Kubernetes RBAC is disabled for AKS

Use Kubernetes RBAC in AKS to limit user and service-account permissions.

Description

Kubernetes RBAC in AKS limits the operations users and service accounts can perform through roles and role bindings. Configurations with enable_rbac disabled cannot use this access control.

Potential impact

It is harder to restrict the operations of principals that can reach the cluster, potentially exposing workloads or secrets to unnecessary access.

Remediation

Enable enable_rbac when creating the cluster and configure least-privilege roles and bindings. Check whether an existing cluster supports the change and plan workload migration if direct conversion is unsupported.

Examples

The examples compare only RBAC settings. Supply a kubernetes_version supported in the region and configure node pools and identity separately. Kubernetes RBAC and Azure RBAC authorization are distinct settings.

Before

yaml
- name: AKS 생성
  azure.azcollection.azure_rm_aks:
    name: myAKS
    resource_group: myResourceGroup
    location: eastus
    dns_prefix: akstest
    kubernetes_version: "{{ kubernetes_version }}"
    enable_rbac: no

After

yaml
- name: AKS 생성
  azure.azcollection.azure_rm_aks:
    name: myAKS
    resource_group: myResourceGroup
    location: eastus
    dns_prefix: akstest
    kubernetes_version: "{{ kubernetes_version }}"
    enable_rbac: yes

References