Multi-Tenant Architecture
Documentation status: architecture — see Maturity and evidence.
Multi-tenancy is an isolation and governance decision. It must not be achieved by implicitly mixing data from several organizations in the same application context.
Dimensions to isolate
Depending on deployment, isolation may cover:
- identities and groups;
- data and conceptual memory;
- configuration;
- secrets;
- queues/messages;
- compute resources;
- logs and audit;
- retention and backup policies.
Topology choices
A tenant may be isolated by application, Runtime, process, node, database, graph, or logical partition. The selected level depends on security, cost, performance, and operational requirements.
Security rule
A tenant identifier supplied by a client is never authorization. Authenticated identity and authorization rules determine the accessible scope.
Evolution
Migrations should be versioned and observable per tenant. Global operations should prevent one failing tenant from blocking the others.