Review AKS Dashboard use

Remove unnecessary management UIs and restrict access and permissions for those you retain.

Description

Kubernetes Dashboard is a management UI for cluster information. Leaving it enabled unnecessarily adds another interface to maintain. Enabling it does not by itself mean internet exposure, but weak authentication or access controls can expose information and management functions to unintended users.

Potential impact

  • An unnecessary management interface creates more opportunities for access-control mistakes.
  • Excessive permissions can increase the impact of incorrect changes through the UI.

Remediation

  • Identify the Dashboard installations and operational dependencies in use, and remove unnecessary ones. Perform required management tasks through approved paths protected by RBAC.
  • If a management UI is needed, restrict its access paths and apply authentication and least privilege. Manage separately installed Dashboards through their own deployment configuration.

Examples

These excerpts compare the historical AKS Dashboard add-on only. Current AKS does not support this add-on; do not add it to a new cluster configuration.

Before

bicep
resource aksCluster 'Microsoft.ContainerService/managedClusters@2020-02-01' = {
  name: 'aksCluster'
  location: resourceGroup().location
  properties: {
    addonProfiles: {
      kubeDashboard: {
        enabled: true
      }
    }
    dnsPrefix: 'team-aks'
  }
}

The historical add-on is enabled. Actual reachability depends on networking and authentication.

After

bicep
resource aksCluster 'Microsoft.ContainerService/managedClusters@2020-02-01' = {
  name: 'aksCluster'
  location: resourceGroup().location
  properties: {
    addonProfiles: {
      kubeDashboard: {
        enabled: false
      }
    }
    dnsPrefix: 'team-aks'
  }
}

The historical add-on is disabled. This does not remove a separately installed management UI.

References