Description
RBAC controls who can view and change Kubernetes resources. Disabling it makes fine-grained separation of user and service-account permissions difficult. Enabling the feature and configuring actual roles and bindings must be reviewed together.
Potential impact
- Users and service accounts can receive more access than their tasks require.
- Least privilege by namespace and resource can be harder to enforce.
Remediation
- Enable
role_based_access_control_enabled = trueor the RBAC setting supported by the version in use. For existing clusters, review Terraform replacement plans and operational impacts. - Minimize user, group and service-account roles according to the selected Kubernetes RBAC or Azure RBAC for AKS model. Remove unnecessary administrator bindings and test allowed and denied operations.
Examples
The examples compare RBAC and specify the Azure CNI plugin required by the network profile. Supply the resource group and remaining deployment configuration separately.
Before
hcl
resource "azurerm_kubernetes_cluster" "example" {
name = "example-aks1"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
dns_prefix = "exampleaks1"
role_based_access_control_enabled = false
default_node_pool {
name = "default"
node_count = 1
vm_size = "Standard_D2_v2"
}
identity {
type = "SystemAssigned"
}
tags = {
Environment = "Production"
}
network_profile {
network_plugin = "azure"
network_policy = "azure"
}
}
After
hcl
resource "azurerm_kubernetes_cluster" "example" {
name = "example-aks1"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
dns_prefix = "exampleaks1"
role_based_access_control_enabled = true
default_node_pool {
name = "default"
node_count = 1
vm_size = "Standard_D2_v2"
}
identity {
type = "SystemAssigned"
}
tags = {
Environment = "Production"
}
network_profile {
network_plugin = "azure"
network_policy = "azure"
}
}
Explanation:
- Before: Kubernetes RBAC is disabled.
- After: Kubernetes RBAC is enabled. Existing excessive roles or bindings are not automatically removed.