Ensuring the security of your Azure Kubernetes Service (AKS) cluster is crucial. In this video, we delve into the essential security features and best practices that AKS Automatic configures for you out-of-the-box. Discover how AKS Deployment Safeguards help enforce security standards and prevent non-compliant deployments. Learn about AKS Automatic for secure cluster access and various security measures like Microsoft Entra ID for login, Azure Linux for node security, disabling SSH, automated cluster upgrades, and more.
Documentation:
https://learn.microsoft.com/azure/aks/intro-aks-automatic
https://learn.microsoft.com/azure/aks/enable-authentication-microsoft-entra-id#disable-local-accounts
https://learn.microsoft.com/azure/aks/use-azure-linux
https://learn.microsoft.com/azure/aks/manage-ssh-node-access?tabs=node-shell
https://learn.microsoft.com/azure/aks/node-resource-group-lockdown
https://learn.microsoft.com/azure/aks/auto-upgrade-cluster?tabs=azure-cli
https://learn.microsoft.com/azure/aks/csi-secrets-store-driver
https://learn.microsoft.com/azure/aks/image-cleaner
https://learn.microsoft.com/azure/aks/workload-identity-overview?tabs=go
https://learn.microsoft.com/azure/aks/deployment-safeguards
0:00 Welcome
0:15 Overview of AKS cluster security
1:51 AKS cluster login with Microsoft Entra
3:45 Node security: Azure Linux
4:21 Node security: Disable SSH
5:07 Automated cluster upgrades
6:13 Node Resource Group Lockdown
7:20 AKS secrets store for Azure Key Vault
8:22 AKS Image Cleaner
10:02 AKS Workload Identity
11:24 Deployment Safeguards
14:18 Summary