Microsoft plugs Active Directory authentication into AKS on Azure Stack HCI

Begone foul stash for the secret hash


Microsoft has issued an update for its Azure Kubernetes Service on Azure Stack HCI software that adds integration with Active Directory.

Rolled out in preview form last year, the arrival of the Azure Kubernetes Service (AKS) on Azure Stack HCI was aimed directly at customers leery of Microsoft's public cloud. The arrival of AKS-HCI meant that developers got, in theory, a consistent AKS experience over cloud and the resolutely on-premises world of Azure Stack HCI. Hybrid indeed.

However, although Microsoft cheerfully trumpeted the security strengths of AKS-HCI at the launch of the public preview, it admitted several were not quite ready for public consumption, "these and more will be released in the lead-up to general availability."

Enter the Active Directory (AD) integration, which has arrived in the February update. The addition to the public preview brings single sign on via AD authentication using kubectl rather than certificate-based client authentication.

"Think of AD kubeconfig as a type of kubeconfig," said Microsoft, referring to the configuration stored on the client to connect to the api-server. As a default, AKS-HCI uses certificate-based kubeconfig, containing the likes of private keys.

"If malware or attacker gets access to this configuration file," the company admitted, "they will be able to get access to the api-server and that would be like getting keys to the kingdom."

Microsoft's view of the cloud workforce

Azure Stack will need special sysadmins, says Microsoft

READ MORE

Hence the advantages of AD kubeconfig. While the certificate-based approach is still available, "the AD kubeconfig can be freely distributed without any security concerns to a wider group of users."

The Windows server or container host don't even need to be domain-joined to use the functionality, as long as the domain server and container host are time synchronised.

Making use of the Kerberos protocol, it's a useful update if you've bought into the Microsoft way of doing things (and if you're using Azure Stack HCI, you probably have.)

The update also ditches the need for a DHCP server and supports completely static IP environments, and, for those keen to check out AKS-HCI but less keen on the spending cash on hardware just for a test drive, a guide on how to bring the system up on an Azure VM is also available. ®


Other stories you might like

  • Monero-mining botnet targets Windows, Linux web servers
    Sysrv-K malware infects unpatched tin, Microsoft warns

    The latest variant of the Sysrv botnet malware is menacing Windows and Linux systems with an expanded list of vulnerabilities to exploit, according to Microsoft.

    The strain, which Microsoft's Security Intelligence team calls Sysrv-K, scans the internet for web servers that have security holes, such as path traversal, remote file disclosure, and arbitrary file download bugs, that can be exploited to infect the machines.

    The vulnerabilities, all of which have patches available, include flaws in WordPress plugins such as the recently uncovered remote code execution hole in the Spring Cloud Gateway software tracked as CVE-2022-22947 that Uncle Sam's CISA warned of this week.

    Continue reading
  • Red Hat Kubernetes security report finds people are the problem
    Puny human brains baffled by K8s complexity, leading to blunder fears

    Kubernetes, despite being widely regarded as an important technology by IT leaders, continues to pose problems for those deploying it. And the problem, apparently, is us.

    The open source container orchestration software, being used or evaluated by 96 per cent of organizations surveyed [PDF] last year by the Cloud Native Computing Foundation, has a reputation for complexity.

    Witness the sarcasm: "Kubernetes is so easy to use that a company devoted solely to troubleshooting issues with it has raised $67 million," quipped Corey Quinn, chief cloud economist at IT consultancy The Duckbill Group, in a Twitter post on Monday referencing investment in a startup called Komodor. And the consequences of the software's complication can be seen in the difficulties reported by those using it.

    Continue reading
  • Infosys skips government meeting – and collecting government taxes
    Tax portal wobbles, again

    Services giant Infosys has had a difficult week, with one of its flagship projects wobbling and India's government continuing to pressure it over labor practices.

    The wobbly projext is India's portal for filing Goods and Services Tax returns. According to India's Central Board of Indirect Taxes and Customs (CBIC), the IT services giant reported a "technical glitch" that meant auto-populated forms weren't ready for taxpayers. The company was directed to fix it and CBIC was faced with extending due dates for tax payments.

    Continue reading
  • Google keeps legacy G Suite alive and free for personal use
    Phew!

    Google has quietly dropped its demand that users of its free G Suite legacy edition cough up to continue enjoying custom email domains and cloudy productivity tools.

    This story starts in 2006 with the launch of “Google Apps for Your Domain”, a bundle of services that included email, a calendar, Google Talk, and a website building tool. Beta users were offered the service at no cost, complete with the ability to use a custom domain if users let Google handle their MX record.

    The service evolved over the years and added more services, and in 2020 Google rebranded its online productivity offering as “Workspace”. Beta users got most of the updated offerings at no cost.

    Continue reading
  • GNU Compiler Collection adds support for China's LoongArch CPU family
    MIPS...ish is on the march in the Middle Kingdom

    Version 12.1 of the GNU Compiler Collection (GCC) was released this month, and among its many changes is support for China's LoongArch processor architecture.

    The announcement of the release is here; the LoongArch port was accepted as recently as March.

    China's Academy of Sciences developed a family of MIPS-compatible microprocessors in the early 2000s. In 2010 the tech was spun out into a company callled Loongson Technology which today markets silicon under the brand "Godson". The company bills itself as working to develop technology that secures China and underpins its ability to innovate, a reflection of Beijing's believe that home-grown CPU architectures are critical to the nation's future.

    Continue reading

Biting the hand that feeds IT © 1998–2022