<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Best practice/recommendations - k8s multitenancy and encryption of data in-flight/at rest, OnTap SVM in General Discussion</title>
    <link>https://community.netapp.com/t5/General-Discussion/Best-practice-recommendations-k8s-multitenancy-and-encryption-of-data-in-flight/m-p/155178#M784</link>
    <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;I wasn't sure where to ask/discuss these topics but I'll post it here and see if I'm recommended to put this somewhere else...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Background&lt;/P&gt;
&lt;P&gt;I'm currently looking for best practices with regards to k8s multitenancy and data encryption. We're looking at a three k8s-cluster solution maintained by Rancher.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Multi tenancy&lt;/P&gt;
&lt;P&gt;I was thinking of solving multi-tenancy using a combination of namespaces, RBACs, Network/POD security policies, taints et c.&amp;nbsp; I fooled around with Trident last year for a month or two together with OnTap Select before the project was put on a hold, and now restarted... I remember using k8s "storage resource quotas" for limiting SC access between namespaces but I think this will result in a "maintenance nightmare" when the number of customers/namespaces increase. I'd like to see if there are any updated best practices, from a Trident/NetApp SVM perspective as of how to approach the multitenancy question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Data encryption data in-flight/at rest&lt;/P&gt;
&lt;P&gt;We have some required requirement fulfilments regarding encryption of data in-flight and at-rest. The underlying storage is NetApp cDOT (unsure of the current version(s)). As FS-protocol we have the possibility to use NFSv4. Any recommendations/best practices regarding encryption, pros and cons would be great and tremendously appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the k8s world the options are, almost, limitless and indications as of how to approach topics like these are great input in the following discussions/designs...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks!&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 11:15:02 GMT</pubDate>
    <dc:creator>Litsegaard</dc:creator>
    <dc:date>2025-06-04T11:15:02Z</dc:date>
    <item>
      <title>Best practice/recommendations - k8s multitenancy and encryption of data in-flight/at rest, OnTap SVM</title>
      <link>https://community.netapp.com/t5/General-Discussion/Best-practice-recommendations-k8s-multitenancy-and-encryption-of-data-in-flight/m-p/155178#M784</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;I wasn't sure where to ask/discuss these topics but I'll post it here and see if I'm recommended to put this somewhere else...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Background&lt;/P&gt;
&lt;P&gt;I'm currently looking for best practices with regards to k8s multitenancy and data encryption. We're looking at a three k8s-cluster solution maintained by Rancher.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Multi tenancy&lt;/P&gt;
&lt;P&gt;I was thinking of solving multi-tenancy using a combination of namespaces, RBACs, Network/POD security policies, taints et c.&amp;nbsp; I fooled around with Trident last year for a month or two together with OnTap Select before the project was put on a hold, and now restarted... I remember using k8s "storage resource quotas" for limiting SC access between namespaces but I think this will result in a "maintenance nightmare" when the number of customers/namespaces increase. I'd like to see if there are any updated best practices, from a Trident/NetApp SVM perspective as of how to approach the multitenancy question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Data encryption data in-flight/at rest&lt;/P&gt;
&lt;P&gt;We have some required requirement fulfilments regarding encryption of data in-flight and at-rest. The underlying storage is NetApp cDOT (unsure of the current version(s)). As FS-protocol we have the possibility to use NFSv4. Any recommendations/best practices regarding encryption, pros and cons would be great and tremendously appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the k8s world the options are, almost, limitless and indications as of how to approach topics like these are great input in the following discussions/designs...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 11:15:02 GMT</pubDate>
      <guid>https://community.netapp.com/t5/General-Discussion/Best-practice-recommendations-k8s-multitenancy-and-encryption-of-data-in-flight/m-p/155178#M784</guid>
      <dc:creator>Litsegaard</dc:creator>
      <dc:date>2025-06-04T11:15:02Z</dc:date>
    </item>
  </channel>
</rss>

