CHƯƠNG 08 AZ-500 5 labs Secure Compute, Storage & Databases 20–25%

Secure Compute, Containers & App Services

Azure Bastion, JIT VM Access, Disk Encryption, AKS Security, ACR — bảo vệ toàn diện workload máy chủ, container và ứng dụng web trên Azure.

🎯 Mục Tiêu Chương

  • Bảo mật remote access tới VM bằng Azure Bastion và JIT.
  • Cấu hình disk encryption các cấp độ khác nhau.
  • Bảo mật AKS cluster với Entra ID và network policy.
  • Kiểm soát truy cập Azure Container Registry an toàn.
  • Bảo mật App Service và API Management.

📚 Nội Dung Chi Tiết

8.1 Virtual Machine Security

Nguyên tắc vàng: VM không nên expose RDP/SSH port trực tiếp ra Internet. Azure cung cấp 2 cơ chế bảo vệ remote access chính.

Azure Bastion
  • • Truy cập RDP/SSH qua Azure Portal — không cần public IP trên VM
  • • Deploy vào subnet AzureBastionSubnet (/26 tối thiểu)
  • Basic SKU: HTML5 browser only
  • Standard SKU: file transfer, shareable link, IP-based connection
  • • Không cần NSG đặc biệt trên VM subnet
Just-in-Time VM Access
  • • Yêu cầu Defender for Servers Plan 2
  • • Port RDP/SSH bị block mặc định (NSG deny)
  • • User request access → NSG allow tạm thời theo IP nguồn
  • • Auto-close sau thời gian quy định (mặc định 3 giờ)
  • • Log đầy đủ ai request, khi nào, từ IP nào
Disk Encryption — 3 cấp độ
Azure Disk Encryption

BitLocker (Windows) / DM-Crypt (Linux). Key lưu trong Key Vault. Mã hóa OS và data disk.

Encryption at Host

Mã hóa trên host server, bao gồm cả temp disk và cache. Không qua Key Vault agent. Toàn diện hơn ADE.

Confidential Disk Encryption

Dành cho Confidential VMs. Key gắn với TPM của VM — ngay cả Microsoft operator không đọc được.

8.2 AKS Security

Azure Kubernetes Service cần bảo mật ở nhiều lớp: authentication, authorization, network và image security.

Authentication & Authorization
  • Microsoft Entra integration: dùng Entra identity để kubectl
  • Azure RBAC for Kubernetes: gán role trực tiếp trên cluster
  • Kubernetes RBAC: ClusterRole, RoleBinding nội bộ
  • • Workload Identity thay cho pod managed identity (2026)
Network Security
  • Network Policy: kiểm soát pod-to-pod traffic (Calico/Azure)
  • Private AKS Cluster: API server không expose public
  • • Defender for Containers: runtime threat detection
  • • Image scanning: Microsoft Defender Vulnerability Management
2026 — Microsoft Entra Workload Identity: Thay thế aad-pod-identity và pod managed identity cũ. Pod được cấp federated credential qua OIDC, không cần secret tĩnh hay sidecar. Đây là best practice hiện tại cho AKS workloads truy cập Azure resources.

8.3 Azure Container Registry

RBAC thay vì Admin User
  • Tắt admin user — không dùng username/password tĩnh
  • AcrPull: gán cho AKS/App Service để pull image
  • AcrPush: gán cho CI/CD pipeline managed identity
  • AcrDelete: chỉ admin cần, restrict tối đa
Content Trust & Network
  • • Private endpoint để tắt public registry access
  • • Geo-replication cho multi-region availability
  • • Vulnerability scanning tích hợp Defender
  • • Retention policy cho untagged manifests

8.5 App Service & API Management Security

Authentication (Easy Auth)

Tích hợp Microsoft Entra ID không cần code. Cấu hình qua Portal → Authentication. Hỗ trợ Google, Facebook, Twitter, GitHub.

TLS & Managed Identity

Enforce HTTPS only, minimum TLS 1.2. Dùng Managed Identity (system hoặc user-assigned) để truy cập Key Vault, SQL, Storage — không lưu secret trong app settings.

API Management

Subscription key bắt buộc. Client certificate authentication. OAuth 2.0/JWT validation policy. Rate limiting và IP filter.

🧪 Lab Trong Chương

✅ Checklist Cuối Chương

  • Truy cập VM qua Azure Bastion (không cần public IP).
  • Cấu hình được JIT VM Access và test request/auto-close.
  • Phân biệt ADE, Encryption at Host, Confidential Disk Encryption.
  • Bảo mật AKS cơ bản: Entra integration, network policy.
  • Bảo mật ACR: tắt admin, dùng RBAC, private endpoint.
Zalo