Working with the VNET Injection add a feature to put the API Server on an internal vnet. https://learn.microsoft.com/en-us/azure/aks/api-server-vnet-integration