Review AKS API server access scope

Restrict public API server access to the required management networks.

Description

Without authorized IP ranges on a public AKS API server, unnecessary networks can attempt connections. The control plane is a critical cluster management interface, so access should be limited to approved management paths. Network access still requires separate authentication and RBAC permissions.

Potential impact

  • The management endpoint can receive scans and access attempts from a wider range of sources.
  • More connection paths may be available for abusing stolen credentials or incorrect permissions.

Remediation

  • For a public API server, use apiServerAccessProfile.authorizedIPRanges to allow actual management client and required cluster egress public IP ranges. Check operational and automation paths before changing them.
  • This feature does not apply to private clusters; manage their private connectivity separately. Test that required management access works and access from other sources is blocked.

Examples

These excerpts compare historical API formats; Kubernetes 1.15.7 is not a version for current deployment. Use a supported version and supply the omitted cluster configuration before applying them. Replace the documentation CIDRs with actual management and egress public ranges.

Before

bicep
resource aksCluster 'Microsoft.ContainerService/managedClusters@2017-08-31' = {
  name: 'aksCluster'
  location: resourceGroup().location
  properties: {
    dnsPrefix: 'team-aks'
    kubernetesVersion: '1.15.7'
  }
}

No authorized IP ranges are specified. Also check the actual cluster’s public or private mode.

After

bicep
resource aksCluster 'Microsoft.ContainerService/managedClusters@2020-02-01' = {
  name: 'aksCluster'
  location: resourceGroup().location
  properties: {
    dnsPrefix: 'team-aks'
    kubernetesVersion: '1.15.7'
    apiServerAccessProfile: {
      authorizedIPRanges: [
        '203.0.113.10/32'
        '198.51.100.0/24'
      ]
    }
  }
}

Authorized ranges are specified for the public API server. Using the illustrative addresses unchanged may block required operational access.

References