While technically a loophole, I wouldn't say that its impact was too high. It would be concerning only if you'd run multi-tenant clusters, where customers' pods run on the shared nodes. And even then, it could have been mitigated with
pullPolicy: Always. While I never encountered this, I could imagine such setup in some PaaS company.The gist is that previously (or still, depends on your K8s version),
kubelet doesn't check the correct permissions to use a container image if this image is already present on a node.#kubernetes #security