Session
Securing Azure Kubernetes Service (AKS): Network Policies, Private Clusters & Pod Security
AKS security is often treated as an extension of general Azure network security. Still, Kubernetes networking has its own model, its own failure modes, and its own set of tools — and getting it wrong can undermine every other security control in the environment.
This advanced session is built for platform and security engineers who need a comprehensive understanding of securing AKS networking.
We'll start by comparing AKS networking models — kubenet, Azure CNI, and CNI Overlay — and the security and scalability trade-offs of each.
From there, we dive into Kubernetes Network Policies, comparing Azure's native Network Policy Manager with Calico, and showing how to enforce pod-to-pod and namespace-level segmentation that mirrors the micro-segmentation principles used at the VNet layer.
We'll cover private AKS cluster architecture in depth, including how API server access works when the control plane has no public endpoint, and the DNS considerations that come with it. The session also addresses identity: comparing Workload Identity (the modern, recommended approach) against legacy pod-managed identities, and why this choice matters for both security and operational simplicity.
A demo session with cluster security settings.
Santhoshkumar Anandakrishnan
Lead Cloud Architect
Melbourne, Australia
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top