A private AKS cluster places the API server behind a private endpoint in the node resource group's virtual network, removing any public-facing endpoint. When the cluster is configured with the Azure CNI network plugin, every pod receives an IP address from the virtual network subnet, allowing direct, routable communication to other resources in that subnet without requiring SNAT. Public clusters with authorized IP ranges still expose the API server over the Internet, Kubenet relies on source NAT for pod egress, and an Application Gateway Ingress Controller secures application ingress but does not hide the control-plane endpoint.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Azure CNI network plugin?
Open an interactive chat with Bash
How does a private AKS cluster differ from a public AKS cluster?
Open an interactive chat with Bash
Why does Kubenet require SNAT for pod communication?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .