√ pods do not use host networking √ pods do not have a 3rd party proxy or initContainer already injected √ pods are not annotated to disable injection √ at least one resource can be injected or annotated √ pod specs do not include UDP ports √ pods do not have automountServiceAccountToken set to "false" or service account token projection is enabled deployment "contour" injected