Review Azure Policy configuration for AKS

Configure policy assignments and effects, then verify the required detection and blocking behavior.

Description

The Azure Policy add-on applies assigned policies to AKS workloads. Enabling the add-on does not block every policy violation; behavior depends on assignments, effects and exemptions. An audit effect records violations without blocking deployment.

Potential impact

  • Required controls may not be enforced, allowing configurations outside organizational standards.
  • Assuming audit results mean deployments were blocked can lead to incorrect operational decisions.

Remediation

  • For clusters using Azure Policy, set the current AzureRM azure_policy_enabled = true and assign the required policies. If another policy engine is used, verify that it satisfies the same requirements.
  • Review audit or deny effects and exemptions, then test legitimate deployments and prohibited configurations. Check impacts on existing workloads before rollout.

Examples

These excerpts compare the add-on in the historical AzureRM 2.x addon_profile format. Current AzureRM uses azure_policy_enabled instead; omitted required settings such as node pools and identity must also be supplied.

Before

hcl
resource "azurerm_kubernetes_cluster" "example" {
  name                = "example-aks1"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  dns_prefix          = "exampleaks1"

  addon_profile {
    azure_policy {
      enabled = false
    }
  }
}

After

hcl
resource "azurerm_kubernetes_cluster" "example" {
  name                = "example-aks1"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  dns_prefix          = "exampleaks1"

  addon_profile {
    azure_policy {
      enabled = true
    }
  }
}

Explanation:

  • Before: The Azure Policy add-on is disabled.
  • After: The add-on is enabled. Separate policy assignments and effects determine what is checked or blocked.

References