Which pull policy prevents stale image tags in Podman?
0 reputation · 25 Jan 2024, 15:34 UTC
Podman provides several pull policies—missing, always, never, and newer—to manage how local image caches are handled during container creation or builds. When using mutable tags like latest, the default missing policy reuses any existing local image, which can lead to environments running outdated code if the remote registry has been updated.
While --pull=always ensures the most recent image is used, it introduces a dependency on network availability and increases startup latency. The --pull=newer policy aims to balance these needs by checking registry metadata, but its reliability depends on the registry's ability to provide accurate timestamps or digests.
Given these behaviors, what are the specific trade-offs between always and newer regarding reproducibility and performance? Does --pull=newer consistently detect stale tags across all OCI-compliant registries, or is always the only way to guarantee image freshness?