CNG kubectl container is hard-set to sha, will not roll in master
master branch, and subsequently all releases, hard-codes the
kubectl image SHA, which means it will never update without explicit committed changes. This means that a change to the ci_variables or Dockerfile for the image will never be reflected without direct interaction.
We need to have a method to ensure that updated images are actually used, or to alert & automate the update of the hard-coded SHA tag. We will soon have to update the version of
kubectl in use, as
1.15.x is on the way. Although the APIs for Secrets & Jobs are quite stable, we're likely to be forced to update this container.