# NetworkPolicy Has No Rules | ZopNight

> The policy selects pods but defines no rules, so it either silently blocks traffic they need or reads as segmentation that is not actually filtering.

Source: https://zop.dev/zopnight/rules/networkpolicy-has-no-rules

---

_Security · Low severity_

## NetworkPolicy Has No Rules

The policy selects pods but defines no rules, so it either silently blocks traffic they need or reads as segmentation that is not actually filtering anything.

- 3 — clouds covered
- Low — severity
- Risk — where it shows up
- Manual — fix, change spelled out

Free to start. No card. The playground just needs your work email.

## Found, explained, handed over.

Exposure and fragility, security posture and single points of failure.

- 01. Detect — ZopNight checks this automatically across AWS, Azure and Google Cloud, with read-only access to the account.
- 02. Explain — Every finding says exactly what to change: Add rules to the empty network policy.
- 03. Fix — The finding opens with the change already spelled out, so the fix is one ticket, not an investigation.

- applies_to_fallback: Any resource in the account
- where_it_appears: The Risk tab of Recommendations, with every affected resource listed.

## Related

- [Privileged Container](https://zop.dev/zopnight/rules/privileged-container)
- [Bedrock Agent Without Guardrail](https://zop.dev/zopnight/rules/bedrock-agent-without-guardrail)
- [Bedrock Guardrail Missing PII / Sensitive-Information Protection](https://zop.dev/zopnight/rules/bedrock-guardrail-missing-pii-sensitive-information-protection)
- [Container Running as Root](https://zop.dev/zopnight/rules/container-running-as-root)
- [Container with Host Network](https://zop.dev/zopnight/rules/container-with-host-network)
- [Ingress Without TLS](https://zop.dev/zopnight/rules/ingress-without-tls)

## See the security findings in your account.

Connect a read-only role and the first pass runs on your own estate. This check, and the rest of the catalogue, with it.

[object Object]
