Kubernetes ImagePullBackOff: Causes in Order of Likelihood

Symptom

Pod stuck with ErrImagePull then ImagePullBackOff.

Root cause

kubelet cannot fetch the image: name/tag, registry auth, or network.

Fix, in order

1. Confirm the tag exists in the registrydocker manifest inspect <image>:<tag>
2. Check secret exists and is referencedkubectl get secret <pull-secret> && kubectl describe pod <pod> | grep -A2 "Image:"
3. Look at the kubelet event detailkubectl describe pod <pod> | grep -A5 Events
4. For private registries verify imagePullSecretsimagePullSecrets: [{ name: regcred }]

Prevent it coming back

Pin digests for critical images; validate manifests in CI.

Deep-dive article

Full walkthrough: Kubernetes ImagePullBackOff: Causes in Order of Likelihood on the NinjaOps blog.

Run it on clean infra

Spinning up a fresh box to reproduce or escape this error?

Managed cloud hosting

Related

Cloud & DevOps tool comparisons · Hardware build guides

NinjaOps publishes free engineering guides. Some outbound links are affiliate links: they cost you nothing and support the site.

Last reviewed 2026-10-02 · NinjaOps SEO grid · DevOps blog