Unsolved
1 Rookie
•
3 Posts
0
1963
January 30th, 2020 04:00
CSI dynamic provisioning in a multitenancy model
Hello, we plan to buy a unity 380f and after reviewing the csi site (https://github.com/dell/csi-unity/) I couldn't see anything related to chap authentication and/or multitenancy features.
In our usage case we plan to share the control (rest-api) and data plane (iscsi) with multiple customer using a service network and thus, we have to ensure a secure manner of giving to each customer only what belong to them.
Could anybody share if with this product I would be able to:
- Limit visibility of iscsi targets between customer by IP source. For example if a customer create a centos pod into his kubernetes cluster he won't be able to watch targets running a iscsiadm discovery command.
- Limit access to iscsi targets by customer. Being able to do it by means of IP source controls would be good, but being able to set at provision and access stage a chap password would be the best.
Looking forward for your help.
Thanks in advance.
-David
No Events found!