Kubernetes Storage Tenant Isolation via Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In hyper-converged infrastructure (HCI) using Kubernetes, the existing storage systems face challenges in securely separating storage volumes across multiple Kubernetes clusters, leading to operation errors and security risks due to shared access.
Innovation Solution
An information processing system with a management unit that creates tenants and assigns node clusters and storage resources, controlling access based on tenant assignments to ensure secure separation of volumes across multiple node clusters.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a single HCI cluster is constructed to share storage resources among multiple Kubernetes clusters, then resource utilization and productivity are improved, but security risks and operational errors increase due to unauthorized access between clusters
Solution Approach 1:
The patent segments the storage system by introducing tenant IDs that logically divide the shared storage into isolated namespaces for different Kubernetes clusters. Each tenant ID creates a virtual boundary that allows physical sharing while maintaining logical separation, thus improving resource utilization without compromising security.
Solution Approach 2:
The patent introduces an intermediary access control mechanism that mediates between multiple Kubernetes clusters and the shared storage system. This intermediary layer validates tenant IDs and enforces access policies, enabling secure multi-tenant sharing without requiring separate physical storage systems for each cluster.
2Ease of operation
If storage volumes are shared across multiple Kubernetes clusters without access control, then ease of operation is improved, but security risks and unauthorized access increase
Solution Approach 1:
The patent applies local quality by associating specific tenant IDs with specific Kubernetes clusters, creating localized access rights. This allows each cluster to have unrestricted access to its designated storage volumes while maintaining security boundaries, thus preserving ease of operation for authorized users while preventing unauthorized access.
3Reliability
If separate HCI clusters are constructed for each Kubernetes cluster to ensure security, then security is improved, but device complexity and division loss increase
Solution Approach 1:
The patent makes the storage system universal by designing it to serve multiple Kubernetes clusters simultaneously through the multi-tenant architecture. A single HCI cluster can function as the storage provider for multiple clusters, eliminating the need for separate storage infrastructures and reducing overall system complexity while maintaining security through tenant isolation.
Data Source
AI summary
An object of the invention is to appropriately separate an available cluster for each user in a storage system configured by using a plurality of clusters each of which is an aggregate of nodes. A computer system includes a plurality of K8s clusters each configured by one or a plurality of K8s nodes, a storage that provides a volume, and a tenant management unit that manages the plurality of the K8s clusters and the storage. The tenant management unit creates, in the storage, a plurality of tenants respectively corresponding to the plurality of the K8s clusters. The storage, for each of the plurality of the K8s clusters, permits access from the K8s cluster to a tenant corresponding to the K8s cluster and prohibits access from the K8s cluster to a tenant not corresponding to the K8s cluster.


