Default Configuration Left Enabled
AKS clusters created without explicitly setting local_account_disabled leave the local admin account enabled by default.
Attackers using leaked or shared local admin credentials can gain full cluster control, bypassing Azure AD integration and RBAC protections.
AKS clusters created without explicitly setting local_account_disabled leave the local admin account enabled by default.
Sourcery automatically identifies authorization bypass due to enabled local admin account in aks cluster in terraform and many other security issues in your codebase.