AKS cluster should be a private cluster
High
Azure
General
aks-aks-cluster-private-cluster
Applies to
Microsoft.ContainerService/managedClusters
What CGPulse checks
A resource passes this rule when apiServerAccessProfile.enablePrivateCluster must equal true. Anything else is reported as a finding with the evaluated property value attached as evidence.
How to fix it
Enable private cluster to restrict API server access to the VNet, preventing unauthorized internet exposure. Set private cluster at creation time. See: https://learn.microsoft.com/en-us/azure/aks/private-clusters
CLI
az aks show --ids "{id}" --query "apiServerAccessProfile.enablePrivateCluster" -o tsvBicep
// Note: Private cluster mode cannot be changed after creation. Create a new private clusterTerraform
resource "azurerm_kubernetes_cluster" "{name}" {
name = "{name}"
resource_group_name = "{rg}"
location = var.location
dns_prefix = "{name}"
private_cluster_enabled = true
default_node_pool {
name = "default"
node_count = 1
vm_size = "Standard_D2s_v5"
}
identity { type = "SystemAssigned" }
}
Compliance frameworks
Is your environment compliant with this rule?
CGPulse checks it — and 621 others — against your Azure and AWS accounts with read-only access.
Related Azure rules
- Action Group should be enabled
- Activity Log Alert should be enabled
- AKS cluster logs should be sent to Log Analytics
- AKS cluster must enable RBAC
- AKS cluster must enable RBAC
- AKS cluster should disable local accounts
- AKS cluster should enable Azure RBAC for Kubernetes
- AKS cluster should have diagnostic settings configured