A software-as-a-service (SaaS) provider is designing its Zero Trust architecture. They host multiple customer tenants within a shared Azure Kubernetes Service (AKS) cluster. A critical requirement is to ensure that while resources are shared, each customer's data and applications are strictly isolated from other tenants, with no possibility of cross-tenant data leakage or unauthorized access, even in the event of a compromise in an adjacent tenant. Which architectural approach is MOST effective for achieving this stringent isolation in a multi-tenant AKS environment?
- AUtilizing Kubernetes Network Policies to segment traffic within the cluster.
- BImplementing network security groups (NSGs) at the subnet level for the AKS cluster.
- CDeploying separate AKS clusters for each customer tenant.
- DEnforcing identity-based micro-segmentation using service mesh technologies.
Show answer & explanationAnswer & explanation
Correct answer: D. Enforcing identity-based micro-segmentation using service mesh technologies.
Identity-based micro-segmentation, often achieved with service mesh technologies, provides the most granular and robust isolation in a multi-tenant AKS cluster. It enforces policies at the workload (pod/service) level based on cryptographic identities, ensuring that even if a network segment is compromised, unauthorized communication between tenants is prevented, aligning with Zero Trust's 'Assume Breach' and 'Least Privilege' principles.
Why the other options are wrong
- A. Kubernetes Network Policies provide pod-level network segmentation but are still primarily IP-based and do not inherently provide cryptographic identity-based isolation or advanced traffic management features of a service mesh.
- B. NSGs operate at the network layer (Layer 3/4) and are too coarse-grained for strict isolation within a shared AKS cluster and do not provide identity-based enforcement.
- C. Deploying separate AKS clusters for each tenant provides strong isolation but is often cost-prohibitive and operationally complex for a SaaS provider with many tenants. The question asks for an approach *within* a shared cluster.
Identity-Based Micro-segmentation (AKS Multi-tenant)
A security approach that enforces granular network access policies between individual workloads (e.g., pods) within a shared Kubernetes cluster based on cryptographic identities.
- Enforces 'least privilege' at the workload level.
- Uses cryptographic identities for authentication and authorization.
- Prevents lateral movement and cross-tenant data leakage in shared environments.
Memory trick: Identity micro-segmentation: Each pod has its own secure ID.