Description
Without authorized IP ranges on a public AKS API server, unnecessary networks can attempt connections. The control plane is a critical cluster management interface, so access should be limited to approved management paths. Network access still requires separate authentication and RBAC permissions.
Potential impact
- The management endpoint can receive scans and access attempts from a wider range of sources.
- More connection paths may be available for abusing stolen credentials or incorrect permissions.
Remediation
- For a public API server, use apiServerAccessProfile.authorizedIPRanges to allow actual management client and required cluster egress public IP ranges. Check operational and automation paths before changing them.
- This feature does not apply to private clusters; manage their private connectivity separately. Test that required management access works and access from other sources is blocked.
Examples
These excerpts compare historical API formats; Kubernetes 1.15.7 is not a version for current deployment. Use a supported version and supply the omitted cluster configuration before applying them. Replace the documentation CIDRs with actual management and egress public ranges.
Before
resource aksCluster 'Microsoft.ContainerService/managedClusters@2017-08-31' = {
name: 'aksCluster'
location: resourceGroup().location
properties: {
dnsPrefix: 'team-aks'
kubernetesVersion: '1.15.7'
}
}
No authorized IP ranges are specified. Also check the actual cluster’s public or private mode.
After
resource aksCluster 'Microsoft.ContainerService/managedClusters@2020-02-01' = {
name: 'aksCluster'
location: resourceGroup().location
properties: {
dnsPrefix: 'team-aks'
kubernetesVersion: '1.15.7'
apiServerAccessProfile: {
authorizedIPRanges: [
'203.0.113.10/32'
'198.51.100.0/24'
]
}
}
}
Authorized ranges are specified for the public API server. Using the illustrative addresses unchanged may block required operational access.