit_image_tags task (io.kestra.plugin.scripts.python.Script) executes a Python parser within a Docker container to check each image URI against strict immutability standards (checking for :latest, branch-like tags, and mandatory @sha256: digest hashes).
  3. Violation Evaluation: The check_for_violations task (io.kestra.plugin.core.flow.If) branches based on whether any image violations were detected.
  4. Slack Security Alerting: If non-compliant images are detected, send_slack_immutability_alert (io.kestra.plugin.slack.notifications.SlackIncomingWebhook) sends a formatted alert detailing the offending images and required fixes.
  5. Audit Manifest Generation: The export_audit_manifest task (io.kestra.plugin.core.debug.Return) emits a JSON manifest for automated compliance reporting.

Architecture diagram

flowchart TD
    A[Schedule: Daily 07:00 UTC] --> B[audit_image_tags: Python Image Parser]
    B --> C{Violations Detected?}
    C -- Yes --> D[send_slack_immutability_alert: Slack Webhook]
    C -- No --> E[log_compliant_status: Log]
    D --> F[export_audit_manifest: Return JSON]
    E --> F

Use cases

  • Supply Chain Security Enforcement: Prevent deployment of mutable images that could be modified after passing security validation stages.
  • Production Stability Assurance: Guarantee that pods rescheduled onto new nodes run the exact same bytecode and operating system packages as originally tested.
  • Regulatory Compliance Auditing: Satisfy SOC2, ISO 27001, and NIST container security controls requiring immutable software artifact provenance.

Inputs

Name Type Default Description
container_images_list STRING registry.company.com/... Comma-separated list of container image URIs to verify.
disallow_latest_tag BOOLEAN true Whether to flag :latest and omitted tags as violations.
require_sha256_digest BOOLEAN false When true, enforces cryptographic @sha256: digest hashes.
slack_channel STRING #security-alerts Slack channel destination for security notifications.

Expected outputs

  • {{ outputs.audit_image_tags.vars.has_violations }}: Boolean flag indicating if mutable image tags were detected.
  • {{ outputs.audit_image_tags.vars.violations_count }}: Total number of non-compliant container image references.
  • {{ outputs.audit_image_tags.vars.top_violating_image }}: First non-compliant container image URI.
  • {{ outputs.audit_image_tags.outputFiles['image_immutability_report.json'] }}: Complete JSON diagnostic report.

Prerequisites

  • Outbound network connectivity from Kestra workers to dispatch notifications to the Slack webhook endpoint.
  • A valid Slack Incoming Webhook configured for your security alerting channel.

Secrets

  • SLACK_WEBHOOK_URL: Slack Incoming Webhook endpoint URL.

Quick start

  1. Configure SLACK_WEBHOOK_URL in your Kestra namespace secrets.
  2. Import this flow YAML into your Kestra workspace.
  3. Specify the list of active container images in container_images_list or dynamically pipe them from your CI/CD pipeline.
  4. Click Execute in the UI to run an immediate compliance scan.

Common pitfalls and troubleshooting

  • Digest Notation vs Tag Notation: Container images formatted as repo:tag@sha256:... include both a human-readable tag and an immutable digest. The auditor correctly recognizes these as pinned.
  • Registry Hostname Stripping: Container references with port numbers (e.g., registry.internal:5000/app:v1) are correctly handled by the regex parser without confusing the port colon with a tag colon.

How to extend

  • Integrate directly with kubectl get pods -A -o jsonpath via io.kestra.plugin.kubernetes.pods to dynamically audit all running cluster pods in real time.
  • Add automated Jira ticket creation for development teams responsible for services with mutable tags.
  • Connect to AWS ECR or Harbor registry APIs to enforce repository-level tag immutability settings.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.