Bug 1258041 - RFE: Network isolation for multi-tenant OSE 3 environment.
RFE: Network isolation for multi-tenant OSE 3 environment.
Product: OpenShift Container Platform
Classification: Red Hat
Component: RFE (Show other bugs)
Unspecified Unspecified
unspecified Severity unspecified
: ---
: ---
Assigned To: Mike Barrett
Meng Bo
Depends On:
  Show dependency treegraph
Reported: 2015-08-28 14:06 EDT by Ali Sogukpinar
Modified: 2017-03-08 13 EST (History)
9 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2015-11-23 09:25:54 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Ali Sogukpinar 2015-08-28 14:06:45 EDT
3. What is the nature and description of the request?  

At the moment OSE has a flat network structure and any POD can access to the any service available. However, flat network structure is not always acceptable for a multi-tenant environment. For some use-cases it is a requirement to have isolation of traffic from a specific tenant.

    4. Why does the customer need this? (List the business requirements here)  
Isolation of traffic from different tenants.

    5. How would the customer like to achieve this? (List the functional requirements here)  
    6. For each functional requirement listed, specify how Red Hat and the customer can test to confirm the requirement is successfully implemented.  
Pods from different tenants cannot reach Pods and services from other tenants.	
    7. Is there already an existing RFE upstream or in Red Hat Bugzilla?  

    8. Does the customer have any specific timeline dependencies and which release would they like to target (i.e. RHEL5, RHEL6)?  
       Before end of 2015

    9. Is the sales team involved in this request and do they have any additional input?  

    10. List any affected packages or components.  
    11. Would the customer be able to assist in testing this functionality if implemented?  
Comment 5 Mike Barrett 2015-09-30 12:10:42 EDT
Network isolation at the project layer is shipping in OSE 3.1.  The platform admin will be able to turn on the isolation plugin on the nodes and any project created from that point forward will be isolated from each other.  There will remain a concept of a global network namespace so that services like the router can still route services in and out of the PaaS for the project.
Comment 7 Meng Bo 2015-10-19 03:36:29 EDT
Multi-tenant networking plugin is supported in OSE now.
Comment 8 Brenton Leanhardt 2015-11-23 09:25:54 EST
This fix is available in OpenShift Enterprise 3.1.

Note You need to log in before you can comment on or make changes to this bug.