Pod IPs are in 10.0.0.0/24, not 10.42.0.0/16 as assumed. Broadening to 10.0.0.0/8 covers pods, services, and CNI overlays.