Description
Kubernetes RBAC controls the operations available to users and service accounts through roles and bindings. If it is disabled in AKS, those role-based restrictions cannot be enforced. When the setting is absent from a template, check the actual cluster state.
Potential impact
Users or service accounts able to perform more operations than necessary can affect additional cluster resources or access data beyond their intended scope.
Remediation
Explicitly set properties.enableRBAC: true and grant only the necessary Role, ClusterRole and bindings. Check the settings and administrator permissions on existing clusters, and test allowed and denied operations as ordinary users and service accounts. This setting is distinct from the Azure RBAC authorization option selected through aadProfile.enableAzureRBAC.
Examples
This example creates a cluster with a supported API and a managed identity. Supply the account name and public key through adminUserName and sshPublicKey and choose a VM size available in the target region. Kubernetes uses the service's supported default version.
Before
param adminUserName string
param sshPublicKey string
param nodeVmSize string = 'Standard_D2s_v3'
resource aksCluster1 'Microsoft.ContainerService/managedClusters@2024-10-01' = {
name: 'aksCluster1'
location: resourceGroup().location
identity: {
type: 'SystemAssigned'
}
properties: {
dnsPrefix: 'dnsprefix'
agentPoolProfiles: [
{
name: 'agentpool'
count: 2
vmSize: nodeVmSize
osType: 'Linux'
mode: 'System'
}
]
linuxProfile: {
adminUsername: adminUserName
ssh: {
publicKeys: [
{
keyData: sshPublicKey
}
]
}
}
}
}
The configuration does not explicitly specify RBAC. Omission alone does not establish that it is disabled.
After
param adminUserName string
param sshPublicKey string
param nodeVmSize string = 'Standard_D2s_v3'
resource aksCluster1 'Microsoft.ContainerService/managedClusters@2024-10-01' = {
name: 'aksCluster1'
location: resourceGroup().location
identity: {
type: 'SystemAssigned'
}
properties: {
enableRBAC: true
dnsPrefix: 'dnsprefix'
agentPoolProfiles: [
{
name: 'agentpool'
count: 2
vmSize: nodeVmSize
osType: 'Linux'
mode: 'System'
}
]
linuxProfile: {
adminUsername: adminUserName
ssh: {
publicKeys: [
{
keyData: sshPublicKey
}
]
}
}
}
}
RBAC is explicitly enabled. The assigned roles and bindings determine the actual permissions.