Description
Kubernetes RBAC in AKS limits the operations users and service accounts can perform through roles and role bindings. Configurations with enable_rbac disabled cannot use this access control.
Potential impact
It is harder to restrict the operations of principals that can reach the cluster, potentially exposing workloads or secrets to unnecessary access.
Remediation
Enable enable_rbac when creating the cluster and configure least-privilege roles and bindings. Check whether an existing cluster supports the change and plan workload migration if direct conversion is unsupported.
Examples
The examples compare only RBAC settings. Supply a kubernetes_version supported in the region and configure node pools and identity separately. Kubernetes RBAC and Azure RBAC authorization are distinct settings.
Before
- name: AKS 생성
azure.azcollection.azure_rm_aks:
name: myAKS
resource_group: myResourceGroup
location: eastus
dns_prefix: akstest
kubernetes_version: "{{ kubernetes_version }}"
enable_rbac: no
After
- name: AKS 생성
azure.azcollection.azure_rm_aks:
name: myAKS
resource_group: myResourceGroup
location: eastus
dns_prefix: akstest
kubernetes_version: "{{ kubernetes_version }}"
enable_rbac: yes