The kubelet cannot pull your container image. Almost always one of four things: wrong tag, private registry without credentials, or a rate limit.
Typo in the tag, or the image was never pushed. 'manifest unknown' in events confirms it.
Private registry without an imagePullSecret. Events show 'unauthorized: authentication required'.
Anonymous pulls are limited; events show 'toomanyrequests'. Common on clusters pulling public images.
docker manifest inspect registry.example.com/app:v1.2.3
kubectl create secret docker-registry regcred \
--docker-server=registry.example.com \
--docker-username=you --docker-password=$PAT
imagePullSecrets:
- name: regcred
kubectl describe pod <pod> | grep -A3 Events
For rate limits, host a cached copy of base images in your own registry or use a pull-through cache. It removes the whole class of problem.
ErrImagePull is the live failure on the current attempt; ImagePullBackOff means the kubelet has given up for now and is waiting to retry with exponential backoff. Same causes, different phase — both point at the pull, not the app.
imagePullPolicy: Always (the default for :latest tags) forces a registry pull even when the image is present on the node. Use a pinned tag with IfNotPresent, or a local registry for internal images.
Kustomize base with probes, PDBs, and zero-downtime rollouts already wired.
Kubernetes Production Blueprints — $27 →One-time. Yours to modify. Instant download from the NinjaOps template store.