# Kubernetes ImageInspectError: what it means and how to fix

## TL;DR
The kubelet could not even read the image metadata, so the problem is earlier and vaguer than a pull failure: usually the registry is unreachable, the tag was deleted, or auth failed. Verify the tag still exists, the registry is reachable from the node, and the pull secret is valid. Inspect happens before pull, which is why you get this instead of the more familiar ImagePullBackOff.

```text
Kubernetes "ImageInspectError": what it means and how to fix
```

## Steps

1. **Read the full message.** Run `kubectl describe pod [pod]` and find the ImageInspectError event.
   Expected: the message names the registry and image it tried to inspect.

2. **Verify the tag still exists.** Check your registry UI or API for the exact repository and tag.
   Expected: the tag is present, or you discover it was deleted or overwritten.

3. **Test registry reachability from a node.** Confirm DNS resolves the registry host and the registry port is open from the node network.
   Expected: no network block between node and registry.

4. **Check the pull secret.** Confirm the secret exists in the pod's namespace and its credentials are current. Private registries with rotated passwords are a classic cause.
   Expected: the secret is present and fresh.

5. **Read the kubelet and runtime logs.** The pod event is terse; the logs usually carry the real error (TLS failure, 401, 404).
   Expected: you find the underlying error the event summary hid.

6. **Fix and retry.** Correct whichever layer failed, then delete the pod so it retries immediately (or wait out the backoff).
   Expected: the pod moves to pulling, then Running.

## Use this when
- Pod events show ImageInspectError
- Private registry images suddenly stop working
- Tags get cleaned by registry retention policies

## Not for this skill when
- The error is ImagePullBackOff (the pull started, then failed)
- The error is ErrImagePull (transient pull problem)
- The image pulls fine but the container crashes (that is CrashLoopBackOff)

## Variant phrasings
- kubernetes image inspect error
- failed to inspect image kubernetes
- imageinspecterror fix
- kubelet failed to inspect image

## Why it happens
The container runtime inspects image metadata before creating the container. If the registry handshake fails at that metadata step (auth, TLS, 404 on the manifest), you get ImageInspectError instead of a pull error. Same family, earlier failure point.

## Edge cases
- Registries using mutual TLS need the client certs on the node, not just in the pod. Easy to miss.
- Registry garbage collection can delete tags out from under a deployment that used to work.
- The terse event sometimes masks a plain DNS failure. If everything else looks right, check name resolution.
- Cached credentials on the node can go stale independently of the pod's pull secret.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_XyLgkfi2N_40it2FowKo1A
