Review AKS audit log collection

Collect the Kubernetes API audit events needed for investigations and verify receipt and retention.

Description

Audit logs provide evidence for permission changes, resource modifications and unusual API calls. kube-audit collects API audit events, while kube-audit-admin excludes get and list events. Without records of the required operations, incident reconstruction can be difficult.

Potential impact

  • It can be harder to establish who performed Kubernetes API operations after an incident.
  • Responses to permission abuse or suspicious control-plane activity can be delayed.

Remediation

  • In an azurerm_monitor_diagnostic_setting targeting the AKS cluster, select kube-audit or kube-audit-admin through enabled_log according to investigation needs. Consider the exclusions when read operations must also be recorded.
  • Send logs to an approved destination such as Log Analytics and verify receipt, retention and access permissions. Collection alone does not create alerts; configure the required detection and response as well.

Examples

These are partial AKS and diagnostic configurations. Prepare omitted resources, including node pools, identity and the logging destination, separately.

Before

hcl
resource "azurerm_kubernetes_cluster" "example" {
  name                = "example-aks"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  dns_prefix          = "exampleaks"
}

resource "azurerm_monitor_diagnostic_setting" "example" {
  name                       = "aks-diagnostics"
  target_resource_id         = azurerm_kubernetes_cluster.example.id
  log_analytics_workspace_id = azurerm_log_analytics_workspace.example.id

  enabled_log {
    category = "kube-apiserver"
  }
}

After

hcl
resource "azurerm_kubernetes_cluster" "example" {
  name                = "example-aks"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  dns_prefix          = "exampleaks"
}

resource "azurerm_monitor_diagnostic_setting" "example" {
  name                       = "aks-diagnostics"
  target_resource_id         = azurerm_kubernetes_cluster.example.id
  log_analytics_workspace_id = azurerm_log_analytics_workspace.example.id

  enabled_log {
    category = "kube-audit"
  }
}

Explanation:

  • Before: API-server operational logs are selected. Check whether another diagnostic setting collects the required audit categories.
  • After: The kube-audit category sends API audit events to the selected logging destination.

References