Skip to content

Azure Monitor Container Insights add-on use nodes/proxy permission #5752

@rashmichandrashekar

Description

@rashmichandrashekar

More here: https://learn.microsoft.com/azure/aks/security-bulletins/overview#aks-2026-0003-azure-monitor-container-insights-add-on-removes-use-of-nodesproxy-permission

A public disclosure described how the Kubernetes nodes/proxy GET permission can be abused to execute commands in any pod on a reachable node via the Kubelet API (port 10250). The Kubernetes Security Team determined this is working as intended; the long-term mitigation is KEP-2862, which is GA in Kubernetes v1.33.

The Azure Monitor Container Insights add-on (ama-logs) uses nodes/proxy on AKS causing security risk.

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions