last sync: 2025-Jun-11 17:24:09 UTC

Append AKS API IP Restrictions

Community Policy definition

Source Repository Community-Policy GitHub
JSON Community-Policy GitHub
Deploy policy 0533f5f7-f3ac-4c10-9823-c5812a1476f9 (1.1.0) to Azure
Display name Append AKS API IP Restrictions
Id 0533f5f7-f3ac-4c10-9823-c5812a1476f9
Version 1.1.0
Details on versioning
Category Kubernetes
Microsoft Learn
Description This policy will restrict access to the AKS API server as documented here: https://docs.microsoft.com/en-us/azure/aks/api-server-authorized-ip-ranges
Mode Indexed
Type Custom Community
Effect Default
Append
Allowed
Append, Deny, Audit, Disabled
RBAC role(s) none
Rule aliases IF (2)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.ContainerService/managedClusters/apiServerAccessProfile.authorizedIPRanges Microsoft.ContainerService managedClusters properties.apiServerAuthorizedIPRanges False properties.apiServerAccessProfile.authorizedIPRanges False
Microsoft.ContainerService/managedClusters/apiServerAccessProfile.authorizedIPRanges[*] Microsoft.ContainerService managedClusters properties.apiServerAuthorizedIPRanges[*] False properties.apiServerAccessProfile.authorizedIPRanges[*] False
THEN-Details (1)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.ContainerService/managedClusters/apiServerAccessProfile.authorizedIPRanges Microsoft.ContainerService managedClusters properties.apiServerAuthorizedIPRanges False properties.apiServerAccessProfile.authorizedIPRanges False
Rule resource types IF (1)
Microsoft.ContainerService/managedClusters
JSON
EPAC
Deploy policy 0533f5f7-f3ac-4c10-9823-c5812a1476f9 (1.1.0) to Azure