Review Kubernetes metadata label syntax

Check valid label syntax and actual selector matches together.

Description

When a Kubernetes label violates syntax rules, the API can reject resource creation or modification. Services, NetworkPolicies and automation use labels to select resources, so both syntax and meaning matter.

A label value may be empty or contain up to 63 characters. A nonempty value must start and end with an ASCII letter or digit; internal characters may also include hyphens, underscores and dots.

Potential impact

  • Invalid labels can cause deployment or resource updates to fail.
  • Even valid labels may not select the intended resources if selectors do not match.

Remediation

  • Use label keys and values that follow Kubernetes rules. Check the optional DNS prefix and name portion of keys as well.
  • When changing labels, review Service and policy selectors together and verify the actual selected resources.

Examples

These historical examples compare label values. Use a maintained, verified image for deployment.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: goproxy
  labels:
    app: g**dy.l+bel.
spec:
  containers:
    - name: goproxy
      image: k8s.gcr.io/goproxy:0.1

The app value contains asterisks, a plus sign and a trailing dot, making it invalid.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: goproxy
  labels:
    app: goproxy
spec:
  containers:
    - name: goproxy
      image: k8s.gcr.io/goproxy:0.1

The valid value goproxy is used. Selectors on other resources must match it as well.

References