🎯 Mục Tiêu Chương
- Bảo mật remote access tới VM bằng Azure Bastion và JIT.
- Cấu hình disk encryption các cấp độ khác nhau.
- Bảo mật AKS cluster với Entra ID và network policy.
- Kiểm soát truy cập Azure Container Registry an toàn.
- Bảo mật App Service và API Management.
📚 Nội Dung Chi Tiết
8.1 Virtual Machine Security
Nguyên tắc vàng: VM không nên expose RDP/SSH port trực tiếp ra Internet. Azure cung cấp 2 cơ chế bảo vệ remote access chính.
- • Truy cập RDP/SSH qua Azure Portal — không cần public IP trên VM
- • Deploy vào subnet
AzureBastionSubnet(/26 tối thiểu) - • Basic SKU: HTML5 browser only
- • Standard SKU: file transfer, shareable link, IP-based connection
- • Không cần NSG đặc biệt trên VM subnet
- • Yêu cầu Defender for Servers Plan 2
- • Port RDP/SSH bị block mặc định (NSG deny)
- • User request access → NSG allow tạm thời theo IP nguồn
- • Auto-close sau thời gian quy định (mặc định 3 giờ)
- • Log đầy đủ ai request, khi nào, từ IP nào
BitLocker (Windows) / DM-Crypt (Linux). Key lưu trong Key Vault. Mã hóa OS và data disk.
Mã hóa trên host server, bao gồm cả temp disk và cache. Không qua Key Vault agent. Toàn diện hơn ADE.
Dành cho Confidential VMs. Key gắn với TPM của VM — ngay cả Microsoft operator không đọc được.
8.2 AKS Security
Azure Kubernetes Service cần bảo mật ở nhiều lớp: authentication, authorization, network và image security.
- • Microsoft Entra integration: dùng Entra identity để kubectl
- • Azure RBAC for Kubernetes: gán role trực tiếp trên cluster
- • Kubernetes RBAC: ClusterRole, RoleBinding nội bộ
- • Workload Identity thay cho pod managed identity (2026)
- • Network Policy: kiểm soát pod-to-pod traffic (Calico/Azure)
- • Private AKS Cluster: API server không expose public
- • Defender for Containers: runtime threat detection
- • Image scanning: Microsoft Defender Vulnerability Management
8.3 Azure Container Registry
- • Tắt admin user — không dùng username/password tĩnh
- • AcrPull: gán cho AKS/App Service để pull image
- • AcrPush: gán cho CI/CD pipeline managed identity
- • AcrDelete: chỉ admin cần, restrict tối đa
- • Private endpoint để tắt public registry access
- • Geo-replication cho multi-region availability
- • Vulnerability scanning tích hợp Defender
- • Retention policy cho untagged manifests
8.5 App Service & API Management Security
Tích hợp Microsoft Entra ID không cần code. Cấu hình qua Portal → Authentication. Hỗ trợ Google, Facebook, Twitter, GitHub.
Enforce HTTPS only, minimum TLS 1.2. Dùng Managed Identity (system hoặc user-assigned) để truy cập Key Vault, SQL, Storage — không lưu secret trong app settings.
Subscription key bắt buộc. Client certificate authentication. OAuth 2.0/JWT validation policy. Rate limiting và IP filter.
🧪 Lab Trong Chương
Triển khai Azure Bastion
Truy cập VM không cần public IP qua Bastion host trong AzureBastionSubnet.
Just-in-Time VM Access
Mở port quản trị theo yêu cầu, NSG rule tự đóng sau thời gian quy định.
Encryption at Host cho VM
Bật mã hóa tại host bao gồm temp disk và cache, so sánh với Azure Disk Encryption.
Cấu hình bảo mật AKS
Bật Entra integration, Azure RBAC cho Kubernetes, network policy, kiểm tra quyền truy cập.
Bảo mật Azure Container Registry
Tắt admin user, gán AcrPull cho AKS/managed identity, cấu hình private endpoint, kiểm tra pull image.
✅ Checklist Cuối Chương
- Truy cập VM qua Azure Bastion (không cần public IP).
- Cấu hình được JIT VM Access và test request/auto-close.
- Phân biệt ADE, Encryption at Host, Confidential Disk Encryption.
- Bảo mật AKS cơ bản: Entra integration, network policy.
- Bảo mật ACR: tắt admin, dùng RBAC, private endpoint.