How We Securely Scaled Multi-Tenancy with VCluster, Crossplane... Ilia Medvedev & Kostis Kapelonis

  Рет қаралды 3,668

CNCF [Cloud Native Computing Foundation]

CNCF [Cloud Native Computing Foundation]

Жыл бұрын

How We Securely Scaled Multi-Tenancy with VCluster, Crossplane, and Argo CD - Ilia Medvedev & Kostis Kapelonis, Codefresh
What do you do when RBAC with namespaces aren’t enough to meet your multi-tenancy needs? Namespaces are easy to implement but they generally do not provide the level of isolation that is needed when working with external users. Instead of running multiple clusters, which are complex to manage, hard to scale and often costly, we turned to vCluster. vCluster is an open source project that allows you to create virtual clusters in any Kubernetes cluster. Virtual clusters enjoy higher isolation than simple namespaces and can also be used for cluster level resources like CRDs without any versioning conflicts. Using virtual clusters in the Codefresh’s hosted GitOps platform that is powered by thousands of Argo instances we enabled high isolation between tenants while lowering the cost of application multi-tenancy. For most companies, multi-tenancy means supporting multiple teams within an organization, or perhaps a partner. For us, multi-tenancy means providing access to the general public. We needed to go deeper than RBAC, namespaces, and auditing. In this end-user talk, we’ll share how we leveraged vCluster, Crossplane, and Argo CD to approach multi-tenancy, scale, and security in a totally GitOps fashion. You’ve never seen vCluster scale like this before!

Пікірлер: 2
@keneanalemayehu6832
@keneanalemayehu6832 3 күн бұрын
This is very interesting, I am thinking of building Heroku like platform as a side project with this exact approach. One thing am not still clear on is the noisy neighbor issue and whether Vcluster is good enough to provide solid isolation.
@austinloveless5171
@austinloveless5171 8 ай бұрын
Super interesting. I'm curious to see a code sample of the composition that deploys the providers onto the other clusters.
Cluster API and GitOps: the key to Kubernetes lifecycle management
1:03:09
CNCF [Cloud Native Computing Foundation]
Рет қаралды 7 М.
Running a multi-tenant platform on a managed Kubernetes cluster
47:52
CNCF [Cloud Native Computing Foundation]
Рет қаралды 3,8 М.
Is it Cake or Fake ? 🍰
00:53
A4
Рет қаралды 14 МЛН
When someone reclines their seat ✈️
00:21
Adam W
Рет қаралды 23 МЛН
Multi-Tenancy in Kubernetes : Three Different Ways
10:48
Loft Labs
Рет қаралды 1 М.
Kubernetes Services networking
7:13
Project Calico
Рет қаралды 78 М.
What is Vcluster ?
41:09
Is it Observable
Рет қаралды 844
The Next Episode in Workload Isolation: Confidential Containers - Jeremi Piotrowski, Microsoft
30:33
CNCF [Cloud Native Computing Foundation]
Рет қаралды 694
How To Create Virtual Kubernetes Clusters With vcluster By loft
22:00
DevOps Toolkit
Рет қаралды 10 М.
Learnings From Providing A Platform API With Kubernetes And Crossplane - Hannes Blut & Jan Willies
31:03
CNCF [Cloud Native Computing Foundation]
Рет қаралды 1,4 М.
Multi-Tenancy For Argo Workflows And Argo CD At Adobe - Srinivas Malladi, Adobe
38:06
CNCF [Cloud Native Computing Foundation]
Рет қаралды 4,2 М.
Multi-tenancy architecture | The Backend Engineering Show
25:29
Hussein Nasser
Рет қаралды 39 М.
ЭТОТ ЗАБЫТЫЙ ФЛАГМАН СИЛЬНО ПОДЕШЕВЕЛ! Стоит купить...
12:54
Thebox - о технике и гаджетах
Рет қаралды 157 М.
Дени против умной колонки😁
0:40
Deni & Mani
Рет қаралды 11 МЛН
Карточка Зарядка 📱 ( @ArshSoni )
0:23
EpicShortsRussia
Рет қаралды 714 М.