Description
AKS managed disks are encrypted with platform-managed keys by default. Omitting disk_encryption_set_id does not mean that disks are stored in plaintext. If the organization requires customer-managed keys, associate a Disk Encryption Set with supported disks.
Potential impact
- The configuration may not meet a customer-managed-key policy.
- Incorrect key permissions or availability changes can make disks and workloads unavailable.
Remediation
- When customer-managed keys are required, specify
disk_encryption_set_idand verify key permissions, availability and rotation procedures. Check support for the disk type and node pool. - Customer-managed encryption for OS disks must be configured when the cluster is created, so plan replacement and data/workload migration for existing environments. For Ephemeral OS disks, also check the applicable key-rotation procedure.
Examples
These excerpts compare the Disk Encryption Set association only. Supply omitted required configuration, including identity, keys and the Disk Encryption Set, separately.
Before
hcl
resource "azurerm_kubernetes_cluster" "example" {
name = "example-aks1"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
dns_prefix = "exampleaks1"
default_node_pool {
name = "default"
node_count = 1
vm_size = "Standard_D2_v2"
}
}
After
hcl
resource "azurerm_kubernetes_cluster" "example" {
name = "example-aks1"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
dns_prefix = "exampleaks1"
disk_encryption_set_id = azurerm_disk_encryption_set.example.id
default_node_pool {
name = "default"
node_count = 1
vm_size = "Standard_D2_v2"
}
}
Explanation:
- Before: No customer-managed key is selected. This is distinct from default encryption with platform-managed keys.
- After: A Disk Encryption Set is specified. Key access and a supported disk configuration are required.