Description
Audit logs provide evidence for permission changes, resource modifications and unusual API calls. kube-audit collects API audit events, while kube-audit-admin excludes get and list events. Without records of the required operations, incident reconstruction can be difficult.
Potential impact
- It can be harder to establish who performed Kubernetes API operations after an incident.
- Responses to permission abuse or suspicious control-plane activity can be delayed.
Remediation
- In an
azurerm_monitor_diagnostic_settingtargeting the AKS cluster, selectkube-auditorkube-audit-adminthroughenabled_logaccording to investigation needs. Consider the exclusions when read operations must also be recorded. - Send logs to an approved destination such as Log Analytics and verify receipt, retention and access permissions. Collection alone does not create alerts; configure the required detection and response as well.
Examples
These are partial AKS and diagnostic configurations. Prepare omitted resources, including node pools, identity and the logging destination, separately.
Before
hcl
resource "azurerm_kubernetes_cluster" "example" {
name = "example-aks"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
dns_prefix = "exampleaks"
}
resource "azurerm_monitor_diagnostic_setting" "example" {
name = "aks-diagnostics"
target_resource_id = azurerm_kubernetes_cluster.example.id
log_analytics_workspace_id = azurerm_log_analytics_workspace.example.id
enabled_log {
category = "kube-apiserver"
}
}
After
hcl
resource "azurerm_kubernetes_cluster" "example" {
name = "example-aks"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
dns_prefix = "exampleaks"
}
resource "azurerm_monitor_diagnostic_setting" "example" {
name = "aks-diagnostics"
target_resource_id = azurerm_kubernetes_cluster.example.id
log_analytics_workspace_id = azurerm_log_analytics_workspace.example.id
enabled_log {
category = "kube-audit"
}
}
Explanation:
- Before: API-server operational logs are selected. Check whether another diagnostic setting collects the required audit categories.
- After: The kube-audit category sends API audit events to the selected logging destination.