Professional Cloud ArchitectDesign for security and complianceHard
A SaaS provider is building a multi-tenant application on Google Cloud. Each tenant's data must be logically isolated from other tenants, and the provider needs to ensure that access to each tenant's data is strictly controlled, even by administrators. They want to use a combination of Google Cloud services to achieve robust logical isolation and access control for tenant data, while minimizing operational overhead. Which combination of services provides the strongest logical isolation and access control for multi-tenant data in Google Cloud?
- ASeparate Cloud Storage buckets per tenant and IAM service accounts.
- BSeparate projects per tenant and IAM policies.
- CSeparate GKE namespaces per tenant and Kubernetes RBAC.
- DSeparate VPC networks per tenant and network firewall rules.
Show answer & explanationAnswer & explanation
Correct answer: B. Separate projects per tenant and IAM policies.
Separate projects per tenant provide the strongest logical isolation boundary at the Google Cloud resource hierarchy level. IAM policies applied at the project level ensure that access to all resources within a tenant's project is strictly controlled and isolated from other tenants, even for administrators with broader organizational roles.
Why the other options are wrong
- A. While separate Cloud Storage buckets provide data isolation, they reside within a project, making project-level administrators potentially able to access all buckets.
- C. GKE namespaces and RBAC provide isolation within a Kubernetes cluster, but this is a lower level of isolation than a full Google Cloud project and does not isolate other non-Kubernetes resources.
- D. Separate VPC networks provide network isolation but don't inherently isolate other Google Cloud resources like databases or storage, which can still be accessed across networks if IAM permits.
Google Cloud Resource Hierarchy for Isolation
The Google Cloud resource hierarchy (Organization > Folders > Projects > Resources) provides natural boundaries for logical isolation and access control, with Projects offering the strongest isolation for multi-tenant architectures.
- Projects serve as fundamental billing and resource grouping units.
- IAM policies are inherited down the hierarchy, but project boundaries are strong.
- Separating tenants by project offers robust logical isolation and access control.
Memory trick: Projects Protect Tenants, Each with its Own Place.