Flags Bitnami image lines that broke with the 2025-09-29 catalog change: removed docker.io/bitnami tags, frozen bitnamilegacy images, Helm values pins, allowInsecureImages. Runs entirely in your browser — nothing is uploaded.
Same engine as the VS Code extension, byte for byte.
This page is the working piece. The full pack has everything below.
Finds the Bitnami image lines that broke on 2025-09-29, when versioned docker.io/bitnami tags moved to the frozen docker.io/bitnamilegacy archive
Bitnami Secure Images, the subscription that keeps versioned Bitnami tags, is reported at $50,000 to $72,000 per year (Minimus, iits-consulting).
Buy the full version — $29· ReadyStack
Real numbers from this tool, line by line.

Six Bitnami lines to fix: that is what DevOps and platform engineers see when the dirty.yaml sample, a docker-compose file plus Helm values written before the 2025-09-29 Bitnami catalog change, runs through Bitnami Image Gate. Four findings are errors that stop a pull or pin a frozen image; two are warnings.
Bitnami moved every versioned tag out of the public docker.io/bitnami catalog into docker.io/bitnamilegacy. Bitnami states that the legacy repository receives no further updates. The free images that stay under docker.io/bitnami are published for development on the latest tag only. Versioned images, LTS branches and continuous patches moved to Bitnami Secure Images, a subscription reported at $50,000 to $72,000 per year by Minimus and iits-consulting.
A cluster that already holds the image in its node cache keeps running. The failure waits for the next fresh node, an autoscaling event, a new CI runner or a cache eviction. Then the pod sits in ImagePullBackOff with manifest unknown, usually during a rollout nobody planned around the image. A cached local docker pull still succeeds, so the laptop test passes. Chatbots trained before the change still write bitnami/postgresql:15 into new compose files.
| Broken line | Rule | Fix |
|---|---|---|
| image: bitnami/postgresql:15.4.0 | BN01 error | mirror the tag into your own registry |
| image: docker.io/bitnami/redis:7.2 | BN01 error | upstream redis:7.2 |
| image: bitnamilegacy/kafka:3.6.1 | BN02 error | frozen archive: move to a maintained image |
| image: bitnami/nginx@sha256:3f1a... | BN06 warning | re-resolve the digest from your mirror |
| allowInsecureImages: true | BN05 warning | keep only for your own verified mirror |
| repository: bitnami/mongodb + tag: 7.0.5 | BN03 error | override image.registry and image.repository |
The clean.yaml sample, where every image comes from a private mirror or an upstream image such as redis:7.2 or apache/kafka:3.8.0, returns 0 findings.
The engine works line by line and skips comment lines. It looks at image: keys, Dockerfile FROM lines and docker run or docker pull commands. For Helm values it pairs a repository: bitnami/<app> line with the tag: that follows within five lines, because Bitnami charts split registry, repository and tag into separate keys. A bitnamilegacy reference is flagged wherever it appears. The allowInsecureImages flag gets its own rule because Bitnami charts refuse a non-default image unless it is true, and teams flip it to reach bitnamilegacy, which also turns off the chart's image verification.
The check date is an input. Set it before 2025-09-29 and the removed-tag rules drop to warnings marked breaks on 2025-09-29; from that date on they are errors.
The free version scans the open Dockerfile, Compose or Helm values file with all seven rules and shows every finding with its fix, with no key and no account. The same engine runs in the free web version on the hub page. The full version scans every file in the workspace at once and exports one Markdown migration report with file, line, image and replacement, for $29 once with one licence key per person or team seat.
Bitnami Image Gate reads docker-compose files, Helm values files and Dockerfiles line by line and flags Bitnami image references that broke with the 2025-09-29 catalog change: versioned docker.io/bitnami tags that no longer pull, frozen bitnamilegacy images, Helm values that pin a removed tag, digest pins from the old catalog and allowInsecureImages overrides. Each finding shows the line and a fix.
It is for DevOps engineers, platform teams and developers who run Bitnami containers or Bitnami Helm charts in Docker Compose, Kubernetes or CI pipelines. If a cluster still starts pods from docker.io/bitnami images with a version tag, the next fresh node or new CI runner can fail the pull with ImagePullBackOff, and this tool shows which lines cause it.
Chatbots trained before 2025-09-29 still suggest tags such as bitnami/postgresql:15 in new compose files. A local docker pull can succeed from the image cache, so the laptop test passes while a new Kubernetes node fails. Bitnami Image Gate checks the text of the file against the catalog change, so a cached image does not hide the broken reference.
The free version scans the open Dockerfile, Compose or Helm values file with all 7 rules and shows every finding with its fix, with no key and no account. The paid version, one payment of $29, scans every file in the workspace at once and exports one Markdown migration report listing file, line, image and replacement for the team.
Keeping versioned Bitnami tags means licensing Bitnami Secure Images, a subscription reported at $50,000 to $72,000 per year by Minimus and iits-consulting. Mirroring images into your own registry or moving to upstream images costs engineering time instead. Bitnami Image Gate does not replace either path; it lists which lines need one of them.
A general AI chat answers from training data with a cutoff date, cannot read your repository and names no rule version. Bitnami Image Gate: Compose, Helm, Dockerfile checks the file you open against 7 rules from a rule set dated 2026-09-27, and points at the exact line with the fix. For a filing, an audit or a client you need that dated result on your own files.
One question, answered by the person who built it. Your email only if you want the answer sent.