AKS network policies are not configured

Apply network policies in AKS to allow only required pod traffic.

Description

Without a network policy engine in AKS, Kubernetes NetworkPolicy cannot restrict traffic between pods. Pod-to-pod traffic is allowed by default.

Potential impact

Unnecessary connectivity can make it easier for a compromised workload to reach other services.

Remediation

Enable a policy engine compatible with the cluster network and deploy NetworkPolicy resources allowing the required ingress and egress. Check both allowed and blocked traffic.

Examples

These excerpts configure Azure NPM on Linux nodes. Supply a supported Kubernetes version and node size. Enabling the engine still requires deploying policies; for new clusters, also consider Microsoft’s recommended Cilium option.

Before

bicep
param kubernetesVersion string
param nodeVmSize string

resource aksCluster1 'Microsoft.ContainerService/managedClusters@2020-02-01' = {
  name: 'aksCluster1'
  location: resourceGroup().location
  properties: {
    kubernetesVersion: kubernetesVersion
    dnsPrefix: 'dnsprefix'
    agentPoolProfiles: [
      {
        name: 'agentpool'
        count: 2
        vmSize: nodeVmSize
        osType: 'Linux'
      }
    ]
  }
}

After

bicep
param kubernetesVersion string
param nodeVmSize string

resource aksCluster1 'Microsoft.ContainerService/managedClusters@2020-02-01' = {
  name: 'aksCluster1'
  location: resourceGroup().location
  properties: {
    kubernetesVersion: kubernetesVersion
    dnsPrefix: 'dnsprefix'
    agentPoolProfiles: [
      {
        name: 'agentpool'
        count: 2
        vmSize: nodeVmSize
        osType: 'Linux'
      }
    ]
    networkProfile: {
      networkPlugin: 'azure'
      networkPolicy: 'azure'
    }
  }
}

References