How to Inspect The containerd Image Hash in a Kubernetes Cluster
In certain circumstances, you might need to compare the Containerd image hashes of two images. Below are the instructions to inspect a Containerd image hash of an image in a Kubernetes cluster. We will be using the Envoy pod as an example.
- Run the following command to get the Pod name of the running Envoy Proxy container:
kubectl get pods -A
- Run the following command to get the image name and tag of the Envoy Proxy container:
kubectl describe pod <pod-name> -n <namespace> | grep "Image:"
//Replace <pod-name> with the Pod name obtained in the previous step.
//This command will output the Docker image name and tag of the Envoy Proxy container. It should look something like this:
Image: envoyproxy/envoy:v1.15.0
- Run the following command to get the container image hash of the Envoy Proxy image:
ctr -n k8s.io images ls | awk '/envoyproxy\/envoy:v1.15.0/ {print $3}'
//This command will output the Containerd image hash of the Envoy Proxy image. It should look something like this:
sha256:3f5f11e23883561f6f064a82dcfd3d2942136a3cd400255fc37af918b6521b02