Multi-tenancy in database-as-a-service
A system may include a memory having computer-readable instructions stored thereon and a processor that executes the computer-readable instructions to receive, from a user, a first login credential associated with an organization on a database management service. The system may receive, from the user, a selection of the first cloud account, retrieve a second login credential for the first cloud account based on the selection, automatically log in to the first cloud account using the second login credential, receive, from the user, input to perform an operation on data in the first database on the first cloud, and transmit, to the first cloud, using the second login credential for the first cloud account, a signal to perform the operation based on the input.
1 . A system comprising:
a memory having computer-readable instructions stored thereon; and
a processor that executes the computer-readable instructions to:
receive, from a user, a first login credential associated with an organization on a database management service, wherein a first tenancy of the organization defines a first database access privilege for a first database associated with a first tenant identifier and a third database associated with the same first tenant identifier on a first cloud, and a second tenancy of the organization defines a second database access privilege for a second database on a second cloud;
authenticate the user to the first tenancy using the first login credential to establish a tenant context scoped to the first tenant identifier;
receive, from the user, a selection of a first cloud account;
retrieve a second login credential for the first cloud account based on the selection;
automatically log in to the first cloud account using the second login credential;
receive, from the user, input to perform an operation on data in the first database on the first cloud;
transmit, to the first cloud, using the second login credential for the first cloud account and within the established tenant context, a signal to perform the operation based on the input;
receive, from the user, a selection of the first database corresponding to the first tenancy;
grant access to the user to the first database;
receive, from the user, a selection of a third database corresponding to the first tenancy; and
deny access to the user to the third database within the established tenant context and without re-authenticating to a different tenancy based on a user role evaluated after the tenancy authentication, wherein the user role grants access to the first database but not the third database.
2 . The system of claim 1 , wherein the processor further executes the computer-readable instructions to:
receive, from the user, a selection of a second cloud account; and
deny access to the user to the second cloud account based on a project associated with the user, wherein the project defines a project access privilege for the first cloud account but not the second cloud account.
3 . The system of claim 1 , wherein the database management service is configured to manage database operations of the first database on the first cloud corresponding to the first tenancy and manage operations of the second database on the second cloud corresponding to the second tenancy.
4 . The system of claim 1 , wherein the processor further executes the computer-readable instructions to:
create, on the first cloud, using the second login credential, the first tenancy; and
provision, on the first cloud, within the first tenancy, the first database on the first cloud.
5 . The system of claim 1 , wherein the processor further executes the computer-readable instructions to:
associate each row of the first database on the first cloud with the first tenancy; and
associate each row of the second database on the second cloud with the second tenancy.
6 . The system of claim 5 , wherein the processor further executes the computer-readable instructions to:
receive a request from the user to view a row from the first database on the first cloud, wherein the request is not associated with the first tenancy; and
deny the request based on the request not being associated with the first tenancy.
7 . The system of claim 1 , wherein the processor further executes the computer-readable instructions to:
calculate a first billing amount for the organization based on usage information associated with the first tenancy; and
calculate a second billing amount for the organization based on usage information associated with the second tenancy.
8 . The system of claim 1 , wherein the processor further executes the computer-readable instructions to:
associate the user with the second tenancy;
receive, from the user, a selection of the second tenancy;
receive, from the user, a request associated with a second tenancy context; and
grant access to the user to the second database on the second cloud based on the second tenancy context.
9 . The system of claim 1 , wherein the processor further executes the computer-readable instructions to:
receive, from the user, a subscription request;
generate, in response to the subscription request, a third tenancy; and
generate a tenant admin role for the third tenancy for the user.
10 . A non-transitory, computer-readable medium comprising instructions which, when executed by a processor, cause the processor to:
receive, from a user, a first login credential associated with an organization on a database management service, wherein a first tenancy of the organization defines a first database access privilege for a first database associated with a first tenant identifier and a third database associated with the same first tenant identifier on a first cloud, and a second tenancy of the organization defines a second database access privilege for a second database on a second cloud;
authenticate the user to the first tenancy using the first login credential to establish a tenant context scoped to the first tenant identifier;
receive, from the user, a selection of a first cloud account;
retrieve a second login credential for the first cloud account based on the selection;
automatically log in to the first cloud account using the second login credential;
receive, from the user, input to perform an operation on data in the first database on the first cloud;
transmit, to the first cloud, using the second login credential for the first cloud account and within the established tenant context, a signal to perform the operation based on the input;
receive, from the user, a selection of the first database corresponding to the first tenancy;
grant access to the user to the first database;
receive, from the user, a selection of a third database corresponding to the first tenancy; and
deny access to the user to the third database within the established tenant context and without re-authenticating to a different tenancy based on a user role evaluated after the tenancy authentication, wherein the user role grants access to the first database but not the third database.
11 . The medium of claim 10 , wherein the instructions further cause the processor to:
receive, from the user, a selection of a second cloud account; and
deny access to the user to the second cloud account based on a project associated with the user, wherein the project defines a project access privilege for the first cloud account but not the second cloud account.
12 . The medium of claim 11 , wherein the database management service is configured to manage database operations of the first database on the first cloud corresponding to the first tenancy and manage operations of the second database on the second cloud corresponding to the second tenancy.
13 . The medium of claim 10 , wherein the instructions further cause the processor to:
create, on the first cloud, using the second login credential, the first tenancy; and
provision, on the first cloud, within the first tenancy, the first database on the first cloud.
14 . The medium of claim 10 , wherein the instructions further cause the processor to:
associate each row of the first database on the first cloud with the first tenancy; and
associate each row of the second database on the second cloud with the second tenancy.
15 . The medium of claim 14 , wherein the instructions further cause the processor to:
receive a request from the user to view a row from the first database on the first cloud, wherein the request is not associated with the first tenancy; and
deny the request based on the request not being associated with the first tenancy.
16 . The medium of claim 10 , wherein the instructions further cause the processor to:
calculate a first billing amount for the organization based on usage information associated with the first tenancy; and
calculate a second billing amount for the organization based on usage information associated with the second tenancy.
17 . The medium of claim 10 , wherein the instructions further cause the processor to:
associate the user with the second tenancy;
receive, from the user, a selection of the second tenancy;
receive, from the user, a request associated with a second tenancy context; and
grant access to the user to the second database on the second cloud based on the second tenancy context.
18 . The medium of claim 10 , wherein the instructions further cause the processor to:
receive, from the user, a subscription request;
generate, in response to the subscription request, a third tenancy; and
generate a tenant admin role for the third tenancy for the user.
19 . A method comprising:
receiving, by a computer, from a user, a first login credential associated with an organization on a database management service, wherein a first tenancy of the organization defines a first database access privilege for a first database associated with a first tenant identifier and a third database associated with the same first tenant identifier on a first cloud, and a second tenancy of the organization defines a second database access privilege for a second database on a second cloud;
authenticating, by a computer, the user to the first tenancy using the first login credential to establish a tenant context scoped to the first tenant identifier;
receiving, by the computer, from the user, a selection of a first cloud account;
retrieving, by the computer, a second login credential for the first cloud account based on the selection;
automatically logging in, by the computer, to the first cloud account using the second login credential;
receiving, by the computer, from the user, input to perform an operation on data in the first database on the first cloud;
transmitting, by the computer, to the first cloud, using the second login credential for the first cloud account and within the established tenant context, a signal to perform the operation based on the input;
receiving, from the user, a selection of the first database corresponding to the first tenancy;
granting access to the user to the first database;
receiving, from the user, a selection of a third database corresponding to the first tenancy; and
denying access to the user to the third database within the established tenant context and without re-authenticating to a different tenancy based on a user role evaluated after the tenancy authentication, wherein the user role grants access to the first database but not the third database.
20 . The method of claim 19 , further comprising:
receiving, by the computer, from the user, a selection of a second cloud account; and
deny access to the user to the second cloud account based on a project associated with the user, wherein the project defines a project access privilege for the first cloud account but not the second cloud account.
21 . The method of claim 19 , wherein the database management service is configured to manage database operations of the first database on the first cloud corresponding to the first tenancy and manage operations of the second database on the second cloud corresponding to the second tenancy.
22 . The method of claim 19 , further comprising:
creating, by the computer, on the first cloud, using the second login credential, the first tenancy; and
provisioning, by the computer, on the first cloud, within the first tenancy, the first database on the first cloud.
23 . The system of claim 1 , wherein the processor executes the instructions to:
receive, from the user, a selection of a fourth database corresponding to the first tenancy, wherein the user role does not grant access to the fourth database; and
grant access to the user to the fourth database based on a project associated with the user, wherein the project defines a project access privilege for the fourth database.
24 . The non-transitory, computer-readable medium of claim 10 , wherein the instructions cause the processor to:
receive, from the user, a selection of a fourth database corresponding to the first tenancy, wherein the user role does not grant access to the fourth database; and
grant access to the user to the fourth database based on a project associated with the user, wherein the project defines a project access privilege for the fourth database.
25 . The method of claim 19 , further comprising:
receiving, from the user, a selection of a fourth database corresponding to the first tenancy, wherein the user role does not grant access to the fourth database; and
granting access to the user to the fourth database based on a project associated with the user, wherein the project defines a project access privilege for the fourth database.