啟用 Azure Kubernetes 服務 (AKS) 節點池的聯邦資訊處理標準(FIPS)

聯邦資訊處理標準(FIPS)140-3 是美國政府的一項標準,定義了資訊科技產品與系統中密碼模組的最低安全要求。 Azure Kubernetes Service (AKS) 允許您在啟用 FIPS 140-3 的情況下建立 Linux 和 Windows 節點池。 在支援 FIPS 的節點池上運行的部署會使用這些加密模組,以提升安全性並協助符合 FedRAMP 合規的安全控管。 欲了解更多FIPS 140-3資訊,請參閱 聯邦資訊處理標準(FIPS)140。

重要事項

自 2027 年 3 月 17 日 起,Azure Kubernetes Service (AKS) 不再支援或提供 Ubuntu 20.04 的安全更新。 所有現有的節點映像檔都會被刪除,且你無法擴展任何運行 Ubuntu 20.04 的節點池。 透過 將節點池升級 到 Kubernetes 的 1.35+ 版本,來遷移到受支援的 Ubuntu 版本。 欲了解更多退休資訊,請參閱 Retirement GitHub issue 及 Azure 更新退休公告 。 欲掌握最新公告與更新,請參考AKS發布說明。

重要事項

自 2025 年 11 月 30 日起,Azure Kubernetes Service (AKS) 將不再支援或提供 Azure Linux 2.0 的安全更新。 Azure Linux 2.0 節點映像已凍結在202512.06.0發行版本。 自 2026 年 10 月 31 日起,節點映像將被移除,且你將無法擴展你的節點池。 遷移到支援的 Azure Linux 版本時,可以升級你的節點池到 支援的 Kubernetes 版本,或遷移到 osSku AzureLinux3。 欲了解更多資訊,請參閱 退休GitHub議題 及 Azure 更新退休公告。 欲掌握最新公告與更新,請參考AKS發布說明。

先決條件

  • 一個有效的 Azure 訂閱。 如果你沒有Azure訂閱,請在開始前建立一個free帳號。

  • 請用指令 az account set 設定你的訂閱上下文。 例如:

    az account set --subscription "00000000-0000-0000-0000-000000000000"
    
  • Kubectl 已安裝。 您可以使用命令 az aks install-cli 在本機安裝它。

版本相容性

  • Azure CLI 版本 2.32.0 或更新版本已安裝並配置。 若要尋找版本,請執行 az --version。 欲了解更多安裝或升級Azure CLI的資訊,請參見 Install Azure CLI。
  • 本文中的 ARM 範本範例使用 API 版本 2023-03-01,用於 Microsoft.ContainerService/managedClusters 和 Microsoft.ContainerService/managedClusters/agentPools。
  • 本文中的 Bicep 範例使用 API 版本 2023-03-01,適用於 Microsoft.ContainerService/managedClusters 和 Microsoft.ContainerService/managedClusters/agentPools。
  • 本文中的 Terraform 範例使用 AzureRM 提供者 3.x。
  • 對於 Terraform FIPS 設定,請使用 enable_fips_image 在 azurerm_kubernetes_cluster.default_node_pool 上,並將 fips_enabled 用於 azurerm_kubernetes_cluster_node_pool。

限制

啟用 FIPS 的節點池有以下限制:

  • 已啟用 FIPS 的節點集區需要 Kubernetes 1.19 版和更新版本。
  • 啟用 FIPS 的 Trusted Launch 僅支援 Gen2 虛擬機器規格上的 Ubuntu 22.04。
  • 要更新用於 FIPS 的底層套件或模組,必須使用 Node 映像升級。
  • FIPS 節點上的容器映像不會進行 FIPS 合規性評估。
  • 掛接 CIFS 共用失敗,因為 FIPS 會停用某些驗證模組。 若要解決此問題,請參閱在已啟用 FIPS 的節點集區上掛接檔案共用時發生錯誤。
  • 支援 FIPS 的節點池,包含 Arm64 虛擬機,僅支援 Azure Linux 3.0+。
  • AKS 監控外掛支援 FIPS 節點池,支援 Ubuntu、Azure Linux 及 Windows,從 Agent 版本 3.1.17(Linux)及 Win-3.1.17(Windows)開始。

重要事項

已啟用 FIPS 的 Linux 映像與用於 Linux 節點集區的預設 Linux 映像不同。

啟用 FIPS 的節點映像檔可能擁有不同的作業系統版本和核心版本,與未啟用 FIPS 的映像檔不同。 啟用 FIPS 的節點集區和節點映像的更新週期可能與未啟用 FIPS 的節點集區和映射不同。

支援的 OS 版本

你可以在所有支援的作業系統類型(Linux 和 Windows)上建立啟用 FIPS 的節點池。 不過,並非所有作系統版本都支援已啟用 FIPS 的節點集區。 發行新的 OS 版本之後,通常會有等候期間,才符合 FIPS 規範。

下表列出支援支援 FIPS 節點池的作業系統版本:

OS 類型 作業系統 SKU FIPS 合規性 預設值
Linux Ubuntu 支援 Ubuntu 20.04 與 Ubuntu 22.04 預設為停用
Linux Azure Linux 支援 Azure Linux 3.0 預設為停用
Windows Windows Server 2022 支援 預設啟用
Windows Windows Server 2025 支援 預設啟用,無法關閉

當請求啟用 FIPS 的 Ubuntu 時,如果預設的 Ubuntu 版本不支援 FIPS,AKS 會預設使用最新支援 FIPS 的 Ubuntu。 例如,Ubuntu 24.04 是 Linux 節點池的預設版本。 由於 Ubuntu 24.04 目前不支援 FIPS,AKS 預設使用 Ubuntu 22.04 來支援 Linux FIPS 的節點池。

附註

過去,你可以用 GetOSOptions API 判斷某個作業系統是否支援 FIPS。 該 GetOSOptions API 現已棄用,並自 2024-05-01 起不再包含在新的 AKS API 版本中。

建立 Terraform 設定檔

Terraform 設定檔定義了 Terraform 所建立和管理的基礎架構。

  1. 建立一個名為 main.tf 的檔案,並加入以下程式碼來定義 Terraform 版本並指定Azure提供者:

    terraform {
      required_version = ">= 1.0"
    
      required_providers {
        azurerm = {
          source  = "hashicorp/azurerm"
          version = "~> 3.0"
        }
      }
    }
    
    provider "azurerm" {
      features {}
    }
    
  2. 將以下程式碼加入 main.tf 以建立Azure資源群組。 如有需要,歡迎更改資源群組的名稱和地點。

    resource "azurerm_resource_group" "example" {
      name     = "example-fips-rg"
      location = "East US"
    }
    

建立一個啟用 FIPS 預設節點池的 AKS 叢集

你可以在建立新的 AKS 叢集時,在預設節點池啟用 FIPS。

當在已有 FIPS 預設節點池的叢集上建立更多節點池時,你也必須使用 --enable-fips-image 參數在新節點池上啟用 FIPS。

  1. 在預設節點池上使用 az aks create 指令和其帶有的 --enable-fips-image 參數建立一個啟用 FIPS 的 AKS 叢集。

    az aks create \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --node-count 3 \
        --enable-fips-image
    
  2. 請使用 az aks show 指令,在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池是否啟用了 FIPS。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    

    以下範例輸出顯示預設節點池已啟用 FIPS:

    Name       enableFips
    ---------  ------------
    nodepool1  True
    

目前在 Azure portal 中不支援在建立 AKS 叢集時啟用 FIPS。 要建立一個支援 FIPS 的預設節點池叢集,請使用本文中的 Azure CLI、ARM 範本、Bicep 或 Terraform 的指示。

當在具有已啟用 FIPS 的預設節點池的叢集上建立更多節點池時,你必須透過將enableFips 設定為true,來啟用新的節點池上的 FIPS。

  1. 在預設節點池中,使用 ARM 範本設定代理池設定檔中的 enableFips 屬性為 true,以建立啟用 FIPS 的 AKS 叢集。 例如:

    {
      "type": "Microsoft.ContainerService/managedClusters",
      "location": "[parameters('location')]",
      "name": "[parameters('clusterName')]",
      "properties": {
        "kubernetesVersion": "1.27",
        "enableRBAC": true,
        "dnsPrefix": "[parameters('dnsPrefix')]",
        "agentPoolProfiles": [
          {
            "name": "nodepool1",
            "count": 3,
            "vmSize": "Standard_D2s_v3",
            "osType": "Linux",
            "osSKU": "Ubuntu",
            "type": "VirtualMachineScaleSets",
            "mode": "System",
            "enableFips": true
          }
        ]
      },
      "identity": {
        "type": "SystemAssigned"
      }
    }
    
  2. 使用 Azure portal、Azure CLI 或 Azure PowerShell 部署 ARM 範本。 欲了解更多部署 ARM 範本的資訊,請參閱 「使用 ARM 範本部署資源」。

  3. 請使用 az aks show 指令,在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池是否啟用了 FIPS。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    

    以下範例輸出顯示預設節點池已啟用 FIPS:

    Name       enableFips
    ---------  ------------
    nodepool1  True
    

當在具有已啟用 FIPS 的預設節點池的叢集上建立更多節點池時,你必須透過將enableFIPS 設定為true,來啟用新的節點池上的 FIPS。

  1. 使用 Bicep 建立啟用 FIPS 的 AKS 叢集於預設節點池,方法是在代理池設定檔中將 enableFIPS 設定為 true。 例如:

    param location string
    param clusterName string
    param dnsPrefix string
    
    resource aks 'Microsoft.ContainerService/managedClusters@2023-03-01' = {
      name: clusterName
      location: location
      identity: {
        type: 'SystemAssigned'
      }
      properties: {
        kubernetesVersion: '1.27'
        enableRBAC: true
        dnsPrefix: dnsPrefix
        agentPoolProfiles: [
          {
            name: 'nodepool1'
            count: 3
            vmSize: 'Standard_D2s_v3'
            osType: 'Linux'
            osSKU: 'Ubuntu'
            type: 'VirtualMachineScaleSets'
            mode: 'System'
            enableFIPS: true
          }
        ]
      }
    }
    
  2. 請使用 Azure CLI、Azure PowerShell 或 Azure 入口部署 Bicep 檔案。 欲了解更多有關部署 Bicep 檔案的資訊,請參閱<使用 Visual Studio Code 建立 Bicep 檔案>。

  3. 請使用 az aks show 指令,在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池是否啟用了 FIPS。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    

    以下範例輸出顯示預設節點池已啟用 FIPS:

    Name       enableFips
    ---------  ------------
    nodepool1  True
    

在已啟用 FIPS 預設節點集區的叢集上建立更多節點集區時,您也必須在新節點集區上啟用 FIPS,方法是在fips_enabled上將true設定為azurerm_kubernetes_cluster_node_pool。

  1. 在預設節點池中建立啟用 FIPS 的 AKS 叢集時,新增以下程式碼至 main.tf:

    resource "azurerm_kubernetes_cluster" "example" {
      name                = "example-aks-cluster"
      location            = azurerm_resource_group.example.location
      resource_group_name = azurerm_resource_group.example.name
      dns_prefix          = "example-aks"
    
      default_node_pool {
        name              = "nodepool1"
        node_count        = 3
        vm_size           = "Standard_D2s_v3"
        os_sku            = "Ubuntu"
        enable_fips_image = true
      }
    
      identity {
        type = "SystemAssigned"
      }
    }
    
  2. 在包含你 main.tf 檔案的目錄中,使用 terraform init 指令初始化 Terraform。

    terraform init
    
  3. 使用 terraform plan 命令建立 Terraform 執行計畫。

    terraform plan
    
  4. 使用 terraform apply 命令套用設定,部署具備 FIPS 預設節點池的叢集。

    terraform apply
    
  5. 使用 [az aks get-credentials][az-aks-get-credentials] 指令連接到 AKS 叢集。

    az aks get-credentials \
        --resource-group myResourceGroup \
        --name myAKSCluster
    
  6. 請使用 az aks show 指令,在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池是否啟用了 FIPS。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    

    以下範例輸出顯示預設節點池已啟用 FIPS:

    Name       enableFips
    ---------  ------------
    nodepool1  True
    

欲了解更多關於 azurerm_kubernetes_cluster 資源的資訊,請參閱 Terraform Azure 提供者文件。

在現有的 AKS 叢集中新增支援 FIPS 的 Linux 節點池

  1. 使用 az aks nodepool add 帶有參數的 --enable-fips-image 指令,將支援 FIPS 的 Linux 節點池加入現有叢集。

    az aks nodepool add \
        --resource-group myResourceGroup \
        --cluster-name myAKSCluster \
        --name fipsnp \
        --enable-fips-image
    
  2. 請使用az aks show指令並在 agentPoolProfiles 查詢 enableFIPS 值來驗證你的節點池設定。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    

    下列範例輸出顯示 fipsnp 節點集區已啟用 FIPS:

    Name       enableFips
    ---------  ------------
    fipsnp     True
    nodepool1  False  
    
  3. 使用 kubectl get nodes 命令列出節點。

    kubectl get nodes
    

    下列範例輸出顯示叢集中的節點清單。 開頭為 aks-fipsnp 的節點是已啟用 FIPS 節點集區的一部分。

    NAME                                STATUS   ROLES   AGE     VERSION
    aks-fipsnp-12345678-vmss000000      Ready    agent   6m4s    v1.19.9
    aks-fipsnp-12345678-vmss000001      Ready    agent   5m21s   v1.19.9
    aks-fipsnp-12345678-vmss000002      Ready    agent   6m8s    v1.19.9
    aks-nodepool1-12345678-vmss000000   Ready    agent   34m     v1.19.9
    
  4. 在已啟用 FIPS 節點集區的其中一個節點上,使用 kubectl debug 命令以透過互動式工作階段來執行部署。

    kubectl debug node/aks-fipsnp-12345678-vmss000000 -it --image=mcr.microsoft.com/dotnet/runtime-deps:6.0
    
  5. 從互動式工作階段輸出來確認 FIPS 密碼編譯程式庫已啟用。 您的輸出看起來應該類似下列範例輸出:

    root@aks-fipsnp-12345678-vmss000000:/# cat /proc/sys/crypto/fips_enabled
    1
    

    已啟用 FIPS 的節點集區也有 kubernetes.azure.com/fips_enabled=true 標籤,部署可用這些節點集區設為目標。

目前在 Azure 入口網站中不支援新增 Linux 節點集區時啟用 FIPS。 要新增支援 FIPS 的 Linux 節點池,請使用本文中的 Azure CLI、ARM 範本、Bicep 或 Terraform 指示。

  1. 透過部署將 enableFips 屬性設定為 true的代理池資源,使用 ARM 範本建立支援 FIPS 的 Linux 節點池。 例如:

    {
      "type": "Microsoft.ContainerService/managedClusters/agentPools",
      "apiVersion": "2023-03-01",
      "name": "[concat(parameters('clusterName'), '/fipsnp')]",
      "properties": {
        "count": 3,
        "vmSize": "Standard_D2s_v3",
        "osType": "Linux",
        "osSKU": "Ubuntu",
        "mode": "User",
        "enableFips": true
      }
    }
    
  2. 使用 Azure portal、Azure CLI 或 Azure PowerShell 部署 ARM 範本。 欲了解更多部署 ARM 範本的資訊,請參閱 「使用 ARM 範本部署資源」。

  3. 請使用az aks show指令並在 agentPoolProfiles 查詢 enableFIPS 值來驗證你的節點池設定。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    

    下列範例輸出顯示 fipsnp 節點集區已啟用 FIPS:

    Name       enableFips
    ---------  ------------
    fipsnp     True
    nodepool1  False  
    
  4. 使用 kubectl get nodes 命令列出節點。

    kubectl get nodes
    

    下列範例輸出顯示叢集中的節點清單。 開頭為 aks-fipsnp 的節點是已啟用 FIPS 節點集區的一部分。

    NAME                                STATUS   ROLES   AGE     VERSION
    aks-fipsnp-12345678-vmss000000      Ready    agent   6m4s    v1.19.9
    aks-fipsnp-12345678-vmss000001      Ready    agent   5m21s   v1.19.9
    aks-fipsnp-12345678-vmss000002      Ready    agent   6m8s    v1.19.9
    aks-nodepool1-12345678-vmss000000   Ready    agent   34m     v1.19.9
    
  5. 在已啟用 FIPS 節點集區的其中一個節點上,使用 kubectl debug 命令以透過互動式工作階段來執行部署。

    kubectl debug node/aks-fipsnp-12345678-vmss000000 -it --image=mcr.microsoft.com/dotnet/runtime-deps:6.0
    
  6. 從互動式工作階段輸出來確認 FIPS 密碼編譯程式庫已啟用。 您的輸出看起來應該類似下列範例輸出:

    root@aks-fipsnp-12345678-vmss000000:/# cat /proc/sys/crypto/fips_enabled
    1
    

    已啟用 FIPS 的節點集區也有 kubernetes.azure.com/fips_enabled=true 標籤,部署可用這些節點集區設為目標。

  1. 透過部署代理池資源,將 enableFIPS 設為 true,使用 Bicep 建立支援 FIPS 的 Linux 節點池。 例如:

    param clusterName string
    param nodePoolName string = 'fipsnp'
    
    resource nodePool 'Microsoft.ContainerService/managedClusters/agentPools@2023-03-01' = {
      name: '${clusterName}/${nodePoolName}'
      properties: {
        count: 3
        vmSize: 'Standard_D2s_v3'
        osType: 'Linux'
        osSKU: 'Ubuntu'
        mode: 'User'
        enableFIPS: true
      }
    }
    
  2. 請使用 Azure CLI、Azure PowerShell 或 Azure 入口部署 Bicep 檔案。 欲了解更多有關部署 Bicep 檔案的資訊,請參閱<使用 Visual Studio Code 建立 Bicep 檔案>。

  3. 請使用az aks show指令並在 agentPoolProfiles 查詢 enableFIPS 值來驗證你的節點池設定。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    

    下列範例輸出顯示 fipsnp 節點集區已啟用 FIPS:

    Name       enableFips
    ---------  ------------
    fipsnp     True
    nodepool1  False  
    
  4. 使用 kubectl get nodes 命令列出節點。

    kubectl get nodes
    

    下列範例輸出顯示叢集中的節點清單。 開頭為 aks-fipsnp 的節點是已啟用 FIPS 節點集區的一部分。

    NAME                                STATUS   ROLES   AGE     VERSION
    aks-fipsnp-12345678-vmss000000      Ready    agent   6m4s    v1.19.9
    aks-fipsnp-12345678-vmss000001      Ready    agent   5m21s   v1.19.9
    aks-fipsnp-12345678-vmss000002      Ready    agent   6m8s    v1.19.9
    aks-nodepool1-12345678-vmss000000   Ready    agent   34m     v1.19.9
    
  5. 在已啟用 FIPS 節點集區的其中一個節點上,使用 kubectl debug 命令以透過互動式工作階段來執行部署。

    kubectl debug node/aks-fipsnp-12345678-vmss000000 -it --image=mcr.microsoft.com/dotnet/runtime-deps:6.0
    
  6. 從互動式工作階段輸出來確認 FIPS 密碼編譯程式庫已啟用。 您的輸出看起來應該類似下列範例輸出:

    root@aks-fipsnp-12345678-vmss000000:/# cat /proc/sys/crypto/fips_enabled
    1
    

    已啟用 FIPS 的節點集區也有 kubernetes.azure.com/fips_enabled=true 標籤,部署可用這些節點集區設為目標。

  1. 新增以下程式碼,以便在 main.tf 你的 AKS 叢集中加入支援 FIPS 的 Linux 節點池:

    resource "azurerm_kubernetes_cluster_node_pool" "fips_linux" {
      name                   = "fipsnp"
      kubernetes_cluster_id  = azurerm_kubernetes_cluster.example.id
      vm_size                = "Standard_D2s_v3"
      os_type                = "Linux"
      os_sku                 = "Ubuntu"
      node_count             = 3
      fips_enabled           = true
    
      node_taints = []
    }
    
  2. 請使用 terraform plan and terraform apply 指令套用更新後的 Terraform 設定。

    terraform plan
    terraform apply
    
  3. 使用 [az aks get-credentials][az-aks-get-credentials] 指令連接到 AKS 叢集。

    az aks get-credentials \
        --resource-group myResourceGroup \
        --name myAKSCluster
    
  4. 請使用az aks show指令並在 agentPoolProfiles 查詢 enableFIPS 值來驗證你的節點池設定。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    

    下列範例輸出顯示 fipsnp 節點集區已啟用 FIPS:

    Name       enableFips
    ---------  ------------
    fipsnp     True
    nodepool1  False  
    
  5. 使用 kubectl get nodes 命令列出節點。

    kubectl get nodes
    

    下列範例輸出顯示叢集中的節點清單。 開頭為 aks-fipsnp 的節點是已啟用 FIPS 節點集區的一部分。

    NAME                                STATUS   ROLES   AGE     VERSION
    aks-fipsnp-12345678-vmss000000      Ready    agent   6m4s    v1.19.9
    aks-fipsnp-12345678-vmss000001      Ready    agent   5m21s   v1.19.9
    aks-fipsnp-12345678-vmss000002      Ready    agent   6m8s    v1.19.9
    aks-nodepool1-12345678-vmss000000   Ready    agent   34m     v1.19.9
    
  6. 在已啟用 FIPS 節點集區的其中一個節點上,使用 kubectl debug 命令以透過互動式工作階段來執行部署。

    kubectl debug node/aks-fipsnp-12345678-vmss000000 -it --image=mcr.microsoft.com/dotnet/runtime-deps:6.0
    
  7. 從互動式工作階段輸出來確認 FIPS 密碼編譯程式庫已啟用。 您的輸出看起來應該類似下列範例輸出:

    root@aks-fipsnp-12345678-vmss000000:/# cat /proc/sys/crypto/fips_enabled
    1
    

    已啟用 FIPS 的節點集區也有 kubernetes.azure.com/fips_enabled=true 標籤,部署可用這些節點集區設為目標。

欲了解更多關於 azurerm_kubernetes_cluster_node_pool 資源的資訊,請參閱 Terraform Azure 提供者文件。

新增一個啟用 FIPS 和 Trusted Launch 的 Linux 節點池

FIPS 的 Trusted Launch 僅支援 Ubuntu 22.04 在第二代虛擬機容量上。

欲了解更多關於可信啟動需求與行為的資訊,請參閱 Azure Kubernetes Service (AKS) 的可信啟動。

  1. 透過指令 az aks nodepool add 新增一個啟用 FIPS 與 Trusted Launch 的 Linux 節點池。

    az aks nodepool add \
        --resource-group myResourceGroup \
        --cluster-name myAKSCluster \
        --name fipstlnp \
        --os-type Linux \
        --os-sku Ubuntu \
        --node-count 3 \
        --enable-fips-image \
        --enable-vtpm \
        --enable-secure-boot
    
  2. 請使用 az aks show 指令,並查詢 agentPoolProfiles 中的 enableFIPS 值,以確認您的節點集區設定。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    

    以下範例輸出顯示 FIPSTLNP 節點池已啟用 FIPS:

    Name       enableFips
    ---------  ------------
    fipstlnp   True
    nodepool1  False
    
  3. 確認節點池是否使用受信任啟動映像。

    受信任的發射節點回傳以下輸出:

    • 節點映像版本同時包含 "TL" 和 "FIPS"。
    • "Security-type" 是 "Trusted Launch"。
    kubectl get nodes
    kubectl describe node {node-name} | grep -e node-image-version -e security-type
    

目前 Azure 入口網站不支援新增同時啟用 FIPS 和 Trusted Launch 的 Linux 節點集區。 若要新增啟用 FIPS 與 Trusted Launch 的 Linux 節點池,請使用 Azure CLI、Azure Resource Manager 範本(ARM 範本)或本文中的 Bicep 指示。

  1. 使用 ARM 範本建立一個啟用 FIPS 與 Trusted Launch 的 Linux 節點池。 部署一個代理程式集區資源,將 enableFips 設為 true,並將 enableVTPM 和 enableSecureBoot 都設為 true。 例如:

    {
      "type": "Microsoft.ContainerService/managedClusters/agentPools",
      "apiVersion": "2023-03-01",
      "name": "[concat(parameters('clusterName'), '/fipstlnp')]",
      "properties": {
        "count": 3,
        "vmSize": "Standard_D2s_v3",
        "osType": "Linux",
        "osSKU": "Ubuntu",
        "mode": "User",
        "enableFips": true,
        "securityProfile": {
          "enableVTPM": "true",
          "enableSecureBoot": "true"
        }
      }
    }
    
  2. 你可以用 Azure portal、Azure CLI 或 Azure PowerShell 部署 ARM 模板。 欲了解更多部署 ARM 範本的資訊,請參閱 「使用 ARM 範本部署資源」。

  3. 請使用 az aks show 指令,並查詢 agentPoolProfiles 中的 enableFIPS 值,以確認您的節點集區設定。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    
  4. 驗證節點集區使用的是受信任的啟動映像。

    受信任的啟動節點具有下列輸出:

    • 節點映像版本同時包含 "TL" 和 "FIPS"。
    • "Security-type" 是 "Trusted Launch"。
    kubectl get nodes
    kubectl describe node {node-name} | grep -e node-image-version -e security-type
    
  1. 使用 Bicep 建立一個啟用 FIPS 和 Trusted Launch 的 Linux 節點池。 部署一個代理程式集區資源,並將 enableFIPS、enableVTPM 和 enableSecureBoot 設為 true。 例如:

    param clusterName string
    param nodePoolName string = 'fipstlnp'
    
    resource nodePool 'Microsoft.ContainerService/managedClusters/agentPools@2023-03-01' = {
      name: '${clusterName}/${nodePoolName}'
      properties: {
        count: 3
        vmSize: 'Standard_D2s_v3'
        osType: 'Linux'
        osSKU: 'Ubuntu'
        mode: 'User'
        enableFIPS: true
        securityProfile: {
          enableVTPM: true
          enableSecureBoot: true
        }
      }
    }
    
  2. 請使用 Azure CLI、Azure PowerShell 或 Azure portal 來部署 Bicep 檔案。 欲了解更多有關部署 Bicep 檔案的資訊,請參閱<使用 Visual Studio Code 建立 Bicep 檔案>。

  3. 請使用 az aks show 指令,並查詢 agentPoolProfiles 中的 enableFIPS 值,以確認您的節點集區設定。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    
  4. 驗證節點集區使用的是受信任的啟動映像。

    受信任的啟動節點具有下列輸出:

    • 節點映像版本同時包含 "TL" 和 "FIPS"。
    • "Security-type" 是 "Trusted Launch"。
    kubectl get nodes
    kubectl describe node {node-name} | grep -e node-image-version -e security-type
    

目前在 AzureRM 提供者中,使用 Terraform 新增同時啟用 FIPS 和 Trusted Launch 的 Linux 節點集區並不受支援,因為 AzureRM 提供者未公開 Trusted Launch 節點集區設定。

要新增啟用 FIPS 和可信啟動的 Linux 節點池,請使用本文中的 Azure CLI、ARM 範本或 Bicep 指示。

新增支援 FIPS 的 Windows 節點池

在本節中,我們將為現有的 AKS 叢集新增一個 Windows 節點池。 Windows Server 2022及後續節點池預設啟用FIPS,即使enableFips未顯示True。 Windows Server 2025 及以後的節點池不支援停用 FIPS。

  1. 使用 az aks nodepool add 指令建立一個Windows節點池。 與基於 Linux 的節點池不同,Windows 節點池共用相同的映像集。

    az aks nodepool add \
        --resource-group myResourceGroup \
        --cluster-name myAKSCluster \
        --name fipsnp \
        --enable-fips-image \
        --os-type Windows
    
  2. 請使用az aks show指令並在 agentPoolProfiles 查詢 enableFIPS 值來驗證你的節點池設定。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    
  3. 透過建立RDP連線到節點池中的Windows節點並檢查登錄檔,驗證Windows節點池是否能存取FIPS密碼庫。 從 [執行] 應用程式中,輸入 regedit。

  4. 在登錄中尋找 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\FIPSAlgorithmPolicy。

  5. 如果 Enabled 設為 1,則會啟用 FIPS。

    顯示 FIPS 演算法原則的登錄編輯器圖片且已啟用的螢幕擷取畫面。

    已啟用 FIPS 的節點集區也有 kubernetes.azure.com/fips_enabled=true 標籤,部署可用這些節點集區設為目標。

Azure 入口網站沒有功能可以啟用或關閉 Windows 節點池的 FIPS 設定。 任何使用 Azure 入口網站建立的 Windows 節點池都啟用了 FIPS。 Windows Server 2022 及以後版本的節點池預設啟用 FIPS,而 Windows Server 2025 及以後版本的節點池則不支援停用 FIPS。

  1. 使用 ARM 範本建立Windows節點池,部署代理池資源,並將 osType 設為 Windows。 例如:

    {
      "type": "Microsoft.ContainerService/managedClusters/agentPools",
      "apiVersion": "2023-03-01",
      "name": "[concat(parameters('clusterName'), '/fipsnp')]",
      "properties": {
        "count": 3,
        "vmSize": "Standard_D2s_v3",
        "osType": "Windows",
        "osSKU": "Windows2022",
        "mode": "User"
      }
    }
    
  2. 使用 Azure portal、Azure CLI 或 Azure PowerShell 部署 ARM 範本。 欲了解更多部署 ARM 範本的資訊,請參閱 「使用 ARM 範本部署資源」。

  3. 請使用az aks show指令並在 agentPoolProfiles 查詢 enableFIPS 值來驗證你的節點池設定。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    
  4. 透過建立RDP連線到節點池中的Windows節點並檢查登錄檔,驗證Windows節點池是否能存取FIPS密碼庫。 從 [執行] 應用程式中,輸入 regedit。

  5. 在登錄中尋找 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\FIPSAlgorithmPolicy。

  6. 如果 Enabled 設為 1,則會啟用 FIPS。

    顯示 FIPS 演算法原則的登錄編輯器圖片且已啟用的螢幕擷取畫面。

    已啟用 FIPS 的節點集區也有 kubernetes.azure.com/fips_enabled=true 標籤,部署可用這些節點集區設為目標。

  1. 使用 Bicep 建立Windows節點池,部署一個將 osType 設為 Windows 的代理池資源。 例如:

    param clusterName string
    param nodePoolName string = 'fipsnp'
    
    resource nodePool 'Microsoft.ContainerService/managedClusters/agentPools@2023-03-01' = {
      name: '${clusterName}/${nodePoolName}'
      properties: {
        count: 3
        vmSize: 'Standard_D2s_v3'
        osType: 'Windows'
        osSKU: 'Windows2022'
        mode: 'User'
        enableFIPS: true
      }
    }
    
  2. 請使用 Azure CLI、Azure PowerShell 或 Azure 入口部署 Bicep 檔案。 欲了解更多有關部署 Bicep 檔案的資訊,請參閱<使用 Visual Studio Code 建立 Bicep 檔案>。

  3. 請使用az aks show指令並在 agentPoolProfiles 查詢 enableFIPS 值來驗證你的節點池設定。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    
  4. 透過建立RDP連線到節點池中的Windows節點並檢查登錄檔,驗證Windows節點池是否能存取FIPS密碼庫。 從 [執行] 應用程式中,輸入 regedit。

  5. 在登錄中尋找 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\FIPSAlgorithmPolicy。

  6. 如果 Enabled 設為 1,則會啟用 FIPS。

    顯示 FIPS 演算法原則的登錄編輯器圖片且已啟用的螢幕擷取畫面。

    已啟用 FIPS 的節點集區也有 kubernetes.azure.com/fips_enabled=true 標籤,部署可用這些節點集區設為目標。

  1. 在 main.tf 中加入以下程式碼,在你的 AKS 叢集中建立一個Windows節點池:

    resource "azurerm_kubernetes_cluster_node_pool" "fips_windows" {
      name                   = "fipsnp"
      kubernetes_cluster_id  = azurerm_kubernetes_cluster.example.id
      vm_size                = "Standard_D2s_v3"
      os_type                = "Windows"
      os_sku                 = "Windows2022"
      node_count             = 3
      fips_enabled           = true
    
      node_taints = []
    }
    
  2. 請使用 terraform plan and terraform apply 指令套用更新後的 Terraform 設定。

    terraform plan
    terraform apply
    
  3. 使用 [az aks get-credentials][az-aks-get-credentials] 指令連接到 AKS 叢集。

    az aks get-credentials \
        --resource-group myResourceGroup \
        --name myAKSCluster
    
  4. 請使用az aks show指令並在 agentPoolProfiles 查詢 enableFIPS 值來驗證你的節點池設定。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    
  5. 透過建立RDP連線到節點池中的Windows節點並檢查登錄檔,驗證Windows節點池是否能存取FIPS密碼庫。 從 [執行] 應用程式中,輸入 regedit。

  6. 在登錄中尋找 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\FIPSAlgorithmPolicy。

  7. 如果 Enabled 設為 1,則會啟用 FIPS。

    顯示 FIPS 演算法原則的登錄編輯器圖片且已啟用的螢幕擷取畫面。

    已啟用 FIPS 的節點集區也有 kubernetes.azure.com/fips_enabled=true 標籤,部署可用這些節點集區設為目標。

更新現有的節點集區以啟用或停用 FIPS

可以更新現有的 Linux 節點集區以啟用或停用 FIPS。 如果您打算將節點集區從非 FIPS 移轉至 FIPS,請先驗證應用程式是否在測試環境中正常運作,再將其移轉至生產環境。 在測試環境中驗證您的應用程式應該防止 FIPS 核心封鎖某些弱式加密或加密演算法所造成的問題,例如不符合 FIPS 規範的 MD4 演算法。

附註

當更新現有的 Linux 節點池以啟用或停用 FIPS 時,節點池的更新會在 FIPS 與非 FIPS 映像之間移動。 此節點集區更新會觸發重新映像以完成更新。 這可能會導致節點集區更新需要幾分鐘的時間才能完成。

更新現有節點池的前提條件

Azure CLI 版本 2.64.0 或更後版本。 若要尋找版本,請執行 az --version。 如果你需要安裝或升級,請參考 安裝 Azure CLI。

在現有的節點集區上啟用 FIPS

你可以更新現有的 Linux 節點池來啟用 FIPS。 當您更新現有的節點集區時,節點映像會從目前的映像變更為相同 OS SKU 的建議 FIPS 映射。

  1. 用 az aks nodepool update 帶有參數 --enable-fips-image 的指令更新節點池。

    az aks nodepool update \
        --resource-group myResourceGroup \
        --cluster-name myAKSCluster \
        --name np \
        --enable-fips-image
    

    此指令會立即觸發節點池的重映像,以部署符合 FIPS 標準的作業系統。 此重新映像會在節點集區更新期間發生。 不需要額外的步驟。

  2. 請使用 az aks show 指令,在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池是否啟用了 FIPS。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    

    下列範例輸出顯示 np 節點集區已啟用 FIPS:

    Name       enableFips
    ---------  ------------
    np         True
    nodepool1  False  
    

目前在 Azure 入口網站中不支援在現有的節點集區上啟用 FIPS。 要在現有節點池啟用 FIPS,請使用本文中的 Azure CLI、ARM 範本、Bicep 或 Terraform 指示。

  1. 透過更新代理池設定檔,將屬性設定 enableFips 為 true,即可在現有節點池使用 ARM 範本啟用 FIPS。 例如:

    {
      "type": "Microsoft.ContainerService/managedClusters/agentPools",
      "name": "[concat(parameters('clusterName'), '/np')]",
      "apiVersion": "2023-03-01",
      "properties": {
        "enableFips": true
      }
    }
    
  2. 請使用 Azure portal、Azure CLI 或 Azure PowerShell 部署更新後的範本。 欲了解更多部署 ARM 範本的資訊,請參閱 「使用 ARM 範本部署資源」。

  3. 請使用 az aks show 指令,在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池是否啟用了 FIPS。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    

    下列範例輸出顯示 np 節點集區已啟用 FIPS:

    Name       enableFips
    ---------  ------------
    np         True
    nodepool1  False  
    
  1. 使用 Bicep 在現有節點集區上啟用 FIPS,方法是更新 Agent 集區資源以將enableFIPS設定為true。 例如:

    param clusterName string
    param nodePoolName string = 'np'
    
    resource nodePool 'Microsoft.ContainerService/managedClusters/agentPools@2023-03-01' = {
      name: '${clusterName}/${nodePoolName}'
      properties: {
        enableFIPS: true
      }
    }
    
  2. 請使用 Azure CLI、Azure PowerShell 或 Azure portal 部署更新後的 Bicep 檔案。 欲了解更多有關部署 Bicep 檔案的資訊,請參閱<使用 Visual Studio Code 建立 Bicep 檔案>。

  3. 請使用az aks show命令,並查詢agentPoolProfiles中的enableFIPS值,以確認你的節點池是否已啟用 FIPS。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    

    下列範例輸出顯示 np 節點集區已啟用 FIPS:

    Name       enableFips
    ---------  ------------
    np         True
    nodepool1  False  
    
  1. 將 azurerm_kubernetes_cluster_node_pool 設定為 main.tf,以更新 fips_enabledtrue 中的資源。

    resource "azurerm_kubernetes_cluster_node_pool" "example" {
      name                   = "np"
      kubernetes_cluster_id  = azurerm_kubernetes_cluster.example.id
      vm_size                = "Standard_D2s_v3"
      os_type                = "Linux"
      os_sku                 = "Ubuntu"
      node_count             = 3
      fips_enabled           = true
    }
    
  2. 請使用 terraform plan and terraform apply 指令套用更新後的 Terraform 設定。 Terraform 偵測到對fips_enabled的變更並觸發必要的重新安裝映像作業。

    terraform plan
    terraform apply
    
  3. 使用 [az aks get-credentials][az-aks-get-credentials] 指令連接到 AKS 叢集。

    az aks get-credentials \
        --resource-group myResourceGroup \
        --name myAKSCluster
    
  4. 請使用 az aks show 指令,在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池是否啟用了 FIPS。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    

    下列範例輸出顯示 np 節點集區已啟用 FIPS:

    Name       enableFips
    ---------  ------------
    np         True
    nodepool1  False  
    

在現有節點集區上停用 FIPS

你可以更新現有的 Linux 節點池來停用 FIPS。 更新現有的節點集區時,節點映像會從目前的 FIPS 映像變更為相同 OS SKU 的建議的非 FIPS 映像。 節點影像的變更發生在重映像之後。

  1. 使用 az aks nodepool update 帶有 --disable-fips-image 參數的指令更新 Linux 節點池。

    az aks nodepool update \
        --resource-group myResourceGroup \
        --cluster-name myAKSCluster \
        --name np \
        --disable-fips-image
    

    此指令會立即觸發節點池的重映像,以部署符合 FIPS 標準的作業系統。 此重新映像會在節點集區更新期間發生。 不需要額外的步驟。

  2. 使用 az aks show 命令,並在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池沒有啟用 FIPS。

    az aks show \
        --resource-group myResourceGroup \
        --name myAKSCluster \
        --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
        -o table
    

    下列範例輸出顯示 np 節點集區未啟用 FIPS:

    Name       enableFips
    ---------  ------------
    np         False
    nodepool1  False  
    

目前在 Azure 入口網站中不支援在現有的節點集區上停用 FIPS。 要在現有節點池中停用 FIPS,請使用本文中的 Azure CLI、ARM 範本、Bicep 或 Terraform 的說明。

  1. 使用 ARM 範本更新代理池設定檔,將屬性從 enableFips 設定為 false,以關閉現有節點池的 FIPS。 例如:

    {
      "type": "Microsoft.ContainerService/managedClusters/agentPools",
      "name": "[concat(parameters('clusterName'), '/np')]",
      "apiVersion": "2023-03-01",
      "properties": {
        "enableFips": false
      }
    }
    
  2. 請使用 Azure portal、Azure CLI 或 Azure PowerShell 部署更新後的範本。 欲了解更多部署 ARM 範本的資訊,請參閱 「使用 ARM 範本部署資源」。

  3. 使用 az aks show 命令,並在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池沒有啟用 FIPS。

    az aks show \
      --resource-group myResourceGroup \
      --name myAKSCluster \
      --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
      -o table
    

    下列範例輸出顯示 np 節點集區未啟用 FIPS:

    Name       enableFips
    ---------  ------------
    np         False
    nodepool1  False  
    
  1. 使用 Bicep 來停用現有節點池的 FIPS,方法是更新代理池資源,將 enableFIPS 設為 false。 例如:

    param clusterName string
    param nodePoolName string = 'np'
    
    resource nodePool 'Microsoft.ContainerService/managedClusters/agentPools@2023-03-01' = {
      name: '${clusterName}/${nodePoolName}'
      properties: {
        enableFIPS: false
      }
    }
    
  2. 請使用 Azure CLI、Azure PowerShell 或 Azure portal 部署更新後的 Bicep 檔案。 欲了解更多有關部署 Bicep 檔案的資訊,請參閱<使用 Visual Studio Code 建立 Bicep 檔案>。

  3. 使用 az aks show 命令,並在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池沒有啟用 FIPS。

    az aks show \
      --resource-group myResourceGroup \
      --name myAKSCluster \
      --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
      -o table
    

    下列範例輸出顯示 np 節點集區未啟用 FIPS:

    Name       enableFips
    ---------  ------------
    np         False
    nodepool1  False  
    
  1. 將 azurerm_kubernetes_cluster_node_pool 設定為 main.tf,以更新 fips_enabledfalse 中的資源。

    resource "azurerm_kubernetes_cluster_node_pool" "example" {
      name                   = "np"
      kubernetes_cluster_id  = azurerm_kubernetes_cluster.example.id
      vm_size                = "Standard_D2s_v3"
      os_type                = "Linux"
      os_sku                 = "Ubuntu"
      node_count             = 3
      fips_enabled           = false
    }
    
  2. 請使用 terraform plan and terraform apply 指令套用更新後的 Terraform 設定。 Terraform 偵測到對fips_enabled的變更並觸發必要的重新安裝映像作業。

    terraform plan
    terraform apply
    
  3. 使用 az aks show 命令,並在 agentPoolProfiles 中查詢 enableFIPS 值,以確認你的節點池沒有啟用 FIPS。

    az aks show \
      --resource-group myResourceGroup \
      --name myAKSCluster \
      --query="agentPoolProfiles[].{Name:name enableFips:enableFips}" \
      -o table
    

    下列範例輸出顯示 np 節點集區未啟用 FIPS:

    Name       enableFips
    ---------  ------------
    np         False
    nodepool1  False  
    

今日訊息

你可以在建立叢集或新增節點池時,使用 Linux 節點的旗標替換每日--message-of-the-day(MOTD)。

使用 az aks create 命令建立叢集,並設 --message-of-the-day 旗標為新 MOTD 檔案路徑以替換當日訊息。

az aks create --cluster-name myAKSCluster --resource-group myResourceGroup --message-of-the-day ./newMOTD.txt

新增一個節點池,並使用 az aks nodepool add 命令,設置 --message-of-the-day 參數為新的 MOTD 檔案路徑,以替換每日訊息。

az aks nodepool add --name mynodepool1 --cluster-name myAKSCluster --resource-group myResourceGroup --message-of-the-day ./newMOTD.txt