Kubernetes Storage Tenant Isolation via Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In hyper-converged infrastructure (HCI) using Kubernetes, the existing storage systems face challenges in securely separating storage volumes across multiple Kubernetes clusters, leading to operation errors and security risks due to shared access.

Innovation Solution

An information processing system with a management unit that creates tenants and assigns node clusters and storage resources, controlling access based on tenant assignments to ensure secure separation of volumes across multiple node clusters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a single HCI cluster is constructed to share storage resources among multiple Kubernetes clusters, then resource utilization and productivity are improved, but security risks and operational errors increase due to unauthorized access between clusters

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the storage system by introducing tenant IDs that logically divide the shared storage into isolated namespaces for different Kubernetes clusters. Each tenant ID creates a virtual boundary that allows physical sharing while maintaining logical separation, thus improving resource utilization without compromising security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary access control mechanism that mediates between multiple Kubernetes clusters and the shared storage system. This intermediary layer validates tenant IDs and enforces access policies, enabling secure multi-tenant sharing without requiring separate physical storage systems for each cluster.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If storage volumes are shared across multiple Kubernetes clusters without access control, then ease of operation is improved, but security risks and unauthorized access increase

Engineering Contradiction:
Improvestorage accessibilityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by associating specific tenant IDs with specific Kubernetes clusters, creating localized access rights. This allows each cluster to have unrestricted access to its designated storage volumes while maintaining security boundaries, thus preserving ease of operation for authorized users while preventing unauthorized access.

Inventive Principle:
Principle #3Local quality

3Reliability

If separate HCI clusters are constructed for each Kubernetes cluster to ensure security, then security is improved, but device complexity and division loss increase

Engineering Contradiction:
ImprovesecurityVSAvoidcluster management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the storage system universal by designing it to serve multiple Kubernetes clusters simultaneously through the multi-tenant architecture. A single HCI cluster can function as the storage provider for multiple clusters, eliminating the need for separate storage infrastructures and reducing overall system complexity while maintaining security through tenant isolation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12105824B2Information processing system for managing data storage and retrieval and method
Publication Date: 2024.10.01 HITACHI VANTARA LTD
  • US12105824B2 patent drawing
  • US12105824B2 patent drawing
  • US12105824B2 patent drawing

AI summary

An object of the invention is to appropriately separate an available cluster for each user in a storage system configured by using a plurality of clusters each of which is an aggregate of nodes. A computer system includes a plurality of K8s clusters each configured by one or a plurality of K8s nodes, a storage that provides a volume, and a tenant management unit that manages the plurality of the K8s clusters and the storage. The tenant management unit creates, in the storage, a plurality of tenants respectively corresponding to the plurality of the K8s clusters. The storage, for each of the plurality of the K8s clusters, permits access from the K8s cluster to a tenant corresponding to the K8s cluster and prohibits access from the K8s cluster to a tenant not corresponding to the K8s cluster.