Skip to content

Usage

Query inventory

kubectl get images -A
kubectl get images -n my-app
kubectl get img -n my-app

Printer columns: IMAGE, KINDS.

NAMESPACE   NAME                                   IMAGE                         KINDS
payments    docker-io-library-redis-7-4-a1b2c3d4   docker.io/library/redis:7.4   Deployment,Pod

status.kinds lists workload kinds that still reference the image in that namespace. Object names are not stored — list workloads with:

kubectl get deploy,sts,ds,job,cronjob,pod -n my-app

Kind attribution and GC rules: Architecture.

Examples

kubectl -n image-inventory-system rollout status deploy/image-inventory-controller --timeout=120s
make examples
kubectl get images -n image-inventory-demo
Kind Example image
Deployment nginx:1.27
StatefulSet postgres:16-alpine
DaemonSet fluent/fluent-bit:3.0
Job migrate/migrate:v4.17.0
CronJob amazon/aws-cli:2.15.0
Pod (naked) busybox:1.36
Shared httpd:2.4 → Deployment,Pod

Manifests: examples/.

Tenant read access

apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
  name: image-inventory-viewer
  namespace: payments
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: image-inventory-viewer
subjects:
  - kind: User
    name: alice

Scope

Inventory is reference-based: no digests, pod counts, or object-name graphs. Reference is not the same as a running Pod.