Review AKS network policy settings

Use a supported AKS network policy configuration and actual NetworkPolicies to allow only required Pod communication.

Description

AKS network policies can restrict communication between Pods to the required scope. Without a network configuration that enforces policies and workload NetworkPolicy resources, intended traffic restrictions might not take effect.

Ansible's network_profile.network_policy must use a value supported by the installed collection and AKS networking configuration. Selecting a policy engine alone does not automatically restrict all Pod traffic.

Potential impact

  • Unnecessarily open Pod communication can make lateral movement easier after a compromise.
  • Unsupported settings can cause cluster creation or updates to fail.

Remediation

  • Choose a policy configuration supported by the installed azure.azcollection and the cluster's network plugin.
  • Use actual NetworkPolicy resources to allow required traffic, and test permitted and blocked connections.
  • Check whether the existing cluster supports the change and plan for possible disruption before applying it.

Examples

These partial examples focus on the network policy field. Set aks_kubernetes_version to a supported version and supply authentication, node, and network configuration separately. The short module name requires an environment that resolves the collection.

Before

yaml
- name: AKS 클러스터 생성
  azure_rm_aks:
    name: myAKS
    location: eastus
    resource_group: myResourceGroup
    dns_prefix: akstest
    kubernetes_version: "{{ aks_kubernetes_version }}"
    network_profile:
      network_policy: istio
    agent_pool_profiles:
      - name: default
        count: 5
        vm_size: Standard_D2_v2

istio is not a supported choice for this module's network_policy field and is not a valid setting.

After

yaml
- name: AKS 클러스터 생성
  azure_rm_aks:
    name: myAKS
    location: eastus
    resource_group: myResourceGroup
    dns_prefix: akstest
    kubernetes_version: "{{ aks_kubernetes_version }}"
    network_profile:
      network_policy: calico
    agent_pool_profiles:
      - name: default
        count: 5
        vm_size: Standard_D2_v2

calico is a supported module choice. Verify compatibility with the network plugin and deploy actual NetworkPolicy resources to enforce traffic restrictions.

References