Learn/System Design/Multi-tenancy, Fairness & Resource Isolation
Advanced~18 min read

Multi-tenancy, Fairness & Resource Isolation

Design tenant-aware data paths, per-tenant quotas, cells, fair queues, billing boundaries and safe administration.

System DesignDistributed SystemsProduction

Isolation is end to end

A tenant is an organization or ownership boundary, not merely a field sent by the browser. Verify membership and derive permitted tenant context from trusted identity. A request can be authenticated and still access another organization's data.

Carry the boundary through databases, caches, search, object storage, queues, exports and logs. An omitted tenant prefix in one derived store can defeat correct database predicates. Distinguish platform operators from tenant administrators: the latter must not gain platform-wide authority.

Data placement choices

ModelAdvantagesOperational costs
Shared tablesEfficient fleet, simpler shared migrationsEvery path must enforce tenant boundaries
Schema per tenantSeparate names and some administrationMany schemas, migration orchestration and connection context
Database per tenantStronger resource and backup separationFleet size, connection count, provisioning and upgrades
Dedicated cell for selected tenantsContained capacity and fault domainRouting, rebalancing and cost

Database separation alone does not fix an application that opens the wrong connection. Shared tables can use a database enforcement layer in addition to application checks. Run policy tests with the real runtime role; a privileged administrator bypassing restrictions is not a meaningful tenant-isolation test.

Tenant-aware keys and constraints

Use composite ownership keys where appropriate. A child reference should not let a row belonging to tenant A reference a parent belonging to B. Scope uniqueness to the intended boundary: a project's display name may be unique per tenant, while a public custom domain may be globally unique.

Index the actual tenant-filtered queries. An index beginning with tenant and then status/time can serve per-tenant lists; a global support query may require a separately justified index. Keep soft-deletion and permission predicates aligned with index design.

Cache and object paths

Cache keys include tenant, resource, representation and permission-relevant version where required. Never cache a private response as public because its URL looks like a static path. A signed object URL grants whoever possesses it the scoped capability until expiry or revocation by supported mechanisms.

Export jobs recheck authorization when requested and when delivered according to policy. If access is revoked while a large export runs, define whether to cancel, quarantine or require fresh authorization to download. Do not attach private exports to permanent public URLs.

The noisy-neighbor problem

One tenant can exhaust workers through expensive queries, oversized uploads or retry storms. Request-rate limits alone miss work cost: one query can be a thousand times more expensive than another.

Bound concurrent tasks, execution duration, uploaded bytes, output size, fan-out and queued work per tenant. Assign cost classes and reject excess demand visibly. Protect login and support operations from an expensive analytics workload sharing every resource pool.

Fair scheduling

A global FIFO lets a tenant submitting 100,000 tasks delay everyone else. Per-tenant queues with weighted round-robin or deficit-based scheduling give controlled turns. Specify whether unused capacity may be borrowed and how it is reclaimed.

For ten workers, reserve a small interactive pool and allow long batch tasks in a separate pool. If a task is non-preemptible, borrowing an interactive slot can still delay future urgent work. Fairness is a policy with latency consequences, not just a queue implementation detail.

Cells limit blast radius

A cell is a bounded group of resources serving a subset of tenants. Its database, workers and limits form a failure boundary. Routing maps tenants to cells; copying ownership safely during a move requires a migration protocol.

Use several cells to contain overload and deploy changes progressively. Shared identity, configuration and routing remain possible fleet-wide failure points. Keep the data plane able to serve already-known mappings when a management plane is temporarily unavailable, within a safe expiry policy.

Shuffle sharding assigns tenants to small resource subsets so failures overlap with fewer other tenants than a single shared pool. It adds placement and routing complexity; validate its benefit against your specific bottleneck rather than treating it as mandatory infrastructure.

Quotas, metering and entitlements

Entitlement checks determine what a tenant may use. Quotas determine how much. Metering records consumption. These are separate data paths: a delayed analytics count should not silently determine an authoritative spending limit.

For a hard global quota, reserve capacity atomically before use and settle or release afterward. Distributed local budgets can reduce latency but require a documented overshoot bound. Record a stable usage-event ID to prevent billing duplicates; corrections must remain traceable.

Administration and audit

Support access should be time-bounded, purpose-specific and audited. Impersonation must be visible and cannot inherit arbitrary secrets. Log actor, tenant, action and result with sensitive payloads redacted. Access to audit records is itself authorized.

Test cross-tenant IDs, copied cursors, search filters, cache collisions, changed memberships, cancelled exports and restored backups. A successful tenant-A request is not evidence that tenant B is inaccessible.

Exercise

Turn a student learning site into a college portal. Add organizations, student membership, teacher reports and private assignments. Draw both isolation and fairness boundaries. Decide which workloads share a database, how a large college gets a dedicated cell and what happens if its report jobs overload workers.

Section navigation

Keep it in your account.

Your progress is saved securely and available when you return.

Sign in Create a free account