Description
AKS network policies can restrict communication between Pods to the required scope. Without a network configuration that enforces policies and workload NetworkPolicy resources, intended traffic restrictions might not take effect.
Ansible's network_profile.network_policy must use a value supported by the installed collection and AKS networking configuration. Selecting a policy engine alone does not automatically restrict all Pod traffic.
Potential impact
- Unnecessarily open Pod communication can make lateral movement easier after a compromise.
- Unsupported settings can cause cluster creation or updates to fail.
Remediation
- Choose a policy configuration supported by the installed
azure.azcollectionand the cluster's network plugin. - Use actual
NetworkPolicyresources to allow required traffic, and test permitted and blocked connections. - Check whether the existing cluster supports the change and plan for possible disruption before applying it.
Examples
These partial examples focus on the network policy field. Set aks_kubernetes_version to a supported version and supply authentication, node, and network configuration separately. The short module name requires an environment that resolves the collection.
Before
- name: AKS 클러스터 생성
azure_rm_aks:
name: myAKS
location: eastus
resource_group: myResourceGroup
dns_prefix: akstest
kubernetes_version: "{{ aks_kubernetes_version }}"
network_profile:
network_policy: istio
agent_pool_profiles:
- name: default
count: 5
vm_size: Standard_D2_v2
istio is not a supported choice for this module's network_policy field and is not a valid setting.
After
- name: AKS 클러스터 생성
azure_rm_aks:
name: myAKS
location: eastus
resource_group: myResourceGroup
dns_prefix: akstest
kubernetes_version: "{{ aks_kubernetes_version }}"
network_profile:
network_policy: calico
agent_pool_profiles:
- name: default
count: 5
vm_size: Standard_D2_v2
calico is a supported module choice. Verify compatibility with the network plugin and deploy actual NetworkPolicy resources to enforce traffic restrictions.