feat(helm): support image digest pinning for container security

Add `image.digest` field to Helm chart values. When set, the image
reference uses `repository@digest` instead of `repository:tag`, allowing
users to pin to a specific SHA hash and protect against tag overwrites.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Krrish Dholakia 2026-03-25 13:33:33 -07:00
parent 90b850ef8e
commit c59b958145
3 changed files with 6 additions and 2 deletions

View file

@ -53,7 +53,7 @@ spec:
- name: {{ include "litellm.name" . }}
securityContext:
{{- toYaml .Values.securityContext | nindent 12 }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default (printf "main-%s" .Chart.AppVersion) }}"
image: "{{ .Values.image.repository }}{{ if .Values.image.digest }}@{{ .Values.image.digest }}{{ else }}:{{ .Values.image.tag | default (printf "main-%s" .Chart.AppVersion) }}{{ end }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
env:
- name: HOST

View file

@ -41,7 +41,7 @@ spec:
{{- end }}
containers:
- name: prisma-migrations
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default (printf "main-%s" .Chart.AppVersion) }}"
image: "{{ .Values.image.repository }}{{ if .Values.image.digest }}@{{ .Values.image.digest }}{{ else }}:{{ .Values.image.tag | default (printf "main-%s" .Chart.AppVersion) }}{{ end }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
securityContext:
{{- toYaml .Values.securityContext | nindent 12 }}

View file

@ -12,6 +12,10 @@ image:
# Overrides the image tag whose default is the chart appVersion.
# tag: "main-latest"
tag: ""
# Overrides the image tag with a specific image digest for pinning.
# When set, the image will be referenced as `repository@digest` instead of `repository:tag`.
# Example: "sha256:abc123..."
digest: ""
imagePullSecrets: []
nameOverride: "litellm"