Updating the Container Image
Update the AI Runtime Security container image deployed to Kubernetes when a new version is released.
Overview
The container image is hosted on Quay.io and referenced in the deployment manifest:
Do not use the :latest tag in production. Kubernetes will not detect a change if the tag stays the same, so new images won’t be pulled automatically. Use explicit version tags (e.g., 26.1.0) to ensure updates are applied reliably.
Prerequisites
kubectlconfigured with access to your cluster- Access to the Quay.io registry (
quay.io/hiddenlayer) with valid credentials andimagePullSecretconfigured in your cluster - Your deployment name and namespace (referenced as
$NAMESPACEandaidr-genaiin the commands below)
Release Workflow
Step 1: Identify the new image tag
HiddenLayer publishes release notes for each new version. When you receive a release notification, use the tag from the release notes in the steps below.
New releases are published to Quay.io. Find the version you want to deploy:
You do not need to pull the image locally, as Kubernetes pulls it directly from the registry during the rolling update.
Step 2: Apply the update
You can update the image using either the manifest file or a direct kubectl patch.
Update manifest (recommended)
Patch inline
Edit the image tag in your deployment manifest:
Apply the updated manifest:
Kubernetes detects the tag change and triggers a rolling update automatically.
Step 3: Verify the rollout
Monitor the rolling update until it completes:
When the rollout is complete, you will see:
Rolling Back
If the new image causes issues, roll back to the previous version:
To roll back to a specific revision:
After rolling back, update the image tag in your deployment manifest to match the version now running in the cluster. If the manifest still references the newer tag, the next kubectl apply will re-deploy the broken version.