the major problem you're going to run into with Multi-tenant environments is that Service Manager needs to know who lives in that domain, which means giving the Service Manager server LDAP access to at least one domain controller in the client's environment.
You are going to need at least a one-way trust, however, since clients in the target domain must have at least end user access to the Service Manager objects via the role based security.
Once you have read-in users, and granted access to the users in the target domain, then you can place the SharePoint portal and content host in the target domain, and point your users at it.