Azure / AKS

Azure Kubernetes Service
https://azure.github.io/AKS/
1.95k stars 304 forks source link

[Feature Request] Support for Service Tags in AKS API Server Authorization #1855

Open dhananjaya94 opened 3 years ago

dhananjaya94 commented 3 years ago

This request is to support Azure Service Tags in AKS API Server Authorization.

ghost commented 3 years ago

Hi dhananjaya-senanayake, AKS bot here :wave: Thank you for posting on the AKS Repo, I'll do my best to get a kind human from the AKS team to assist you.

I might be just a bot, but I'm told my suggestions are normally quite good, as such: 1) If this case is urgent, please open a Support Request so that our 24/7 support team may help you faster. 2) Please abide by the AKS repo Guidelines and Code of Conduct. 3) If you're having an issue, could it be described on the AKS Troubleshooting guides or AKS Diagnostics? 4) Make sure your subscribed to the AKS Release Notes to keep up to date with all that's new on AKS. 5) Make sure there isn't a duplicate of this issue already reported. If there is, feel free to close this one and '+1' the existing issue. 6) If you have a question, do take a look at our AKS FAQ. We place the most common ones there!

palma21 commented 3 years ago

@aanandr @jluk

ghost commented 3 years ago

Action required from @Azure/aks-pm

ghost commented 3 years ago

Issue needing attention of @Azure/aks-leads

ghost commented 3 years ago

Issue needing attention of @Azure/aks-leads

ghost commented 3 years ago

Issue needing attention of @Azure/aks-leads

ghost commented 3 years ago

Issue needing attention of @Azure/aks-leads

ghost commented 3 years ago

Issue needing attention of @Azure/aks-leads

ghost commented 3 years ago

Issue needing attention of @Azure/aks-leads

ghost commented 3 years ago

Issue needing attention of @Azure/aks-leads

ghost commented 2 years ago

Action required from @Azure/aks-pm

ghost commented 2 years ago

Issue needing attention of @Azure/aks-leads

ghost commented 2 years ago

Issue needing attention of @Azure/aks-leads

fillip1983 commented 2 years ago

This issue has been live for 18 months now and it doesn't seem like anything has been done to even start looking at the issue. The only workarounds for this are:

miwithro commented 2 years ago

@qpetraroia to look into to.

ericsuhong commented 10 months ago

@miwithro @qpetraroia Any update on this feature request?

Our pain point: We had a requirement to lock down our cluster from public. Because service tags are not supported at the control plane, the only choice we had was to use private AKS cluster with a proxy bastion solution (with NSG to use service tags to block traffic).

If service tags were supported for a public AKS cluster, we could have removed all these additional hassle and simply whitelist using service tags instead.

rsgel commented 1 month ago

Checking in on this feature request as well -- any updates? Several Azure Chaos Studio customers have asked about this functionality so they can more easily allowlist Chaos Studio IPs within their cluster.

rseso commented 1 month ago

Doubling on what Rigel commented above. Not being able to use service tags is heavily impacting the adoption of the Azure Chaos Studio. Please prioritize this asap.