Description
The AKS control plane is a management interface for the entire cluster. Broad access to a public API endpoint can increase external connection attempts. A public endpoint does not mean unauthenticated access, and a private cluster still needs authentication and least privilege.
Potential impact
- The cluster API can become a target for external scans and attack attempts.
- Incorrect access changes can interrupt management tools and deployments.
Remediation
- For clusters that need only internal access, consider
private_cluster_enabled = trueand configure management-network routing and DNS first. Test the required connectivity, such as VPN or ExpressRoute. - If a public API is needed, restrict authorized IP ranges and retain authentication and RBAC. Check the Terraform plan for cluster replacement and prepare workload and management-path migration.
Examples
These excerpts compare API exposure only; other required configuration, including node pools and identity, is omitted. Prepare private connectivity and DNS before applying changes to an existing cluster.
Before
hcl
resource "azurerm_kubernetes_cluster" "example" {
name = "example-aks1"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
dns_prefix = "exampleaks1"
private_cluster_enabled = false
}
After
hcl
resource "azurerm_kubernetes_cluster" "example" {
name = "example-aks1"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
dns_prefix = "exampleaks1"
private_cluster_enabled = true
}
Explanation:
- Before: The cluster is not private. Check actual public-API restrictions and authentication separately.
- After: Private API-server access is used. This does not make application LoadBalancers or Ingress private.