Description
Without a network policy engine in AKS, Kubernetes NetworkPolicy cannot restrict traffic between pods. Pod-to-pod traffic is allowed by default.
Potential impact
Unnecessary connectivity can make it easier for a compromised workload to reach other services.
Remediation
Enable a policy engine compatible with the cluster network and deploy NetworkPolicy resources allowing the required ingress and egress. Check both allowed and blocked traffic.
Examples
These excerpts configure Azure NPM on Linux nodes. Supply a supported Kubernetes version and node size. Enabling the engine still requires deploying policies; for new clusters, also consider Microsoft’s recommended Cilium option.
Before
bicep
param kubernetesVersion string
param nodeVmSize string
resource aksCluster1 'Microsoft.ContainerService/managedClusters@2020-02-01' = {
name: 'aksCluster1'
location: resourceGroup().location
properties: {
kubernetesVersion: kubernetesVersion
dnsPrefix: 'dnsprefix'
agentPoolProfiles: [
{
name: 'agentpool'
count: 2
vmSize: nodeVmSize
osType: 'Linux'
}
]
}
}
After
bicep
param kubernetesVersion string
param nodeVmSize string
resource aksCluster1 'Microsoft.ContainerService/managedClusters@2020-02-01' = {
name: 'aksCluster1'
location: resourceGroup().location
properties: {
kubernetesVersion: kubernetesVersion
dnsPrefix: 'dnsprefix'
agentPoolProfiles: [
{
name: 'agentpool'
count: 2
vmSize: nodeVmSize
osType: 'Linux'
}
]
networkProfile: {
networkPlugin: 'azure'
networkPolicy: 'azure'
}
}
}