A SaaS provider is launching a new multi-tenant application where each tenant requires strong data isolation and dedicated compute resources to avoid the 'noisy neighbor' problem and meet strict compliance requirements. Tenants also need to be able to customize their environment without impacting others. The solution must be highly available and scalable. Which multi-tenancy model and corresponding AWS architecture should the company adopt?
- ABridged multi-tenancy, using shared Amazon EC2 instances with separate VPCs for each tenant.
- BPooled multi-tenancy, using a shared Amazon ECS cluster with task-level isolation for each tenant.
- CSiloed multi-tenancy, using separate AWS accounts for each tenant managed by AWS Organizations.
- DTiered multi-tenancy, using a shared Amazon EKS cluster with namespace-level isolation for each tenant.
Show answer & explanationAnswer & explanation
Correct answer: C. Siloed multi-tenancy, using separate AWS accounts for each tenant managed by AWS Organizations.
Siloed multi-tenancy, specifically using separate AWS accounts for each tenant managed by AWS Organizations, provides the strongest data isolation and dedicated compute resources. This approach completely eliminates the 'noisy neighbor' problem, meets strict compliance requirements by physically separating resources, and allows for tenant-specific customizations without cross-tenant impact. It also inherently offers high availability and scalability at the account level.
Why the other options are wrong
- A. Separate VPCs provide network isolation but sharing EC2 instances still introduces the 'noisy neighbor' problem at the compute level and weaker data isolation. Bridged multi-tenancy is not a standard model.
- B. Pooled multi-tenancy with a shared ECS cluster provides logical isolation but not the strong physical isolation or dedicated compute resources required to avoid the 'noisy neighbor' problem and meet strict compliance.
- D. Namespace-level isolation in EKS provides logical separation within a shared cluster, but it does not offer the same strong physical isolation and dedicated compute resources as separate AWS accounts for strict compliance and avoiding the 'noisy neighbor' problem.
Siloed Multi-Tenancy
A multi-tenancy model where each tenant has completely separate, dedicated instances of the application and underlying infrastructure, often in separate AWS accounts.
- Provides the highest level of isolation and security.
- Eliminates the 'noisy neighbor' problem.
- Ideal for strict compliance and tenant-specific customization.
Memory trick: For ultimate isolation, silo each tenant in their own AWS home.