Bug 1258041 - RFE: Network isolation for multi-tenant OSE 3 environment.
Summary: RFE: Network isolation for multi-tenant OSE 3 environment.
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: RFE
Version: 3.0.0
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
: ---
Assignee: Mike Barrett
QA Contact: Meng Bo
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2015-08-28 18:06 UTC by Ali Sogukpinar
Modified: 2019-12-16 04:54 UTC (History)
9 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-11-23 14:25:54 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Ali Sogukpinar 2015-08-28 18:06:45 UTC
3. What is the nature and description of the request?  

At the moment OSE has a flat network structure and any POD can access to the any service available. However, flat network structure is not always acceptable for a multi-tenant environment. For some use-cases it is a requirement to have isolation of traffic from a specific tenant.

    4. Why does the customer need this? (List the business requirements here)  
Isolation of traffic from different tenants.

    5. How would the customer like to achieve this? (List the functional requirements here)  
	
    6. For each functional requirement listed, specify how Red Hat and the customer can test to confirm the requirement is successfully implemented.  
Pods from different tenants cannot reach Pods and services from other tenants.	
      
    7. Is there already an existing RFE upstream or in Red Hat Bugzilla?  
	No      

    8. Does the customer have any specific timeline dependencies and which release would they like to target (i.e. RHEL5, RHEL6)?  
       Before end of 2015

    9. Is the sales team involved in this request and do they have any additional input?  
      	Yes

    10. List any affected packages or components.  
    11. Would the customer be able to assist in testing this functionality if implemented?  
	Yes

Comment 5 Mike Barrett 2015-09-30 16:10:42 UTC
Network isolation at the project layer is shipping in OSE 3.1.  The platform admin will be able to turn on the isolation plugin on the nodes and any project created from that point forward will be isolated from each other.  There will remain a concept of a global network namespace so that services like the router can still route services in and out of the PaaS for the project.

Comment 7 Meng Bo 2015-10-19 07:36:29 UTC
Multi-tenant networking plugin is supported in OSE now.

Comment 8 Brenton Leanhardt 2015-11-23 14:25:54 UTC
This fix is available in OpenShift Enterprise 3.1.


Note You need to log in before you can comment on or make changes to this bug.