Skip to content

AKS does not use Azure policies add-on

Description

Azure Policy Add-on for AKS extends Gatekeeper v3, an admission controller webhook for Open Policy Agent (OPA), to apply at-scale enforcements and safeguards on your clusters in a centralized, consistent manner.

Code Example

go
resource "azurerm_kubernetes_cluster" "example" {
                  ...
+                  addon_profile {
+                    azure_policy {
+                      enabled = true
                    }
                  }         
                }

Remediation

Terraform

  • Resource: azurerm_kubernetes_cluster
  • Arguments: addon_profile.azure_policy.enabled

Rule Details

FieldValue
IDIAC-0623
SeverityLOW
IaC TypeTerraform
FrameworksTerraform, TerraformPlan
Checkov IDCKV_AZURE_116

References