From c59b9581452283629d6cf93f6cc2ae5153563f90 Mon Sep 17 00:00:00 2001 From: Krrish Dholakia Date: Wed, 25 Mar 2026 13:33:33 -0700 Subject: [PATCH] feat(helm): support image digest pinning for container security Add `image.digest` field to Helm chart values. When set, the image reference uses `repository@digest` instead of `repository:tag`, allowing users to pin to a specific SHA hash and protect against tag overwrites. Co-Authored-By: Claude Opus 4.6 --- deploy/charts/litellm-helm/templates/deployment.yaml | 2 +- deploy/charts/litellm-helm/templates/migrations-job.yaml | 2 +- deploy/charts/litellm-helm/values.yaml | 4 ++++ 3 files changed, 6 insertions(+), 2 deletions(-) diff --git a/deploy/charts/litellm-helm/templates/deployment.yaml b/deploy/charts/litellm-helm/templates/deployment.yaml index 3040fb45d86..d9d2cafb8bc 100644 --- a/deploy/charts/litellm-helm/templates/deployment.yaml +++ b/deploy/charts/litellm-helm/templates/deployment.yaml @@ -53,7 +53,7 @@ spec: - name: {{ include "litellm.name" . }} securityContext: {{- toYaml .Values.securityContext | nindent 12 }} - image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default (printf "main-%s" .Chart.AppVersion) }}" + image: "{{ .Values.image.repository }}{{ if .Values.image.digest }}@{{ .Values.image.digest }}{{ else }}:{{ .Values.image.tag | default (printf "main-%s" .Chart.AppVersion) }}{{ end }}" imagePullPolicy: {{ .Values.image.pullPolicy }} env: - name: HOST diff --git a/deploy/charts/litellm-helm/templates/migrations-job.yaml b/deploy/charts/litellm-helm/templates/migrations-job.yaml index 8b93a60c1a3..bf62e96b4ac 100644 --- a/deploy/charts/litellm-helm/templates/migrations-job.yaml +++ b/deploy/charts/litellm-helm/templates/migrations-job.yaml @@ -41,7 +41,7 @@ spec: {{- end }} containers: - name: prisma-migrations - image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default (printf "main-%s" .Chart.AppVersion) }}" + image: "{{ .Values.image.repository }}{{ if .Values.image.digest }}@{{ .Values.image.digest }}{{ else }}:{{ .Values.image.tag | default (printf "main-%s" .Chart.AppVersion) }}{{ end }}" imagePullPolicy: {{ .Values.image.pullPolicy }} securityContext: {{- toYaml .Values.securityContext | nindent 12 }} diff --git a/deploy/charts/litellm-helm/values.yaml b/deploy/charts/litellm-helm/values.yaml index 690ca69e730..be9b940b474 100644 --- a/deploy/charts/litellm-helm/values.yaml +++ b/deploy/charts/litellm-helm/values.yaml @@ -12,6 +12,10 @@ image: # Overrides the image tag whose default is the chart appVersion. # tag: "main-latest" tag: "" + # Overrides the image tag with a specific image digest for pinning. + # When set, the image will be referenced as `repository@digest` instead of `repository:tag`. + # Example: "sha256:abc123..." + digest: "" imagePullSecrets: [] nameOverride: "litellm"