A developer wants to ensure that a pod always uses a specific version of an image that cannot be changed without updating the manifest. Which image reference should be used?
A digest reference pins the pod to the exact image content by its sha256 hash. Unlike a mutable tag, the digest cannot be repointed, so the running image stays identical unless the manifest is edited to a new digest.
Why this answer
(myimage@sha256:abcdef...) uses a digest-based image reference, which pins the image to an immutable content hash. This ensures that the exact same image is always pulled, regardless of tag updates, and any change to the image would require updating the manifest. This aligns with the requirement that the image version cannot be changed without modifying the manifest.
Exam trap
A common misconception is that semantic version tags (e.g., 'v1.0' or '1.0.0') are immutable, but in reality, tags are mutable pointers that can be reassigned, whereas only digest references provide true immutability.
How to eliminate wrong answers
Option B (myimage:latest) is wrong because the 'latest' tag is mutable and can be updated to point to a different image without changing the manifest, violating the requirement. Option C (myimage:v1.0) is wrong because tags like 'v1.0' can be reassigned to a different image digest, allowing the image to change without a manifest update. Option D (myimage:1.0.0) is wrong for the same reason as C—semantic version tags are mutable and can be overwritten, so they do not guarantee immutability.