聯邦資訊處理標準(FIPS)140-3 是美國政府的一項標準,定義了資訊科技產品與系統中密碼模組的最低安全要求。 Azure Kubernetes Service (AKS) 允許您在啟用 FIPS 140-3 的情況下建立 Linux 和 Windows 節點池。 在支援 FIPS 的節點池上運行的部署會使用這些加密模組,以提升安全性並協助符合 FedRAMP 合規的安全控管。 欲了解更多FIPS 140-3資訊,請參閱 聯邦資訊處理標準(FIPS)140。
重要事項
自 2027 年 3 月 17 日
重要事項
自 2025 年 11 月 30 日起,Azure Kubernetes Service (AKS) 將不再支援或提供 Azure Linux 2.0 的安全更新。 Azure Linux 2.0 節點映像已凍結在202512.06.0發行版本。 自 2026 年 10 月 31 日起,節點映像將被移除,且你將無法擴展你的節點池。 遷移到支援的 Azure Linux 版本時,可以升級你的節點池到 支援的 Kubernetes 版本,或遷移到 osSku AzureLinux3。 欲了解更多資訊,請參閱 退休GitHub議題 及 Azure 更新退休公告。 欲掌握最新公告與更新,請參考AKS發布說明。
先決條件
一個有效的 Azure 訂閱。 如果你沒有Azure訂閱,請在開始前建立一個free帳號。
請用指令
az account set設定你的訂閱上下文。 例如:az account set --subscription "00000000-0000-0000-0000-000000000000"Kubectl 已安裝。 您可以使用命令
az aks install-cli在本機安裝它。
- Terraform 本地安裝。 安裝說明請參見 Install Terraform。
版本相容性
- Azure CLI 版本 2.32.0 或更新版本已安裝並配置。 若要尋找版本,請執行
az --version。 欲了解更多安裝或升級Azure CLI的資訊,請參見 Install Azure CLI。
- 本文中的 ARM 範本範例使用 API 版本
2023-03-01,用於Microsoft.ContainerService/managedClusters和Microsoft.ContainerService/managedClusters/agentPools。
- 本文中的 Bicep 範例使用 API 版本
2023-03-01,適用於Microsoft.ContainerService/managedClusters和Microsoft.ContainerService/managedClusters/agentPools。
- 本文中的 Terraform 範例使用 AzureRM 提供者 3.x。
- 對於 Terraform FIPS 設定,請使用
enable_fips_image在azurerm_kubernetes_cluster.default_node_pool上,並將fips_enabled用於azurerm_kubernetes_cluster_node_pool。
限制
啟用 FIPS 的節點池有以下限制:
- 已啟用 FIPS 的節點集區需要 Kubernetes 1.19 版和更新版本。
- 啟用 FIPS 的 Trusted Launch 僅支援 Gen2 虛擬機器規格上的 Ubuntu 22.04。
- 要更新用於 FIPS 的底層套件或模組,必須使用 Node 映像升級。
- FIPS 節點上的容器映像不會進行 FIPS 合規性評估。
- 掛接 CIFS 共用失敗,因為 FIPS 會停用某些驗證模組。 若要解決此問題,請參閱在已啟用 FIPS 的節點集區上掛接檔案共用時發生錯誤。
- 支援 FIPS 的節點池,包含 Arm64 虛擬機,僅支援 Azure Linux 3.0+。
- AKS 監控外掛支援 FIPS 節點池,支援 Ubuntu、Azure Linux 及 Windows,從 Agent 版本 3.1.17(Linux)及 Win-3.1.17(Windows)開始。
重要事項
已啟用 FIPS 的 Linux 映像與用於 Linux 節點集區的預設 Linux 映像不同。
啟用 FIPS 的節點映像檔可能擁有不同的作業系統版本和核心版本,與未啟用 FIPS 的映像檔不同。 啟用 FIPS 的節點集區和節點映像的更新週期可能與未啟用 FIPS 的節點集區和映射不同。
支援的 OS 版本
你可以在所有支援的作業系統類型(Linux 和 Windows)上建立啟用 FIPS 的節點池。 不過,並非所有作系統版本都支援已啟用 FIPS 的節點集區。 發行新的 OS 版本之後,通常會有等候期間,才符合 FIPS 規範。
下表列出支援支援 FIPS 節點池的作業系統版本:
| OS 類型 | 作業系統 SKU | FIPS 合規性 | 預設值 |
|---|---|---|---|
| Linux | Ubuntu | 支援 Ubuntu 20.04 與 Ubuntu 22.04 | 預設為停用 |
| Linux | Azure Linux | 支援 Azure Linux 3.0 | 預設為停用 |
| Windows | Windows Server 2022 | 支援 | 預設啟用 |
| Windows | Windows Server 2025 | 支援 | 預設啟用,無法關閉 |
當請求啟用 FIPS 的 Ubuntu 時,如果預設的 Ubuntu 版本不支援 FIPS,AKS 會預設使用最新支援 FIPS 的 Ubuntu。 例如,Ubuntu 24.04 是 Linux 節點池的預設版本。 由於 Ubuntu 24.04 目前不支援 FIPS,AKS 預設使用 Ubuntu 22.04 來支援 Linux FIPS 的節點池。
附註
過去,你可以用 GetOSOptions API 判斷某個作業系統是否支援 FIPS。 該 GetOSOptions API 現已棄用,並自 2024-05-01 起不再包含在新的 AKS API 版本中。
建立 Terraform 設定檔
Terraform 設定檔定義了 Terraform 所建立和管理的基礎架構。
建立一個名為
main.tf的檔案,並加入以下程式碼來定義 Terraform 版本並指定Azure提供者:terraform { required_version = ">= 1.0" required_providers { azurerm = { source = "hashicorp/azurerm" version = "~> 3.0" } } } provider "azurerm" { features {} }將以下程式碼加入
main.tf以建立Azure資源群組。 如有需要,歡迎更改資源群組的名稱和地點。resource "azurerm_resource_group" "example" { name = "example-fips-rg" location = "East US" }
建立一個啟用 FIPS 預設節點池的 AKS 叢集
你可以在建立新的 AKS 叢集時,在預設節點池啟用 FIPS。
當在已有 FIPS 預設節點池的叢集上建立更多節點池時,你也必須使用 --enable-fips-image 參數在新節點池上啟用 FIPS。
在預設節點池上使用
az aks create指令和其帶有的--enable-fips-image參數建立一個啟用 FIPS 的 AKS 叢集。az aks create \ --resource-group myResourceGroup \ --name myAKSCluster \ --node-count 3 \ --enable-fips-image請使用
az aks show指令,在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池是否啟用了 FIPS。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table以下範例輸出顯示預設節點池已啟用 FIPS:
Name enableFips --------- ------------ nodepool1 True
目前在 Azure portal
當在具有已啟用 FIPS 的預設節點池的叢集上建立更多節點池時,你必須透過將enableFips 設定為true,來啟用新的節點池上的 FIPS。
在預設節點池中,使用 ARM 範本設定代理池設定檔中的
enableFips屬性為true,以建立啟用 FIPS 的 AKS 叢集。 例如:{ "type": "Microsoft.ContainerService/managedClusters", "location": "[parameters('location')]", "name": "[parameters('clusterName')]", "properties": { "kubernetesVersion": "1.27", "enableRBAC": true, "dnsPrefix": "[parameters('dnsPrefix')]", "agentPoolProfiles": [ { "name": "nodepool1", "count": 3, "vmSize": "Standard_D2s_v3", "osType": "Linux", "osSKU": "Ubuntu", "type": "VirtualMachineScaleSets", "mode": "System", "enableFips": true } ] }, "identity": { "type": "SystemAssigned" } }使用 Azure portal、Azure CLI 或 Azure PowerShell 部署 ARM 範本。 欲了解更多部署 ARM 範本的資訊,請參閱 「使用 ARM 範本部署資源」。
請使用
az aks show指令,在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池是否啟用了 FIPS。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table以下範例輸出顯示預設節點池已啟用 FIPS:
Name enableFips --------- ------------ nodepool1 True
當在具有已啟用 FIPS 的預設節點池的叢集上建立更多節點池時,你必須透過將enableFIPS 設定為true,來啟用新的節點池上的 FIPS。
使用 Bicep 建立啟用 FIPS 的 AKS 叢集於預設節點池,方法是在代理池設定檔中將
enableFIPS設定為true。 例如:param location string param clusterName string param dnsPrefix string resource aks 'Microsoft.ContainerService/managedClusters@2023-03-01' = { name: clusterName location: location identity: { type: 'SystemAssigned' } properties: { kubernetesVersion: '1.27' enableRBAC: true dnsPrefix: dnsPrefix agentPoolProfiles: [ { name: 'nodepool1' count: 3 vmSize: 'Standard_D2s_v3' osType: 'Linux' osSKU: 'Ubuntu' type: 'VirtualMachineScaleSets' mode: 'System' enableFIPS: true } ] } }請使用 Azure CLI、Azure PowerShell 或 Azure 入口部署 Bicep 檔案。 欲了解更多有關部署 Bicep 檔案的資訊,請參閱<使用 Visual Studio Code 建立 Bicep 檔案>。
請使用
az aks show指令,在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池是否啟用了 FIPS。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table以下範例輸出顯示預設節點池已啟用 FIPS:
Name enableFips --------- ------------ nodepool1 True
在已啟用 FIPS 預設節點集區的叢集上建立更多節點集區時,您也必須在新節點集區上啟用 FIPS,方法是在fips_enabled上將true設定為azurerm_kubernetes_cluster_node_pool。
在預設節點池中建立啟用 FIPS 的 AKS 叢集時,新增以下程式碼至
main.tf:resource "azurerm_kubernetes_cluster" "example" { name = "example-aks-cluster" location = azurerm_resource_group.example.location resource_group_name = azurerm_resource_group.example.name dns_prefix = "example-aks" default_node_pool { name = "nodepool1" node_count = 3 vm_size = "Standard_D2s_v3" os_sku = "Ubuntu" enable_fips_image = true } identity { type = "SystemAssigned" } }在包含你
main.tf檔案的目錄中,使用terraform init指令初始化 Terraform。terraform init使用
terraform plan命令建立 Terraform 執行計畫。terraform plan使用
terraform apply命令套用設定,部署具備 FIPS 預設節點池的叢集。terraform apply使用 [
az aks get-credentials][az-aks-get-credentials] 指令連接到 AKS 叢集。az aks get-credentials \ --resource-group myResourceGroup \ --name myAKSCluster請使用
az aks show指令,在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池是否啟用了 FIPS。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table以下範例輸出顯示預設節點池已啟用 FIPS:
Name enableFips --------- ------------ nodepool1 True
欲了解更多關於 azurerm_kubernetes_cluster 資源的資訊,請參閱 Terraform Azure 提供者文件。
在現有的 AKS 叢集中新增支援 FIPS 的 Linux 節點池
使用
az aks nodepool add帶有參數的--enable-fips-image指令,將支援 FIPS 的 Linux 節點池加入現有叢集。az aks nodepool add \ --resource-group myResourceGroup \ --cluster-name myAKSCluster \ --name fipsnp \ --enable-fips-image請使用
az aks show指令並在 agentPoolProfiles 查詢 enableFIPS 值來驗證你的節點池設定。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table下列範例輸出顯示 fipsnp 節點集區已啟用 FIPS:
Name enableFips --------- ------------ fipsnp True nodepool1 False使用
kubectl get nodes命令列出節點。kubectl get nodes下列範例輸出顯示叢集中的節點清單。 開頭為
aks-fipsnp的節點是已啟用 FIPS 節點集區的一部分。NAME STATUS ROLES AGE VERSION aks-fipsnp-12345678-vmss000000 Ready agent 6m4s v1.19.9 aks-fipsnp-12345678-vmss000001 Ready agent 5m21s v1.19.9 aks-fipsnp-12345678-vmss000002 Ready agent 6m8s v1.19.9 aks-nodepool1-12345678-vmss000000 Ready agent 34m v1.19.9在已啟用 FIPS 節點集區的其中一個節點上,使用
kubectl debug命令以透過互動式工作階段來執行部署。kubectl debug node/aks-fipsnp-12345678-vmss000000 -it --image=mcr.microsoft.com/dotnet/runtime-deps:6.0從互動式工作階段輸出來確認 FIPS 密碼編譯程式庫已啟用。 您的輸出看起來應該類似下列範例輸出:
root@aks-fipsnp-12345678-vmss000000:/# cat /proc/sys/crypto/fips_enabled 1已啟用 FIPS 的節點集區也有 kubernetes.azure.com/fips_enabled=true 標籤,部署可用這些節點集區設為目標。
目前在 Azure 入口網站中不支援新增 Linux 節點集區時啟用 FIPS。 要新增支援 FIPS 的 Linux 節點池,請使用本文中的 Azure CLI、ARM 範本、Bicep 或 Terraform 指示。
透過部署將
enableFips屬性設定為true的代理池資源,使用 ARM 範本建立支援 FIPS 的 Linux 節點池。 例如:{ "type": "Microsoft.ContainerService/managedClusters/agentPools", "apiVersion": "2023-03-01", "name": "[concat(parameters('clusterName'), '/fipsnp')]", "properties": { "count": 3, "vmSize": "Standard_D2s_v3", "osType": "Linux", "osSKU": "Ubuntu", "mode": "User", "enableFips": true } }使用 Azure portal、Azure CLI 或 Azure PowerShell 部署 ARM 範本。 欲了解更多部署 ARM 範本的資訊,請參閱 「使用 ARM 範本部署資源」。
請使用
az aks show指令並在 agentPoolProfiles 查詢 enableFIPS 值來驗證你的節點池設定。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table下列範例輸出顯示 fipsnp 節點集區已啟用 FIPS:
Name enableFips --------- ------------ fipsnp True nodepool1 False使用
kubectl get nodes命令列出節點。kubectl get nodes下列範例輸出顯示叢集中的節點清單。 開頭為
aks-fipsnp的節點是已啟用 FIPS 節點集區的一部分。NAME STATUS ROLES AGE VERSION aks-fipsnp-12345678-vmss000000 Ready agent 6m4s v1.19.9 aks-fipsnp-12345678-vmss000001 Ready agent 5m21s v1.19.9 aks-fipsnp-12345678-vmss000002 Ready agent 6m8s v1.19.9 aks-nodepool1-12345678-vmss000000 Ready agent 34m v1.19.9在已啟用 FIPS 節點集區的其中一個節點上,使用
kubectl debug命令以透過互動式工作階段來執行部署。kubectl debug node/aks-fipsnp-12345678-vmss000000 -it --image=mcr.microsoft.com/dotnet/runtime-deps:6.0從互動式工作階段輸出來確認 FIPS 密碼編譯程式庫已啟用。 您的輸出看起來應該類似下列範例輸出:
root@aks-fipsnp-12345678-vmss000000:/# cat /proc/sys/crypto/fips_enabled 1已啟用 FIPS 的節點集區也有 kubernetes.azure.com/fips_enabled=true 標籤,部署可用這些節點集區設為目標。
透過部署代理池資源,將
enableFIPS設為true,使用 Bicep 建立支援 FIPS 的 Linux 節點池。 例如:param clusterName string param nodePoolName string = 'fipsnp' resource nodePool 'Microsoft.ContainerService/managedClusters/agentPools@2023-03-01' = { name: '${clusterName}/${nodePoolName}' properties: { count: 3 vmSize: 'Standard_D2s_v3' osType: 'Linux' osSKU: 'Ubuntu' mode: 'User' enableFIPS: true } }請使用 Azure CLI、Azure PowerShell 或 Azure 入口部署 Bicep 檔案。 欲了解更多有關部署 Bicep 檔案的資訊,請參閱<使用 Visual Studio Code 建立 Bicep 檔案>。
請使用
az aks show指令並在 agentPoolProfiles 查詢 enableFIPS 值來驗證你的節點池設定。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table下列範例輸出顯示 fipsnp 節點集區已啟用 FIPS:
Name enableFips --------- ------------ fipsnp True nodepool1 False使用
kubectl get nodes命令列出節點。kubectl get nodes下列範例輸出顯示叢集中的節點清單。 開頭為
aks-fipsnp的節點是已啟用 FIPS 節點集區的一部分。NAME STATUS ROLES AGE VERSION aks-fipsnp-12345678-vmss000000 Ready agent 6m4s v1.19.9 aks-fipsnp-12345678-vmss000001 Ready agent 5m21s v1.19.9 aks-fipsnp-12345678-vmss000002 Ready agent 6m8s v1.19.9 aks-nodepool1-12345678-vmss000000 Ready agent 34m v1.19.9在已啟用 FIPS 節點集區的其中一個節點上,使用
kubectl debug命令以透過互動式工作階段來執行部署。kubectl debug node/aks-fipsnp-12345678-vmss000000 -it --image=mcr.microsoft.com/dotnet/runtime-deps:6.0從互動式工作階段輸出來確認 FIPS 密碼編譯程式庫已啟用。 您的輸出看起來應該類似下列範例輸出:
root@aks-fipsnp-12345678-vmss000000:/# cat /proc/sys/crypto/fips_enabled 1已啟用 FIPS 的節點集區也有 kubernetes.azure.com/fips_enabled=true 標籤,部署可用這些節點集區設為目標。
新增以下程式碼,以便在
main.tf你的 AKS 叢集中加入支援 FIPS 的 Linux 節點池:resource "azurerm_kubernetes_cluster_node_pool" "fips_linux" { name = "fipsnp" kubernetes_cluster_id = azurerm_kubernetes_cluster.example.id vm_size = "Standard_D2s_v3" os_type = "Linux" os_sku = "Ubuntu" node_count = 3 fips_enabled = true node_taints = [] }請使用
terraform planandterraform apply指令套用更新後的 Terraform 設定。terraform plan terraform apply使用 [
az aks get-credentials][az-aks-get-credentials] 指令連接到 AKS 叢集。az aks get-credentials \ --resource-group myResourceGroup \ --name myAKSCluster請使用
az aks show指令並在 agentPoolProfiles 查詢 enableFIPS 值來驗證你的節點池設定。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table下列範例輸出顯示 fipsnp 節點集區已啟用 FIPS:
Name enableFips --------- ------------ fipsnp True nodepool1 False使用
kubectl get nodes命令列出節點。kubectl get nodes下列範例輸出顯示叢集中的節點清單。 開頭為
aks-fipsnp的節點是已啟用 FIPS 節點集區的一部分。NAME STATUS ROLES AGE VERSION aks-fipsnp-12345678-vmss000000 Ready agent 6m4s v1.19.9 aks-fipsnp-12345678-vmss000001 Ready agent 5m21s v1.19.9 aks-fipsnp-12345678-vmss000002 Ready agent 6m8s v1.19.9 aks-nodepool1-12345678-vmss000000 Ready agent 34m v1.19.9在已啟用 FIPS 節點集區的其中一個節點上,使用
kubectl debug命令以透過互動式工作階段來執行部署。kubectl debug node/aks-fipsnp-12345678-vmss000000 -it --image=mcr.microsoft.com/dotnet/runtime-deps:6.0從互動式工作階段輸出來確認 FIPS 密碼編譯程式庫已啟用。 您的輸出看起來應該類似下列範例輸出:
root@aks-fipsnp-12345678-vmss000000:/# cat /proc/sys/crypto/fips_enabled 1已啟用 FIPS 的節點集區也有 kubernetes.azure.com/fips_enabled=true 標籤,部署可用這些節點集區設為目標。
欲了解更多關於 azurerm_kubernetes_cluster_node_pool 資源的資訊,請參閱 Terraform Azure 提供者文件。
新增一個啟用 FIPS 和 Trusted Launch 的 Linux 節點池
FIPS 的 Trusted Launch 僅支援 Ubuntu 22.04 在第二代虛擬機容量上。
欲了解更多關於可信啟動需求與行為的資訊,請參閱 Azure Kubernetes Service (AKS) 的可信啟動。
透過指令
az aks nodepool add新增一個啟用 FIPS 與 Trusted Launch 的 Linux 節點池。az aks nodepool add \ --resource-group myResourceGroup \ --cluster-name myAKSCluster \ --name fipstlnp \ --os-type Linux \ --os-sku Ubuntu \ --node-count 3 \ --enable-fips-image \ --enable-vtpm \ --enable-secure-boot請使用
az aks show指令,並查詢 agentPoolProfiles 中的 enableFIPS 值,以確認您的節點集區設定。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table以下範例輸出顯示 FIPSTLNP 節點池已啟用 FIPS:
Name enableFips --------- ------------ fipstlnp True nodepool1 False確認節點池是否使用受信任啟動映像。
受信任的發射節點回傳以下輸出:
- 節點映像版本同時包含
"TL"和"FIPS"。 -
"Security-type"是"Trusted Launch"。
kubectl get nodes kubectl describe node {node-name} | grep -e node-image-version -e security-type- 節點映像版本同時包含
目前 Azure 入口網站不支援新增同時啟用 FIPS 和 Trusted Launch 的 Linux 節點集區。 若要新增啟用 FIPS 與 Trusted Launch 的 Linux 節點池,請使用 Azure CLI、Azure Resource Manager 範本(ARM 範本)或本文中的 Bicep 指示。
使用 ARM 範本建立一個啟用 FIPS 與 Trusted Launch 的 Linux 節點池。 部署一個代理程式集區資源,將
enableFips設為true,並將enableVTPM和enableSecureBoot都設為true。 例如:{ "type": "Microsoft.ContainerService/managedClusters/agentPools", "apiVersion": "2023-03-01", "name": "[concat(parameters('clusterName'), '/fipstlnp')]", "properties": { "count": 3, "vmSize": "Standard_D2s_v3", "osType": "Linux", "osSKU": "Ubuntu", "mode": "User", "enableFips": true, "securityProfile": { "enableVTPM": "true", "enableSecureBoot": "true" } } }你可以用 Azure portal、Azure CLI 或 Azure PowerShell 部署 ARM 模板。 欲了解更多部署 ARM 範本的資訊,請參閱 「使用 ARM 範本部署資源」。
請使用
az aks show指令,並查詢 agentPoolProfiles 中的 enableFIPS 值,以確認您的節點集區設定。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table驗證節點集區使用的是受信任的啟動映像。
受信任的啟動節點具有下列輸出:
- 節點映像版本同時包含
"TL"和"FIPS"。 -
"Security-type"是"Trusted Launch"。
kubectl get nodes kubectl describe node {node-name} | grep -e node-image-version -e security-type- 節點映像版本同時包含
使用 Bicep 建立一個啟用 FIPS 和 Trusted Launch 的 Linux 節點池。 部署一個代理程式集區資源,並將
enableFIPS、enableVTPM和enableSecureBoot設為true。 例如:param clusterName string param nodePoolName string = 'fipstlnp' resource nodePool 'Microsoft.ContainerService/managedClusters/agentPools@2023-03-01' = { name: '${clusterName}/${nodePoolName}' properties: { count: 3 vmSize: 'Standard_D2s_v3' osType: 'Linux' osSKU: 'Ubuntu' mode: 'User' enableFIPS: true securityProfile: { enableVTPM: true enableSecureBoot: true } } }請使用 Azure CLI、Azure PowerShell 或 Azure portal 來部署 Bicep 檔案。 欲了解更多有關部署 Bicep 檔案的資訊,請參閱<使用 Visual Studio Code 建立 Bicep 檔案>。
請使用
az aks show指令,並查詢 agentPoolProfiles 中的 enableFIPS 值,以確認您的節點集區設定。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table驗證節點集區使用的是受信任的啟動映像。
受信任的啟動節點具有下列輸出:
- 節點映像版本同時包含
"TL"和"FIPS"。 -
"Security-type"是"Trusted Launch"。
kubectl get nodes kubectl describe node {node-name} | grep -e node-image-version -e security-type- 節點映像版本同時包含
目前在 AzureRM 提供者中,使用 Terraform 新增同時啟用 FIPS 和 Trusted Launch 的 Linux 節點集區並不受支援,因為 AzureRM 提供者未公開 Trusted Launch 節點集區設定。
要新增啟用 FIPS 和可信啟動的 Linux 節點池,請使用本文中的 Azure CLI、ARM 範本或 Bicep 指示。
新增支援 FIPS 的 Windows 節點池
在本節中,我們將為現有的 AKS 叢集新增一個 Windows 節點池。
Windows Server 2022及後續節點池預設啟用FIPS,即使enableFips未顯示True。
Windows Server 2025 及以後的節點池不支援停用 FIPS。
使用
az aks nodepool add指令建立一個Windows節點池。 與基於 Linux 的節點池不同,Windows 節點池共用相同的映像集。az aks nodepool add \ --resource-group myResourceGroup \ --cluster-name myAKSCluster \ --name fipsnp \ --enable-fips-image \ --os-type Windows請使用
az aks show指令並在 agentPoolProfiles 查詢 enableFIPS 值來驗證你的節點池設定。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table透過
建立RDP連線到節點池中的Windows節點 並檢查登錄檔,驗證Windows節點池是否能存取FIPS密碼庫。 從 [執行] 應用程式中,輸入 regedit。在登錄中尋找
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\FIPSAlgorithmPolicy。如果
Enabled設為 1,則會啟用 FIPS。
已啟用 FIPS 的節點集區也有 kubernetes.azure.com/fips_enabled=true 標籤,部署可用這些節點集區設為目標。
Azure 入口網站沒有功能可以啟用或關閉 Windows 節點池的 FIPS 設定。 任何使用 Azure 入口網站建立的 Windows 節點池都啟用了 FIPS。 Windows Server 2022 及以後版本的節點池預設啟用 FIPS,而 Windows Server 2025 及以後版本的節點池則不支援停用 FIPS。
使用 ARM 範本建立Windows節點池,部署代理池資源,並將
osType設為Windows。 例如:{ "type": "Microsoft.ContainerService/managedClusters/agentPools", "apiVersion": "2023-03-01", "name": "[concat(parameters('clusterName'), '/fipsnp')]", "properties": { "count": 3, "vmSize": "Standard_D2s_v3", "osType": "Windows", "osSKU": "Windows2022", "mode": "User" } }使用 Azure portal、Azure CLI 或 Azure PowerShell 部署 ARM 範本。 欲了解更多部署 ARM 範本的資訊,請參閱 「使用 ARM 範本部署資源」。
請使用
az aks show指令並在 agentPoolProfiles 查詢 enableFIPS 值來驗證你的節點池設定。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table透過
建立RDP連線到節點池中的Windows節點 並檢查登錄檔,驗證Windows節點池是否能存取FIPS密碼庫。 從 [執行] 應用程式中,輸入 regedit。在登錄中尋找
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\FIPSAlgorithmPolicy。如果
Enabled設為 1,則會啟用 FIPS。
已啟用 FIPS 的節點集區也有 kubernetes.azure.com/fips_enabled=true 標籤,部署可用這些節點集區設為目標。
使用 Bicep 建立Windows節點池,部署一個將
osType設為Windows的代理池資源。 例如:param clusterName string param nodePoolName string = 'fipsnp' resource nodePool 'Microsoft.ContainerService/managedClusters/agentPools@2023-03-01' = { name: '${clusterName}/${nodePoolName}' properties: { count: 3 vmSize: 'Standard_D2s_v3' osType: 'Windows' osSKU: 'Windows2022' mode: 'User' enableFIPS: true } }請使用 Azure CLI、Azure PowerShell 或 Azure 入口部署 Bicep 檔案。 欲了解更多有關部署 Bicep 檔案的資訊,請參閱<使用 Visual Studio Code 建立 Bicep 檔案>。
請使用
az aks show指令並在 agentPoolProfiles 查詢 enableFIPS 值來驗證你的節點池設定。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table透過
建立RDP連線到節點池中的Windows節點 並檢查登錄檔,驗證Windows節點池是否能存取FIPS密碼庫。 從 [執行] 應用程式中,輸入 regedit。在登錄中尋找
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\FIPSAlgorithmPolicy。如果
Enabled設為 1,則會啟用 FIPS。
已啟用 FIPS 的節點集區也有 kubernetes.azure.com/fips_enabled=true 標籤,部署可用這些節點集區設為目標。
在
main.tf中加入以下程式碼,在你的 AKS 叢集中建立一個Windows節點池:resource "azurerm_kubernetes_cluster_node_pool" "fips_windows" { name = "fipsnp" kubernetes_cluster_id = azurerm_kubernetes_cluster.example.id vm_size = "Standard_D2s_v3" os_type = "Windows" os_sku = "Windows2022" node_count = 3 fips_enabled = true node_taints = [] }請使用
terraform planandterraform apply指令套用更新後的 Terraform 設定。terraform plan terraform apply使用 [
az aks get-credentials][az-aks-get-credentials] 指令連接到 AKS 叢集。az aks get-credentials \ --resource-group myResourceGroup \ --name myAKSCluster請使用
az aks show指令並在 agentPoolProfiles 查詢 enableFIPS 值來驗證你的節點池設定。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table透過
建立RDP連線到節點池中的Windows節點 並檢查登錄檔,驗證Windows節點池是否能存取FIPS密碼庫。 從 [執行] 應用程式中,輸入 regedit。在登錄中尋找
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\FIPSAlgorithmPolicy。如果
Enabled設為 1,則會啟用 FIPS。
已啟用 FIPS 的節點集區也有 kubernetes.azure.com/fips_enabled=true 標籤,部署可用這些節點集區設為目標。
更新現有的節點集區以啟用或停用 FIPS
可以更新現有的 Linux 節點集區以啟用或停用 FIPS。 如果您打算將節點集區從非 FIPS 移轉至 FIPS,請先驗證應用程式是否在測試環境中正常運作,再將其移轉至生產環境。 在測試環境中驗證您的應用程式應該防止 FIPS 核心封鎖某些弱式加密或加密演算法所造成的問題,例如不符合 FIPS 規範的 MD4 演算法。
附註
當更新現有的 Linux 節點池以啟用或停用 FIPS 時,節點池的更新會在 FIPS 與非 FIPS 映像之間移動。 此節點集區更新會觸發重新映像以完成更新。 這可能會導致節點集區更新需要幾分鐘的時間才能完成。
更新現有節點池的前提條件
Azure CLI 版本 2.64.0 或更後版本。 若要尋找版本,請執行 az --version。 如果你需要安裝或升級,請參考 安裝 Azure CLI。
在現有的節點集區上啟用 FIPS
你可以更新現有的 Linux 節點池來啟用 FIPS。 當您更新現有的節點集區時,節點映像會從目前的映像變更為相同 OS SKU 的建議 FIPS 映射。
用
az aks nodepool update帶有參數--enable-fips-image的指令更新節點池。az aks nodepool update \ --resource-group myResourceGroup \ --cluster-name myAKSCluster \ --name np \ --enable-fips-image此指令會立即觸發節點池的重映像,以部署符合 FIPS 標準的作業系統。 此重新映像會在節點集區更新期間發生。 不需要額外的步驟。
請使用
az aks show指令,在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池是否啟用了 FIPS。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table下列範例輸出顯示 np 節點集區已啟用 FIPS:
Name enableFips --------- ------------ np True nodepool1 False
目前在 Azure 入口網站中不支援在現有的節點集區上啟用 FIPS。 要在現有節點池啟用 FIPS,請使用本文中的 Azure CLI、ARM 範本、Bicep 或 Terraform 指示。
透過更新代理池設定檔,將屬性設定
enableFips為true,即可在現有節點池使用 ARM 範本啟用 FIPS。 例如:{ "type": "Microsoft.ContainerService/managedClusters/agentPools", "name": "[concat(parameters('clusterName'), '/np')]", "apiVersion": "2023-03-01", "properties": { "enableFips": true } }請使用 Azure portal、Azure CLI 或 Azure PowerShell 部署更新後的範本。 欲了解更多部署 ARM 範本的資訊,請參閱 「使用 ARM 範本部署資源」。
請使用
az aks show指令,在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池是否啟用了 FIPS。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table下列範例輸出顯示 np 節點集區已啟用 FIPS:
Name enableFips --------- ------------ np True nodepool1 False
使用 Bicep 在現有節點集區上啟用 FIPS,方法是更新 Agent 集區資源以將
enableFIPS設定為true。 例如:param clusterName string param nodePoolName string = 'np' resource nodePool 'Microsoft.ContainerService/managedClusters/agentPools@2023-03-01' = { name: '${clusterName}/${nodePoolName}' properties: { enableFIPS: true } }請使用 Azure CLI、Azure PowerShell 或 Azure portal 部署更新後的 Bicep 檔案。 欲了解更多有關部署 Bicep 檔案的資訊,請參閱<使用 Visual Studio Code 建立 Bicep 檔案>。
請使用
az aks show命令,並查詢agentPoolProfiles中的enableFIPS值,以確認你的節點池是否已啟用 FIPS。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table下列範例輸出顯示 np 節點集區已啟用 FIPS:
Name enableFips --------- ------------ np True nodepool1 False
將
azurerm_kubernetes_cluster_node_pool設定為main.tf,以更新fips_enabledtrue中的資源。resource "azurerm_kubernetes_cluster_node_pool" "example" { name = "np" kubernetes_cluster_id = azurerm_kubernetes_cluster.example.id vm_size = "Standard_D2s_v3" os_type = "Linux" os_sku = "Ubuntu" node_count = 3 fips_enabled = true }請使用
terraform planandterraform apply指令套用更新後的 Terraform 設定。 Terraform 偵測到對fips_enabled的變更並觸發必要的重新安裝映像作業。terraform plan terraform apply使用 [
az aks get-credentials][az-aks-get-credentials] 指令連接到 AKS 叢集。az aks get-credentials \ --resource-group myResourceGroup \ --name myAKSCluster請使用
az aks show指令,在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池是否啟用了 FIPS。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table下列範例輸出顯示 np 節點集區已啟用 FIPS:
Name enableFips --------- ------------ np True nodepool1 False
在現有節點集區上停用 FIPS
你可以更新現有的 Linux 節點池來停用 FIPS。 更新現有的節點集區時,節點映像會從目前的 FIPS 映像變更為相同 OS SKU 的建議的非 FIPS 映像。 節點影像的變更發生在重映像之後。
使用
az aks nodepool update帶有--disable-fips-image參數的指令更新 Linux 節點池。az aks nodepool update \ --resource-group myResourceGroup \ --cluster-name myAKSCluster \ --name np \ --disable-fips-image此指令會立即觸發節點池的重映像,以部署符合 FIPS 標準的作業系統。 此重新映像會在節點集區更新期間發生。 不需要額外的步驟。
使用
az aks show命令,並在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池沒有啟用 FIPS。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table下列範例輸出顯示 np 節點集區未啟用 FIPS:
Name enableFips --------- ------------ np False nodepool1 False
目前在 Azure 入口網站中不支援在現有的節點集區上停用 FIPS。 要在現有節點池中停用 FIPS,請使用本文中的 Azure CLI、ARM 範本、Bicep 或 Terraform 的說明。
使用 ARM 範本更新代理池設定檔,將屬性從
enableFips設定為false,以關閉現有節點池的 FIPS。 例如:{ "type": "Microsoft.ContainerService/managedClusters/agentPools", "name": "[concat(parameters('clusterName'), '/np')]", "apiVersion": "2023-03-01", "properties": { "enableFips": false } }請使用 Azure portal、Azure CLI 或 Azure PowerShell 部署更新後的範本。 欲了解更多部署 ARM 範本的資訊,請參閱 「使用 ARM 範本部署資源」。
使用
az aks show命令,並在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池沒有啟用 FIPS。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table下列範例輸出顯示 np 節點集區未啟用 FIPS:
Name enableFips --------- ------------ np False nodepool1 False
使用 Bicep 來停用現有節點池的 FIPS,方法是更新代理池資源,將
enableFIPS設為false。 例如:param clusterName string param nodePoolName string = 'np' resource nodePool 'Microsoft.ContainerService/managedClusters/agentPools@2023-03-01' = { name: '${clusterName}/${nodePoolName}' properties: { enableFIPS: false } }請使用 Azure CLI、Azure PowerShell 或 Azure portal 部署更新後的 Bicep 檔案。 欲了解更多有關部署 Bicep 檔案的資訊,請參閱<使用 Visual Studio Code 建立 Bicep 檔案>。
使用
az aks show命令,並在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池沒有啟用 FIPS。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table下列範例輸出顯示 np 節點集區未啟用 FIPS:
Name enableFips --------- ------------ np False nodepool1 False
將
azurerm_kubernetes_cluster_node_pool設定為main.tf,以更新fips_enabledfalse中的資源。resource "azurerm_kubernetes_cluster_node_pool" "example" { name = "np" kubernetes_cluster_id = azurerm_kubernetes_cluster.example.id vm_size = "Standard_D2s_v3" os_type = "Linux" os_sku = "Ubuntu" node_count = 3 fips_enabled = false }請使用
terraform planandterraform apply指令套用更新後的 Terraform 設定。 Terraform 偵測到對fips_enabled的變更並觸發必要的重新安裝映像作業。terraform plan terraform apply使用
az aks show命令,並在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池沒有啟用 FIPS。az aks show \ --resource-group myResourceGroup \ --name myAKSCluster \ --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \ -o table下列範例輸出顯示 np 節點集區未啟用 FIPS:
Name enableFips --------- ------------ np False nodepool1 False
今日訊息
你可以在建立叢集或新增節點池時,使用 Linux 節點的旗標替換每日--message-of-the-day(MOTD)。
使用 az aks create 命令建立叢集,並設 --message-of-the-day 旗標為新 MOTD 檔案路徑以替換當日訊息。
az aks create --cluster-name myAKSCluster --resource-group myResourceGroup --message-of-the-day ./newMOTD.txt
新增一個節點池,並使用 az aks nodepool add 命令,設置 --message-of-the-day 參數為新的 MOTD 檔案路徑,以替換每日訊息。
az aks nodepool add --name mynodepool1 --cluster-name myAKSCluster --resource-group myResourceGroup --message-of-the-day ./newMOTD.txt
相關內容
- 欲了解更多關於 AKS 安全性的資訊,請參閱 Azure Kubernetes Service (AKS) 中叢集安全與升級的最佳實務。
- 欲了解更多關於升級 Linux FIPS 節點池作業系統版本的資訊,請參閱 升級 Linux 作業系統版本。
- 欲了解更多關於升級 Windows FIPS 節點池作業系統版本的資訊,請參閱升級 Windows OS 版本。