Description
The Azure Policy add-on applies assigned policies to AKS workloads. Enabling the add-on does not block every policy violation; behavior depends on assignments, effects and exemptions. An audit effect records violations without blocking deployment.
Potential impact
- Required controls may not be enforced, allowing configurations outside organizational standards.
- Assuming audit results mean deployments were blocked can lead to incorrect operational decisions.
Remediation
- For clusters using Azure Policy, set the current AzureRM
azure_policy_enabled = trueand assign the required policies. If another policy engine is used, verify that it satisfies the same requirements. - Review audit or deny effects and exemptions, then test legitimate deployments and prohibited configurations. Check impacts on existing workloads before rollout.
Examples
These excerpts compare the add-on in the historical AzureRM 2.x addon_profile format. Current AzureRM uses azure_policy_enabled instead; omitted required settings such as node pools and identity must also be supplied.
Before
hcl
resource "azurerm_kubernetes_cluster" "example" {
name = "example-aks1"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
dns_prefix = "exampleaks1"
addon_profile {
azure_policy {
enabled = false
}
}
}
After
hcl
resource "azurerm_kubernetes_cluster" "example" {
name = "example-aks1"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
dns_prefix = "exampleaks1"
addon_profile {
azure_policy {
enabled = true
}
}
}
Explanation:
- Before: The Azure Policy add-on is disabled.
- After: The add-on is enabled. Separate policy assignments and effects determine what is checked or blocked.