Bitnami Image Gate: Compose, Helm, Dockerfile

Flags Bitnami image lines that broke with the 2025-09-29 catalog change: removed docker.io/bitnami tags, frozen bitnamilegacy images, Helm values pins, allowInsecureImages. Runs entirely in your browser — nothing is uploaded.

Same engine as the VS Code extension, byte for byte.

Get the complete version $29

This page is the working piece. The full pack has everything below.

Finds the Bitnami image lines that broke on 2025-09-29, when versioned docker.io/bitnami tags moved to the frozen docker.io/bitnamilegacy archive

Bitnami Secure Images, the subscription that keeps versioned Bitnami tags, is reported at $50,000 to $72,000 per year (Minimus, iits-consulting).

Buy the full version — $29
Want the full version?
Enter your email and we send the download link.
ENDEJAESPT

Find a tool

· ReadyStack

Worked example

Real numbers from this tool, line by line.

Bitnami Image Gate: Compose, Helm, Dockerfile

Six Bitnami lines to fix: that is what DevOps and platform engineers see when the dirty.yaml sample, a docker-compose file plus Helm values written before the 2025-09-29 Bitnami catalog change, runs through Bitnami Image Gate. Four findings are errors that stop a pull or pin a frozen image; two are warnings.

What changed on 2025-09-29

Bitnami moved every versioned tag out of the public docker.io/bitnami catalog into docker.io/bitnamilegacy. Bitnami states that the legacy repository receives no further updates. The free images that stay under docker.io/bitnami are published for development on the latest tag only. Versioned images, LTS branches and continuous patches moved to Bitnami Secure Images, a subscription reported at $50,000 to $72,000 per year by Minimus and iits-consulting.

Why it breaks quietly

A cluster that already holds the image in its node cache keeps running. The failure waits for the next fresh node, an autoscaling event, a new CI runner or a cache eviction. Then the pod sits in ImagePullBackOff with manifest unknown, usually during a rollout nobody planned around the image. A cached local docker pull still succeeds, so the laptop test passes. Chatbots trained before the change still write bitnami/postgresql:15 into new compose files.

The six lines in the sample

Broken lineRuleFix
image: bitnami/postgresql:15.4.0BN01 errormirror the tag into your own registry
image: docker.io/bitnami/redis:7.2BN01 errorupstream redis:7.2
image: bitnamilegacy/kafka:3.6.1BN02 errorfrozen archive: move to a maintained image
image: bitnami/nginx@sha256:3f1a...BN06 warningre-resolve the digest from your mirror
allowInsecureImages: trueBN05 warningkeep only for your own verified mirror
repository: bitnami/mongodb + tag: 7.0.5BN03 erroroverride image.registry and image.repository

The clean.yaml sample, where every image comes from a private mirror or an upstream image such as redis:7.2 or apache/kafka:3.8.0, returns 0 findings.

How the check reads a file

The engine works line by line and skips comment lines. It looks at image: keys, Dockerfile FROM lines and docker run or docker pull commands. For Helm values it pairs a repository: bitnami/<app> line with the tag: that follows within five lines, because Bitnami charts split registry, repository and tag into separate keys. A bitnamilegacy reference is flagged wherever it appears. The allowInsecureImages flag gets its own rule because Bitnami charts refuse a non-default image unless it is true, and teams flip it to reach bitnamilegacy, which also turns off the chart's image verification.

The check date is an input. Set it before 2025-09-29 and the removed-tag rules drop to warnings marked breaks on 2025-09-29; from that date on they are errors.

Free and full version

The free version scans the open Dockerfile, Compose or Helm values file with all seven rules and shows every finding with its fix, with no key and no account. The same engine runs in the free web version on the hub page. The full version scans every file in the workspace at once and exports one Markdown migration report with file, line, image and replacement, for $29 once with one licence key per person or team seat.

15 seconds — what it actually does

Questions people ask

What does Bitnami Image Gate check?

Bitnami Image Gate reads docker-compose files, Helm values files and Dockerfiles line by line and flags Bitnami image references that broke with the 2025-09-29 catalog change: versioned docker.io/bitnami tags that no longer pull, frozen bitnamilegacy images, Helm values that pin a removed tag, digest pins from the old catalog and allowInsecureImages overrides. Each finding shows the line and a fix.

Who is Bitnami Image Gate for?

It is for DevOps engineers, platform teams and developers who run Bitnami containers or Bitnami Helm charts in Docker Compose, Kubernetes or CI pipelines. If a cluster still starts pods from docker.io/bitnami images with a version tag, the next fresh node or new CI runner can fail the pull with ImagePullBackOff, and this tool shows which lines cause it.

Why not just ask a chatbot or run docker pull?

Chatbots trained before 2025-09-29 still suggest tags such as bitnami/postgresql:15 in new compose files. A local docker pull can succeed from the image cache, so the laptop test passes while a new Kubernetes node fails. Bitnami Image Gate checks the text of the file against the catalog change, so a cached image does not hide the broken reference.

What is free and what does the paid version add?

The free version scans the open Dockerfile, Compose or Helm values file with all 7 rules and shows every finding with its fix, with no key and no account. The paid version, one payment of $29, scans every file in the workspace at once and exports one Markdown migration report listing file, line, image and replacement for the team.

What does the alternative cost?

Keeping versioned Bitnami tags means licensing Bitnami Secure Images, a subscription reported at $50,000 to $72,000 per year by Minimus and iits-consulting. Mirroring images into your own registry or moving to upstream images costs engineering time instead. Bitnami Image Gate does not replace either path; it lists which lines need one of them.

Why not just ask ChatGPT or another AI chat?

A general AI chat answers from training data with a cutoff date, cannot read your repository and names no rule version. Bitnami Image Gate: Compose, Helm, Dockerfile checks the file you open against 7 rules from a rule set dated 2026-09-27, and points at the exact line with the fix. For a filing, an audit or a client you need that dated result on your own files.

Ask about this tool

One question, answered by the person who built it. Your email only if you want the answer sent.