Back to Practice
Lab

Block Unpinned Images

Supply-chain hygiene at admission: write a Kyverno policy that rejects the mutable :latest tag so every workload must pin an explicit image version, then prove it admits a pinned image and blocks :latest.

Your mission

:latest is a lie. It's a moving pointer — the image behind it changes without the tag changing, so nginx:latest today and tomorrow can be different bytes. That breaks reproducibility and lets a poisoned upstream push slip straight into your cluster. Supply-chain hygiene starts with pinning every image to an explicit version and refusing anything that doesn't.

Kyverno is already installed. You'll write an admission policy that rejects the :latest tag cluster-wide for the apps namespace, then prove it: a pinned image deploys, a :latest one is turned away at the door.

kubectl config set-context --current --namespace=apps

Skills you'll put into practice

kyvernopolicyadmission-controlsupply-chaincks

Make it your own.

Use this topic as a starting point for a fresh custom scenario.

Create a variation