Misconfigured Pod NetworkPolicy

NetworkPolicy restrictions may not apply as intended when a Pod is outside the policy’s namespace or selector.

Description

A NetworkPolicy does not apply to a Pod if it is in a different namespace or its podSelector does not select that Pod. A workload may therefore remain exposed despite appearing to have network protection.

Check the actual namespace, labels and selected Pods rather than only the presence of a policy. Enforcement requires a network plugin that supports NetworkPolicy, and the traffic allowed by multiple policies is combined.

Potential impact

  • Pod-to-Pod or external communication may be broader than intended.
  • Internal services may remain unprotected.
  • Declared policies may not provide the expected network isolation.

Remediation

  • Place the NetworkPolicy in the same namespace as the Pods it protects.
  • Verify that podSelector matches the actual Pod labels.
  • Test that traffic restrictions are enforced after applying the policy.

Examples

Prepare the namespaces and application images separately. The old nginx version in the example is not a deployment recommendation.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: sample-pod
  namespace: app-one
  labels:
    app: shouldmatch
spec:
  containers:
    - name: nginx
      image: nginx:1.14.2
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: sample-policy
  namespace: app-another
spec:
  podSelector:
    matchLabels:
      app: shouldmatch

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: sample-pod
  namespace: app-safe
spec:
  containers:
    - name: app
      image: images.my-company.example/app:v4
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: sample-policy
  namespace: app-safe
spec:
  podSelector: {}
  policyTypes:
    - Ingress
    - Egress

Explanation:

  • Before: The policy is in a different namespace and does not select the illustrated Pod.
  • After: Applies default-deny ingress and egress to all Pods in the same namespace. Other policies can still allow traffic; review the complete policy set and explicitly allow required DNS and application communication.

References