SaaS Factory (The Series) · Part 2 of 3
SaaS Factory (The Series) — Tenant Isolation: Tenant Isolation Architectures in SaaS (Part 2/3)
In this post, we will continue talking about tenant isolation architectures, detailing each of the common solution components…
Keywords
In this post, we will continue talking about tenant isolation architectures, detailing each of the common solution components, specifically: Security and Connectivity (Tenant Isolation Modeling); Identity, Authentication and Authorization; Monitoring, Logging and Application Performance Management; and Analytics.

Common Components: Security and Connectivity
The first step in any multi-tenant system design is to define a strategy for keeping tenants protected and isolated from one another. This may include security considerations such as defining segregation at the network/storage layer, encrypting data at rest or in transit, securely managing keys and certificates, and even managing application-level security constructs. There are several AWS services you can use to help address security considerations at each level, including AWS CloudHSM, AWS CloudTrail, Amazon VPC, AWS WAF, Amazon Inspector, Amazon CloudWatch and Amazon CloudWatch Logs.
By using native AWS services like these, you can define a model that matches the solution’s security and networking requirements. In addition to native AWS services, many customers also use partner offerings for infrastructure security, with the aim of strengthening their security posture and adding capabilities such as intrusion detection systems (IDS) and intrusion prevention systems (IPS).
Common Components: Identity, Authentication and Authorization
It is important to decide on the user authentication and authorization strategy for managing AWS services and the SaaS application itself. For AWS services, you can use AWS Identity and Access Management (IAM) users, IAM roles, Amazon Elastic Compute Cloud (Amazon EC2) roles, social identities, directory / LDAP users, and even federated identities using SAML integrations. Likewise, for your application, you have several ways to authenticate users. It is recommended to build a layer that supports your authentication requirements. You can consider authentication based on Amazon Cognito and also delegate authentication management to different identity providers.
Common Components: Monitoring, Logging and Application Performance Management
You should have monitoring enabled at multiple layers, not only to help diagnose problems but also to enable proactive measures to prevent them. You can benefit from using Amazon CloudWatch data, which allows detailed monitoring of critical infrastructure and lets you set up alarms to notify you of any issues. You can also use AWS Config, which provides an inventory of AWS resources, configuration history and configuration change notifications to enable security and governance. For application-level monitoring, you can use Amazon CloudWatch Logs, specifically the ability to stream logs to the service in real time; in addition, you can search for patterns, track the number of errors occurring in your application logs, and configure Amazon CloudWatch to send you a notification whenever the error rate exceeds a specified threshold.
Common Components: Analytics
Most SaaS solutions have a wide variety of raw data, including application logs, user access records and billing-related data, which can often provide a lot of insight if properly analyzed. In addition to batch-oriented analysis, you can run real-time analytics to see what kinds of actions are being invoked by various tenants on the platform, or watch infrastructure-related metrics in real time to detect any unexpected behavior and prevent future issues. You can use AWS services such as Amazon Elastic MapReduce (Amazon EMR), Amazon Redshift, Amazon Kinesis, Amazon Machine Learning, Amazon QuickSight, Amazon Simple Storage Service (Amazon S3) and Amazon EC2 Spot Instances to build these kinds of capabilities.
Analytics is usually an auxiliary function of a platform in its early stages, but as soon as multiple tenants are onboarded to a SaaS platform, fast analytics becomes a core function for detecting and understanding usage patterns, providing recommendations and driving decisions. We recommend that you plan this layer early in the solution’s development cycle.
In the next post, we will continue talking about tenant isolation architectures, detailing each of the common solution components, specifically: Configuration Management and Provisioning; Storage, Backup and Restorability; Tagging; and Metering and Billing.
SaaS Factory (The Series) — How to Build Software as a Service Solutions on AWS
See you in the next post! =)
Comments
Every comment is moderated before it appears here. Nothing is published automatically.
Loading…