AKS RBAC is disabled

Grant users and service accounts only the Kubernetes permissions they need.

Description

RBAC controls who can view and change Kubernetes resources. Disabling it makes fine-grained separation of user and service-account permissions difficult. Enabling the feature and configuring actual roles and bindings must be reviewed together.

Potential impact

  • Users and service accounts can receive more access than their tasks require.
  • Least privilege by namespace and resource can be harder to enforce.

Remediation

  • Enable role_based_access_control_enabled = true or the RBAC setting supported by the version in use. For existing clusters, review Terraform replacement plans and operational impacts.
  • Minimize user, group and service-account roles according to the selected Kubernetes RBAC or Azure RBAC for AKS model. Remove unnecessary administrator bindings and test allowed and denied operations.

Examples

The examples compare RBAC and specify the Azure CNI plugin required by the network profile. Supply the resource group and remaining deployment configuration separately.

Before

hcl
resource "azurerm_kubernetes_cluster" "example" {
  name                = "example-aks1"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  dns_prefix          = "exampleaks1"

  role_based_access_control_enabled = false

  default_node_pool {
    name       = "default"
    node_count = 1
    vm_size    = "Standard_D2_v2"
  }

  identity {
    type = "SystemAssigned"
  }

  tags = {
    Environment = "Production"
  }

  network_profile {
    network_plugin = "azure"
    network_policy = "azure"
  }
}

After

hcl
resource "azurerm_kubernetes_cluster" "example" {
  name                = "example-aks1"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  dns_prefix          = "exampleaks1"

  role_based_access_control_enabled = true

  default_node_pool {
    name       = "default"
    node_count = 1
    vm_size    = "Standard_D2_v2"
  }

  identity {
    type = "SystemAssigned"
  }

  tags = {
    Environment = "Production"
  }

  network_profile {
    network_plugin = "azure"
    network_policy = "azure"
  }
}

Explanation:

  • Before: Kubernetes RBAC is disabled.
  • After: Kubernetes RBAC is enabled. Existing excessive roles or bindings are not automatically removed.

References