Note

Image digests over tags, always

A tag is a mutable pointer. Deploying by tag means you cannot state what is running.

A container tag is a mutable reference. myapp:v1.2.0 can be repointed at different bytes at any time, and nothing in a Kubernetes deployment referencing that tag will tell you it happened.

Deploy by digest and "what is running" has exactly one answer. It also makes rollback a redeploy of a known artefact rather than a rebuild and a hope.

The objection is that digests are unreadable. True, and irrelevant: no human types them. CI resolves the tag to a digest at build time and writes the digest into the manifest. The human-readable tag stays as a label for people, and the digest is what the cluster pulls.