Review customer-managed keys for AKS disks

Use supported disk encryption settings when the organization requires customer-managed keys.

Description

AKS managed disks are encrypted with platform-managed keys by default. Omitting disk_encryption_set_id does not mean that disks are stored in plaintext. If the organization requires customer-managed keys, associate a Disk Encryption Set with supported disks.

Potential impact

  • The configuration may not meet a customer-managed-key policy.
  • Incorrect key permissions or availability changes can make disks and workloads unavailable.

Remediation

  • When customer-managed keys are required, specify disk_encryption_set_id and verify key permissions, availability and rotation procedures. Check support for the disk type and node pool.
  • Customer-managed encryption for OS disks must be configured when the cluster is created, so plan replacement and data/workload migration for existing environments. For Ephemeral OS disks, also check the applicable key-rotation procedure.

Examples

These excerpts compare the Disk Encryption Set association only. Supply omitted required configuration, including identity, keys and the Disk Encryption Set, separately.

Before

hcl
resource "azurerm_kubernetes_cluster" "example" {
  name                = "example-aks1"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  dns_prefix          = "exampleaks1"

  default_node_pool {
    name       = "default"
    node_count = 1
    vm_size    = "Standard_D2_v2"
  }
}

After

hcl
resource "azurerm_kubernetes_cluster" "example" {
  name                   = "example-aks1"
  location               = azurerm_resource_group.example.location
  resource_group_name    = azurerm_resource_group.example.name
  dns_prefix             = "exampleaks1"
  disk_encryption_set_id = azurerm_disk_encryption_set.example.id

  default_node_pool {
    name       = "default"
    node_count = 1
    vm_size    = "Standard_D2_v2"
  }
}

Explanation:

  • Before: No customer-managed key is selected. This is distinct from default encryption with platform-managed keys.
  • After: A Disk Encryption Set is specified. Key access and a supported disk configuration are required.

References