Skip to content
kix /docs
Install the CLI

Reference kix helpers

image, image.ref, and pins

The shared image option, the helpers that render and test an image reference, and the pin-file reader.

These helpers give every package the same image shape, so a cluster can pass a committed pin to any package and the digest reaches the manifest.

This page is hand-maintained. Check kix/lib/vocab/compose.nix and kix/lib/vocab/pins.nix when in doubt.

options.image = kix.options.image {
repository = "docker.io/library/nginx";
tag = "1.27-alpine";
};

Returns one lib.mkOption whose type is a submodule. The arguments are the package’s defaults:

ArgumentDefaultMeaning
repositoryrequiredImage repository, registry host included.
tagrequiredThe package’s tag.
digestnullThe package’s resolved digest for tag.
pullPolicy"IfNotPresent"imagePullPolicy for containers using the image. null leaves the field unset, so Kubernetes chooses: Always for :latest, IfNotPresent otherwise.
tagTextnullThe Nix expression the option reference shows as the tag’s default, for a tag the package’s config sets from another option. See Images released together.
descriptiona generic descriptionReplaces the option’s description.
FieldTypeDefault
repositorystringthe package’s repository
tagstringthe package’s tag
digestnull or stringthe package’s digest while tag equals the package’s tag, otherwise null
pullPolicynull or stringthe package’s pullPolicy
sourceRevnull or stringnull. The source revision the image was built from, when Kix built it.
promotedBynull or stringnull. Who resolved the pin.
resolvedAtnull or stringnull. When the pin was resolved, RFC 3339.
notenull or stringnull. Free text that Kix never reads.

An instance that sets some fields keeps the package’s defaults for the rest:

Instance setsResult
nothingThe package’s repository, tag, digest and pull policy.
repository only, such as a registry mirrorThe package’s tag, digest and pull policy under the new repository.
pullPolicy onlyThe package’s repository, tag and digest.
tag only, to a different tagThe package’s repository and pull policy, and no digest, because the package’s digest belongs to its own tag.
a whole pin from pins.getThe pin’s repository, tag and digest, and the package’s pull policy.

sourceRev, promotedBy, resolvedAt and note are declared so the option accepts a whole pin record.

A package whose images share one release can default one image’s tag from another. The package returns config beside options, and tagText makes the option reference show that default:

let
release = "v1.21.2";
in
{
options = {
image = kix.options.image {
repository = "quay.io/jetstack/cert-manager-controller";
tag = release;
};
webhook.image = kix.options.image {
repository = "quay.io/jetstack/cert-manager-webhook";
tag = release;
tagText = "config.image.tag";
};
};
config = { config, ... }: {
webhook.image.tag = lib.mkDefault config.image.tag;
};
}

Declare both tags from the same binding. The declared tag is the value the digest rule compares with, so a follower declared with an older tag would render the main tag without a digest. When an instance moves image.tag, the follower’s tag moves with it and its own digest is dropped. An instance can still set webhook.image.tag directly.

A lib.mkDefault in a package’s config sits below any value an instance or dependency injection sets, including one set with lib.mkDefault. See Add typed package options for the priority rules.

image = kix.image.ref config.image;
imagePullPolicy = config.image.pullPolicy;

Renders repository:tag, followed by @digest when digest is not null. Throws when repository or tag is missing or empty. It does not validate the digest or contact a registry.

A null pullPolicy renders no imagePullPolicy, because Kix drops null fields from manifests.

kix.image.isPinned config.image

True when the image has a non-null digest. It does not validate the digest.

pins = kix.pins ./pins.json;

Reads a pin file or an attrset of pins. mkFlake { pins = ./pins.json; } does the same for every cluster function that takes a pins argument.

AttributeResult
pins.get <key>The pin, shape-checked, ready to assign to an image option. A missing key throws with the kix pin set command that adds it.
pins.ref <key>kix.image.ref (pins.get <key>).
pins.keysEvery pin name in the file.
pins.allEvery pin, shape-checked.

Each pin needs repository and tag. digest, sourceRev, promotedBy, resolvedAt and note are optional, and any other field is an error. A digest must be sha256: followed by 64 lower-case hexadecimal characters. The file declares "version": 1 and holds the pins under images; a bare map of pins is also accepted. The shape check does not contact a registry; kix pin check does.