Description
When a Kubernetes label violates syntax rules, the API can reject resource creation or modification. Services, NetworkPolicies and automation use labels to select resources, so both syntax and meaning matter.
A label value may be empty or contain up to 63 characters. A nonempty value must start and end with an ASCII letter or digit; internal characters may also include hyphens, underscores and dots.
Potential impact
- Invalid labels can cause deployment or resource updates to fail.
- Even valid labels may not select the intended resources if selectors do not match.
Remediation
- Use label keys and values that follow Kubernetes rules. Check the optional DNS prefix and name portion of keys as well.
- When changing labels, review Service and policy selectors together and verify the actual selected resources.
Examples
These historical examples compare label values. Use a maintained, verified image for deployment.
Before
yaml
apiVersion: v1
kind: Pod
metadata:
name: goproxy
labels:
app: g**dy.l+bel.
spec:
containers:
- name: goproxy
image: k8s.gcr.io/goproxy:0.1
The app value contains asterisks, a plus sign and a trailing dot, making it invalid.
After
yaml
apiVersion: v1
kind: Pod
metadata:
name: goproxy
labels:
app: goproxy
spec:
containers:
- name: goproxy
image: k8s.gcr.io/goproxy:0.1
The valid value goproxy is used. Selectors on other resources must match it as well.