Skip to content
| Marketplace
Sign in
Visual Studio Code>Linters>NetPolicy Map: Kubernetes Policies for TerraformNew to Visual Studio Code? Get it now.
NetPolicy Map: Kubernetes Policies for Terraform

NetPolicy Map: Kubernetes Policies for Terraform

netpolicymap

|
1 install
| (0) | Free
Visualize your Kubernetes network policies and infrastructure topology generated from Terraform files as an interactive graph.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

NetPolicy Map — Kubernetes Network Policy Analyzer

Stop guessing whether traffic is allowed. NetPolicy Map reads the Kubernetes NetworkPolicy resources in your Terraform (.tf) files, interprets their selectors and rules across the selected project folders, and explains which declared policies allow or block a connection, with links to the source.

Launch trial: every feature in this VS Code extension is currently available to everyone — no account or license key required. The CLI will be released separately and is not included with the extension.

Important — indicative analysis: The graph and reachability results are an interpretation of the Kubernetes NetworkPolicy resources found in Terraform. They show logical links between selected endpoints and may not match the cluster's runtime behavior exactly. NetPolicy Map does not model every network component or validate the complete end-to-end path, so its results are not a guarantee of connectivity or isolation. Verify critical conclusions in the cluster; the extension is provided as an analysis aid and accepts no responsibility for outcomes based on its visualizations.

NetPolicy Map demo: visualize Terraform policies, test connections, inspect policy evidence, and explore reachability

Why?

Debugging Kubernetes Network Policies defined as Terraform across multiple repos is painful. You stare at kubernetes_network_policy blocks, mentally trace label selectors across namespaces, and still end up guessing whether traffic is allowed or blocked. NetPolicy Map automates that reasoning and shows you the answer — with the exact file:line of the rule that blocks traffic.

Features

Available in the launch trial

Feature What you get
Policy Tree View Namespaces → pods → ingress/egress rules in the sidebar, color-coded: green (allowed), gray (default-deny), yellow (no policy)
"Why? (Can I Connect?)" Pick source pod + destination pod + port → allowed/blocked verdict with the exact blocking policies (file:line)
Diagnostics Malformed policies, missing policyTypes, unintended default-deny, podSelector matching no pod
Hover Summary Human-readable summary of any kubernetes_network_policy block
Project Folder Selector Every directory with .tf files detected as a candidate project, with multi-folder selection
Full Interactive Graph All selectors unlocked: namespace, pod, project folders (multi-select), search
Focus Graph Map Three-column board (Ingress · Focus · Egress) with policy evidence per connection
Connection Inspector Direction, ports, and policy source links for any connection
Reachability Every endpoint a pod, namespace, or IP/CIDR can reach — or be reached from
Cross-Repo Analysis Correlates policies across all repositories in your VS Code workspace
Advanced Linter 0.0.0.0/0 open traffic, overlapping rules that cancel out, orphaned labels, missing default-deny

Screenshots

Allowed connection Blocked connection
Allowed connection Blocked connection

Focus board

Quickstart

  1. Install the extension and open a workspace folder containing .tf files with kubernetes_network_policy, kubernetes_network_policy_v1, or inline kubernetes_manifest NetworkPolicy resources.
  2. Click the NetPolicy Map icon in the activity bar — the policy tree appears.
  3. Press Ctrl+Shift+P → NetPolicy Map: Why? (Can I Connect?) → pick source pod, destination pod, and port → see the verdict and the blocking rules in the Output panel.

Tip: hover any kubernetes_network_policy block in a .tf file for an instant summary, and check the Problems tab for policy diagnostics.

Starting without a project? Run NetPolicy Map: Open Terraform Example, save the example as quickstart.tf inside an open workspace folder, then open the graph. The example policy allows client → API on TCP 8080 and blocks TCP 9090.

Terraform compatibility and analysis scope

Input Support
kubernetes_network_policy, kubernetes_network_policy_v1 Selectors, ingress/egress, CIDR exceptions, named ports, port ranges, TCP/UDP/SCTP
kubernetes_manifest with kind = "NetworkPolicy" Inline networking.k8s.io/v1 objects; unresolved structures are reported as analysis gaps
Pods, Deployments, StatefulSets, DaemonSets Typed resources and inline workload manifests; controller endpoints use pod-template labels
Variables and locals Defaults, terraform.tfvars, *.auto.tfvars, and a selected .tfvars environment; partial expression evaluation
Functions length, keys, values, lookup, merge, concat, format, join, toset, try, coalesce for supported known inputs
for_each, count, dynamic Known resource values; local module instances support count and for_each
Local modules Sources inside the workspace boundary, up to three nested levels

Remote Registry/Git modules, Helm chart rendering, standalone YAML, kubectl_manifest, .tf.json, and .tfvars.json are not analyzed. Terraform environment variables, CLI arguments, remote data sources, and values known only during planning or apply are not automatically available. Resource and dynamic-block expansion is limited to 50 entries per expansion; omissions are reported.

Inspect Terraform analysis for policies requiring attention, skipped resources, missing modules, and expansion limits. Connectivity queries show Indeterminate when missing data could change the result. Reachability requests require complete analysis of the selected scope. “Resolved” describes the available Terraform values, not a guarantee about the running cluster.

Only select project folders that describe the same cluster and environment. Matching namespaces are combined across selected folders; provider aliases do not establish separate clusters. Endpoints inferred from policy selectors represent possible matching pods, not observed running pods. Confirm the selected project folders and variable environment before interpreting results.

Commands

Command Description
NetPolicy Map: Why? (Can I Connect?) Connectivity query between two pods
NetPolicy Map: Open Interactive Graph Full graph view
NetPolicy Map: Open Reachability Reachability analysis
NetPolicy Map: Refresh Re-scan the workspace
NetPolicy Map: Open Terraform Example Open an editable sample project file
NetPolicy Map: Report Issue / Send Feedback Prepare an editable feedback report
NetPolicy Map: Copy Reviewed Feedback and Open Email Draft Copy the reviewed report and open your email client

Launch trial

All extension functionality is enabled during the launch trial, including the full graph, reachability, cross-repository analysis, and advanced linting. There is no Pro tier to purchase or activate in this release.

CLI (CI/CD)

The CLI is being prepared as a separate CI/CD package. It is not included when installing the VS Code extension and is not yet available for installation.

Requirements

  • VS Code 1.90 or newer
  • Terraform files containing supported Kubernetes NetworkPolicy resources (see compatibility above)

Support & Feedback

  • Email: netpolicymap@gmail.com

Use Report Issue / Send Feedback from the Command Palette or the policy sidebar's feedback button. It opens an editable local report with extension/VS Code versions, platform, and aggregate counts. Add what you expected, what happened, and steps to reproduce. A small sanitized .tf example or screenshot is optional and especially useful for compatibility issues.

After reviewing the report, run Copy Reviewed Feedback and Open Email Draft. Paste the report into the draft and send it yourself. If no email app opens, the support address and report remain available for use in webmail. Terraform content, file paths, labels, variables, account details, and license keys are never automatically included. No report is sent automatically.

Data & Privacy

NetPolicy Map collects no telemetry. During the launch trial, the extension runs without an account or license key.

License

Proprietary. The current Marketplace release is a launch trial with all extension features enabled. See the LICENSE.txt file bundled with this extension.

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft