Description
Kubernetes Dashboard is a useful management UI, but its authentication, permissions and exposure need management. Enabling it does not necessarily expose it to the internet. Remove an unnecessary UI to reduce management interfaces.
Potential impact
- Weak authentication or permissions can expose cluster information and management operations to unintended users.
- Unnecessary interfaces increase the configuration that must be maintained and reviewed.
Remediation
- Check the Dashboard actually in use and its dependencies, then remove it if unnecessary. Perform required management through approved paths protected by RBAC.
- If Dashboard is required, restrict its access path and apply authentication and least privilege. Manage separately installed UIs through their own deployment settings.
Examples
These excerpts compare a historical AKS Dashboard add-on setting. Current AzureRM does not support this addon_profile.kube_dashboard block; do not add it to new configurations.
Before
hcl
resource "azurerm_kubernetes_cluster" "example" {
name = "example-aks1"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
dns_prefix = "exampleaks1"
addon_profile {
kube_dashboard {
enabled = true
}
}
}
After
hcl
resource "azurerm_kubernetes_cluster" "example" {
name = "example-aks1"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
dns_prefix = "exampleaks1"
addon_profile {
kube_dashboard {
enabled = false
}
}
}
Explanation:
- Before: The historical Dashboard add-on is enabled. Actual reachability and authentication depend on separate settings.
- After: The historical add-on is disabled. This does not remove independently installed management UIs.