Comprehensive Guide to Rubrik Tenant Organizations and Multi-Tenancy

Definition and Subsets of Tenant Organizations

  • In Group Link, an organization is a subset of a main group.
  • The structure consists of a global organization that contains various sub-organizations.
  • Sub-segments or sub-organizations act as individual units or clients within a single RSE environment.
  • Practical examples of sub-segments include the HR department, engineering department, and transport and facilities departments within an IT company.

Hierarchical Structure and Domain Access

  • The main RSE URL for a company is formatted as sttps.//my.rubric.com (using the company name).
  • Organizations created under this main URL follow a specific naming convention, such as infraorg-trainingteam, where Training Team is the main organization and Infra is the sub-department. Other examples of sub-departments include accounting.
  • Users navigate to the global organization and use a wizard to create multiple sub-organizations.

Concepts of Multi-Tenancy

  • Multi-tenancy involves segments of users who share common traits, including departments, projects, or daily responsibilities.
  • Every RSE domain features exactly 11 organization portal.
  • Upon initial login, there is a single global organization by default, which can be delegated to create multiple internal tenants.
  • A specific use case for organizations is becoming a partner to Rubrik (or Ruplink). In this model, an entity uses one RSE license to manage multiple tenants on behalf of Ruby Link. Each customer is created as a separate organization (e.g., ABC customer or x y z customer).
  • Organizations within a multi-tenant cluster possess a subset of administrative privileges and have access only to specified resources, such as specific objects for backup and recovery.

Organizational Elements and Graphical Representation

  • The graphical representation of an organization includes several managed elements:
    • Protected objects
    • Recovery targets
    • Users
    • Clusters
    • SLA reports
  • While these are created in the global organization, sub-organizations (e.g., Org A for System Engineering) can be assigned specific existing objects or new objects.
  • An organization for System Engineering might include server compliance SLAs and specific servers for recovery (e.g., Server A and Server B), whereas a Database (DB) organization (Production System Engineering Team) might require different elements like Lupin Edge for database discovery.

User Management and Identity Providers

  • Users in a multi-tenant environment can be managed through a unique SSO provider.
  • SSO users can be inherited from the global SSO provider, allowing sub-tenants to use the same SSO features.
  • Local users can also be created separately within the quality tenant organization.
  • A prerequisite for creating an organization is defining an Org Ad (Organization Admin), who serves as the head of the organization.
  • The Org Ad can invite local users by entering an email address to send an invitation link.
  • Users must have a role assigned to function. When first created, organizations only contain one default admin role; subsequently, custom defined users or roles can be created.

Step-by-Step Tenant Creation Process

  • Initiation: Access the app tray settings, select the organization, and open the organization management window.
  • Naming and Identification:
    • Provide the organization name (e.g., Accounts or HR).
    • Create a Unique ID, which is used for the login URL.
    • Enter a description for the organization.
  • Authentication Configuration:
    • Enable Per-Tenant Access Control: Only users who are specifically part of the sub-organization are allowed to log in.
    • Inherit SSO: Allows all SSO users from the global organization to log in to the sub-organization.
    • Keep All Users Local: All users in the RSE are allowed to log in as part of the user set.
    • Best practice generally involves choosing the specific per-tenant access control to limit access.
  • Security and White Listing:
    • Configuring Multi-Factor Authentication (MFA) is a mandatory requirement for sub-organizations and multi-tenant organizations.
    • The tenant organization can inherit the IP white list from the RSE. Enabling this fetches the rules globally, ensuring IPs blocked at the RSE level are also blocked for the sub-organization.
  • User Invitation: Existing users can be invited, or new users can be added by typing an email address. Administrators can enable the admin role for these users after they arrive through the invitation link.

Assigning Clusters and Resource Privileges

  • After creating a blank organization, objects must be added via Rubrik clusters.
  • Privileges are assigned based on specific tasks:
    • Cluster Configuration: For management-related tasks.
    • Replication: For replication-related tasks.
    • SMB: For SMB options.
    • UI Specific Access: For specific user interface access.
  • A built-in RBAC (Role-Based Access Control) framework is followed where the user chooses data management privileges, specifying objects, SLAs, and recovery targets.
  • System-level configurations available for sub-organizations include:
    • Downloading reports and events.
    • Network level configurations such as NTP, DNS, and DHCP.
  • Workload selection allows for granular protection. An admin can choose to protect only vSphere for one customer, and later add AVH, Nutanix, or Hyper-V as inventory changes.
  • Data management permissions cover recovery types, workload-specific options, snapshot retention, SLA management, and on-demand snapshots.
  • Self-service features allow an organization to create and manage its own SLAs. Assignments can be made to existing and future SLAs.
  • Note: "Do not protect" is an explicit assignment, whereas "clear assignment" removes the existing assignment.

Replication and Account Restrictions

  • Cross-account replication is supported, permitting the replication of data from one sub-account to another CDM cluster.
  • Administrators can choose to block service accounts, forcing the use of local accounts only. If disabled, service accounts remain allowed.

Storage Quotas and Billing for Managed Service Providers (MSPs)

  • Storage quotas are used to manage limits and track consumption for each tenant organization.
  • This is particularly useful for MSPs to bill customers based on their monthly or yearly data usage.
  • Administrators can reserve specific capacity (e.g., 5 TB5\,TB).
  • Soft Limits: Provides a reminder to the customer once a specific threshold is reached (e.g., when reaching the paid 5 TB5\,TB limit).
  • Hard Limits: A strict threshold (e.g., an additional 100 GB100\,GB, 200 GB200\,GB, or 500 GB500\,GB beyond the soft limit). Once the hard limit is crossed, backups will stop or fail until capacity is expanded.

Rubrik Envoy for Secure Tenant Isolation

  • Rubrik Envoy acts as a virtualization layer, similar to ESXI, ensuring tenants run in isolation and cannot see each other.
  • It allows tenants to connect securely to Rubrik services on a Rubrik cluster.
  • Envoy is deployed as a virtual appliance (on VMware or other supported platforms) and registered with the RSC.
  • Communication occurs via a secure TLS connection, with NATing options available.
  • Stateless Architecture: Rubrik Envoy is a stateless VM, meaning it has no hard drive for data storage and does not store customer data. It functions as a secure gateway for incoming and outgoing traffic from CDM clusters.
  • Deployment Limits: A maximum of 44 Envoys can be deployed per sub hour (sub-organization). There is no limitation on the number of Envoys required for a global organization.