Block Unpinned Images
Supply-chain hygiene at admission: write a Kyverno policy that rejects the mutable :latest tag so every workload must pin an explicit image version, then prove it admits a pinned image and blocks :latest.
Your mission
:latest is a lie. It's a moving pointer — the image behind it changes without the
tag changing, so nginx:latest today and tomorrow can be different bytes. That
breaks reproducibility and lets a poisoned upstream push slip straight into your
cluster. Supply-chain hygiene starts with pinning every image to an explicit
version and refusing anything that doesn't.
Kyverno is already installed. You'll write an admission policy that rejects the
:latest tag cluster-wide for the apps namespace, then prove it: a pinned image
deploys, a :latest one is turned away at the door.
kubectl config set-context --current --namespace=apps