imagePullPolicy quyết định kubelet kéo image khi nào: Always, IfNotPresent, hoặc Never. Nếu dùng tag mutable như latest, behavior dễ khó đoán và rollback khó hơn.
Production nên dùng immutable version tags hoặc digest, private registry có auth rõ ràng, image scanning trong CI và retention policy. Khi rollout, đổi tag/digest trong manifest để Kubernetes tạo ReplicaSet mới.
imagePullPolicy controls when kubelet pulls an image: Always, IfNotPresent, or Never. Mutable tags such as latest make behavior harder to reason about and rollback harder.
Production should use immutable version tags or digests, private registry auth, image scanning in CI and a retention policy. During rollout, change the tag/digest in the manifest so Kubernetes creates a new ReplicaSet.