Review private access to the AKS API server

Prepare the management path first and restrict API access to the operators who need it.

Description

The AKS control plane is a management interface for the entire cluster. Broad access to a public API endpoint can increase external connection attempts. A public endpoint does not mean unauthenticated access, and a private cluster still needs authentication and least privilege.

Potential impact

  • The cluster API can become a target for external scans and attack attempts.
  • Incorrect access changes can interrupt management tools and deployments.

Remediation

  • For clusters that need only internal access, consider private_cluster_enabled = true and configure management-network routing and DNS first. Test the required connectivity, such as VPN or ExpressRoute.
  • If a public API is needed, restrict authorized IP ranges and retain authentication and RBAC. Check the Terraform plan for cluster replacement and prepare workload and management-path migration.

Examples

These excerpts compare API exposure only; other required configuration, including node pools and identity, is omitted. Prepare private connectivity and DNS before applying changes to an existing cluster.

Before

hcl
resource "azurerm_kubernetes_cluster" "example" {
  name                = "example-aks1"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  dns_prefix          = "exampleaks1"

  private_cluster_enabled = false
}

After

hcl
resource "azurerm_kubernetes_cluster" "example" {
  name                = "example-aks1"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  dns_prefix          = "exampleaks1"

  private_cluster_enabled = true
}

Explanation:

  • Before: The cluster is not private. Check actual public-API restrictions and authentication separately.
  • After: Private API-server access is used. This does not make application LoadBalancers or Ingress private.

References