本文將教你如何利用 API 伺服器授權的 IP 位址範圍,限制哪些 IP 位址和 CIDR 可以存取 Azure Kubernetes Service(AKS)工作負載的控制平面端點。
先決條件
- Azure CLI 版本 2.0.76 或更後版本。 若要檢查您的版本,請執行
az --version。 如果您需要安裝或升級,請參閱安裝 Azure CLI。 - 最新版本的 Azure PowerShell。 安裝說明請參見 Install Azure PowerShell。
- 想了解在整合 AKS 叢集與 Azure DevOps 時應包含哪些 IP 位址,請參閱 允許的 IP 位址與網域 URL。
小提示
在Azure入口網站,使用Azure Copilot更改可存取叢集的 IP 位址。 欲了解更多資訊,請參閱「 使用 Azure Copilot 高效地處理 AKS 叢集」。
限制與考量
- AKS 僅支援標準 SKU 負載平衡器。 AKS 不再支援 Basic SKU 負載平衡器。 如果你已有使用基本 SKU 的叢集,請 遷移到 Standard SKU。 遷移需要停機時間,並有額外的前提條件。
- 你無法在 私有叢集中使用這個功能。
- 對於使用 Node 公有 IP 的叢集,每個擁有公有 IP 的節點池必須使用公有 IP 前綴。 把這些前綴加為授權範圍。
- 你可以指定最多 200 個授權 IP 範圍。 若想突破此限制,建議使用 API Server VNet Integration,支援最多 2,000 個授權 IP 範圍。
API 伺服器授權 IP 範圍的概觀
Kubernetes API 伺服器會暴露底層的 Kubernetes API。 管理工具 kubectl 如 Kubernetes 儀表板透過此 API 伺服器與叢集互動。 AKS 提供單一租戶控制平面,配備專用 API 伺服器,並預設指派公用 IP 位址給該伺服器。 你可以使用 Kubernetes 角色基礎存取控制(Kubernetes RBAC)或 Azure RBAC 來控制存取。
為了保護原本可公開存取的 AKS 控制平面 API 伺服器,請啟用授權的 IP 範圍。 授權的 IP 範圍只允許定義的 IP 位址範圍與 API 伺服器通訊。 API 伺服器會阻擋來自未包含在授權範圍內的 IP 位址的請求。 這些規則最多可能需要兩分鐘才能傳播。 等兩分鐘後再測試連線。
建議允許的 IP 範圍
我們建議在您的 API 伺服器授權 IP 範圍配置中包含以下 IP 位址範圍:
- 叢集輸出 IP 位址 (防火牆、NAT 閘道或其他位址,取決於輸出類型)。
- IP 位址是你用來管理叢集的網路範圍。
建立已啟用 API 伺服器授權 IP 範圍的 AKS 叢集
附註
當你在叢集建立時啟用 API 伺服器授權 IP 範圍,AKS 會預設將 API 伺服器的公共 IP 和 標準 SKU 負載平衡器的 外站公共 IP 加入授權 IP 範圍清單,此外還有你指定的範圍。
特殊情況 - 0.0.0.0/32: 0.0.0.0/32 佔位符指示 AKS 只允許標準 SKU 負載平衡器的外出公共 IP 存取 API 伺服器。 佔位符具有以下行為:
| 行為 | Description |
|---|---|
| 額外的用戶端 IP 範圍 | 關閉預設允許額外用戶端 IP 範圍的行為。 |
| API 伺服器存取 | 限制 API 伺服器存取權限,僅限叢集自身的外站 IP。 |
| 自我管理 | 讓叢集自我管理,同時阻擋外部存取。 |
要建立啟用 API 伺服器授權 IP 範圍的叢集,請提供授權的公共 IP 位址範圍清單。 對於 CIDR 範圍,請使用網路位址,也就是該範圍內的第一個 IP 位址。 例如,若要允許範圍 137.117.106.88 為 137.117.106.95,指定 137.117.106.88/29。
使用 az aks create 帶有 --api-server-authorized-ip-ranges 參數的指令建立一個啟用 API 伺服器授權 IP 範圍的 AKS 叢集。 以下範例在資源群組 myResourceGroup 中建立一個名為 myAKSCluster 的叢集,並允許 IP 位址範圍73.140.245.0/24存取 API 伺服器:
az aks create --resource-group myResourceGroup --name myAKSCluster --vm-set-type VirtualMachineScaleSets --load-balancer-sku standard --api-server-authorized-ip-ranges 73.140.245.0/24 --generate-ssh-keys
使用 New-AzAksCluster 帶有參數 -ApiServerAccessAuthorizedIpRange 的 cmdlet 建立一個啟用 API 伺服器授權 IP 範圍的 AKS 叢集。 以下範例在資源群組 myResourceGroup 中建立一個名為 myAKSCluster 的叢集,並允許 IP 位址範圍73.140.245.0/24存取 API 伺服器:
New-AzAksCluster -ResourceGroupName myResourceGroup -Name myAKSCluster -NodeVmSetType VirtualMachineScaleSets -LoadBalancerSku Standard -ApiServerAccessAuthorizedIpRange '73.140.245.0/24' -GenerateSshKey
- 從 Azure 入口網站首頁,選取 [建立資源]> [容器]> [Azure Kubernetes Service (AKS)]。
- 視需要設定叢集設定。
- 在 [公用存取] 底下的 [網路] 區段中,選取 [設定授權 IP 範圍]。
- 針對 [指定 IP 範圍],請輸入您想要授權存取 API 伺服器的 IP 位址範圍。
- 視需要設定其餘叢集設定。
- 當您準備好時,選取 [檢閱 + 建立]> [建立] 以建立叢集。
使用 Azure CLI 指定標準 SKU 負載平衡器的出站 IP
當你建立一個啟用 API 伺服器授權 IP 範圍的叢集時,你也可以透過 --load-balancer-outbound-ips or --load-balancer-outbound-ip-prefixes 參數來指定其出站 IP 位址或前綴。 AKS 除了參數中的 --api-server-authorized-ip-ranges IP 位址外,還允許使用這些 IP 位址。
使用該 --load-balancer-outbound-ips 參數建立一個啟用 API 伺服器授權 IP 範圍的 AKS 叢集,並指定標準 SKU 負載平衡器的出站 IP 位址。 以下範例在資源群組 myAKSCluster 中建立一個名為 myAKSCluster 的叢集,允許73.140.245.0/24存取 API 伺服器,並為標準 SKU 負載平衡器指定兩個外站 IP 位址。 用你公共 IP 位址的資源 ID 替換 <public-ip-id-1> 和 <public-ip-id-2> 。
az aks create --resource-group myResourceGroup --name myAKSCluster --vm-set-type VirtualMachineScaleSets --load-balancer-sku standard --api-server-authorized-ip-ranges 73.140.245.0/24 --load-balancer-outbound-ips <public-ip-id-1>,<public-ip-id-2> --generate-ssh-keys
只允許標準 SKU 負載平衡器的輸出公用 IP
利用該 --api-server-authorized-ip-ranges 參數建立一個 AKS 叢集,只允許標準 SKU 負載平衡器的外出公共 IP 存取 API 伺服器。 以下範例在資源群組 myAKSCluster 中建立一個名為 myAKSCluster 的叢集:
az aks create --resource-group myResourceGroup --name myAKSCluster --vm-set-type VirtualMachineScaleSets --load-balancer-sku standard --api-server-authorized-ip-ranges 0.0.0.0/32 --generate-ssh-keys
利用該 -ApiServerAccessAuthorizedIpRange 參數建立一個 AKS 叢集,只允許標準 SKU 負載平衡器的外出公共 IP 存取 API 伺服器。 以下範例在資源群組 myAKSCluster 中建立一個名為 myAKSCluster 的叢集:
New-AzAksCluster -ResourceGroupName myResourceGroup -Name myAKSCluster -NodeVmSetType VirtualMachineScaleSets -LoadBalancerSku Standard -ApiServerAccessAuthorizedIpRange '0.0.0.0/32' -GenerateSshKey
- 從 Azure 入口網站首頁,選取 [建立資源]> [容器]> [Azure Kubernetes Service (AKS)]。
- 視需要設定叢集設定。
- 在 [公用存取] 底下的 [網路] 區段中,選取 [設定授權 IP 範圍]。
- 對於 指定 IP 範圍,請輸入
0.0.0.0/32。 此設定僅允許標準 SKU 負載平衡器的外行公有 IP。 - 視需要設定其餘叢集設定。
- 當您準備好時,選取 [檢閱 + 建立]> [建立] 以建立叢集。
更新現有叢集上 API 伺服器授權的 IP 範圍
使用 az aks update 帶有 --api-server-authorized-ip-ranges 參數的指令來更新叢集的 API 伺服器授權的 IP 範圍。 以下範例將資源群組 myAKSCluster 的授權範圍設為 :73.140.245.0/24
az aks update --resource-group myResourceGroup --name myAKSCluster --api-server-authorized-ip-ranges 73.140.245.0/24
允許使用 Azure CLI 進行多個 IP 位址範圍
要允許多個 IP 位址範圍,請用逗號分隔它們。
使用 az aks update 帶有 --api-server-authorized-ip-ranges 參數的指令授權多個 IP 位址範圍。 以下範例更新了資源群組 myAKSCluster 中名為 myAKSCluster 的叢集:
az aks update --resource-group myResourceGroup --name myAKSCluster --api-server-authorized-ip-ranges 73.140.245.0/24,193.168.1.0/24,194.168.1.0/24
使用 Set-AzAksCluster 帶有參數 -ApiServerAccessAuthorizedIpRange 的 cmdlet 來更新叢集的 API 伺服器授權的 IP 範圍。 以下範例將資源群組 myAKSCluster 的授權範圍設為 :73.140.245.0/24
Set-AzAksCluster -ResourceGroupName myResourceGroup -Name myAKSCluster -ApiServerAccessAuthorizedIpRange '73.140.245.0/24'
- 瀏覽至 Azure 入口網站,並選取您想要更新的 AKS 叢集。
- 從服務功能表的 [設定] 底下,選取 [網路]。
- 在 [資源設定] 下,選取 [管理]。
- 在 [授權 IP 範圍] 頁面上,視需要更新授權 IP 範圍。
- 完成時,選取 [儲存]。
在現有叢集上停用 API 伺服器授權的 IP 範圍
要停用 API 伺服器授權的 IP 範圍,請使用指令az aks update並為參數指定空範圍""--api-server-authorized-ip-ranges。
az aks update --resource-group myResourceGroup --name myAKSCluster --api-server-authorized-ip-ranges ""
要停用 API 伺服器授權的 IP 範圍,請使用 Set-AzAksCluster cmdlet 並為參數指定一個空範圍''-ApiServerAccessAuthorizedIpRange。
Set-AzAksCluster -ResourceGroupName myResourceGroup -Name myAKSCluster -ApiServerAccessAuthorizedIpRange ''
- 瀏覽至 Azure 入口網站,並選取您想要更新的 AKS 叢集。
- 從服務功能表的 [設定] 底下,選取 [網路]。
- 在 [資源設定] 下,選取 [管理]。
- 在 [授權 IP 範圍] 頁面上,取消選取 [設定授權 IP 範圍] 核取方塊。
- 選取儲存。
尋找現有的 API 伺服器授權 IP 範圍
要查找現有 API 伺服器授權的 IP 範圍,請使用 az aks show 將 --query 參數設為 apiServerAccessProfile.authorizedIpRanges的指令。
az aks show --resource-group myResourceGroup --name myAKSCluster --query apiServerAccessProfile.authorizedIpRanges
輸出範例:
[
"73.140.245.0/24"
]
要查找現有 API 伺服器授權的 IP 範圍,請使用 Get-AzAksCluster cmdlet。
Get-AzAksCluster -ResourceGroupName myResourceGroup -Name myAKSCluster | Select-Object -ExpandProperty ApiServerAccessProfile
輸出範例:
AuthorizedIPRanges: {73.140.245.0/24}
...
瀏覽至 Azure 入口網站,並選取您的 AKS 叢集。
從服務功能表的 [設定] 底下,選取 [網路]。
網路頁面的資源設定區塊顯示目前已設定的授權 IP 範圍。
從您的開發機器、工具或自動化系統存取 API 伺服器
若要從開發機器、工具或自動化系統存取 API 伺服器,請將其公開 IP 位址加入叢集授權的 IP 範圍。
或者,在防火牆虛擬網路的另一個子網路中配置一個配備必要工具的跳板盒,並將防火牆的 IP 位址加入授權範圍。 如果 AKS 叢集子網路使用防火牆強制隧道,你可以將跳接盒放在 AKS 叢集子網路中。
附註
以下範例保留現有授權範圍,並新增另一個 IP 位址。 如果你省略了現有的 IP 位址,指令會把它替換成新的範圍。
執行以下指令取得你的 IP 位址並設定為環境變數:
# Retrieve your IP address CURRENT_IP=$(dig +short "myip.opendns.com" "@resolver1.opendns.com")使用
az aks update帶有--api-server-authorized-ip-ranges參數的指令,將你的 IP 位址加入授權範圍。 以下範例將您目前的 IP 位址加入名為 myAKSCluster 的叢集中資源群組 myResourceGroup 的現有範圍:az aks update --resource-group myResourceGroup --name myAKSCluster --api-server-authorized-ip-ranges $CURRENT_IP/32,73.140.245.0/24
執行以下指令取得你的 IP 位址並設定為環境變數:
# Retrieve your IP address $CURRENT_IP = (Invoke-RestMethod -Uri 'https://ipinfo.io/json').ip使用
Set-AzAksCluster帶有參數-ApiServerAccessAuthorizedIpRange的 cmdlet 將你的 IP 位址加入授權範圍。 以下範例將您目前的 IP 位址加入名為 myAKSCluster 的叢集中資源群組 myResourceGroup 的現有範圍:Set-AzAksCluster -ResourceGroupName myResourceGroup -Name myAKSCluster -ApiServerAccessAuthorizedIpRange "$CURRENT_IP/32", '73.140.245.0/24'
想用另一種方式來識別你的 IP 位址,請參考 「尋找你的 IP 位址 」或搜尋「 我的 IP 位址是什麼?」 在網頁瀏覽器中。
相關內容
欲了解更多關於 AKS 安全資訊,請參閱以下文章: