Multi-tenancy: a practical guide
The version of this that works is simpler than the version most people imagine. This guide covers what multi-tenancy actually involves, where it usually goes wrong, and how to tell whether yours is in reasonable shape.
Most systems fail at the seams rather than inside any one component. Nothing below assumes a large team or a large budget — most of it is a decision somebody has to make and then write down.
Why this earns attention
Decide early whether tenants share a database or not. Where this goes wrong is almost never a lack of knowledge. The version that survives contact with a real deadline is the simple one.
For most businesses the question is not whether this matters but how much of it is worth doing right now. That depends on what you are trying to achieve in the next few months, not on best practice in the abstract. Where this goes wrong is almost never a lack of knowledge.
What good looks like
Isolation is a security requirement, not a preference. Where this goes wrong is almost never a lack of knowledge. The failure mode is not doing it wrong, it is doing it once and assuming it stays done.
Architecture is the set of decisions that are expensive to reverse, which is the only reason they deserve the name. The version that works in practice is usually less elaborate than the version described in the guides.
Noisy neighbours become a support problem before an engineering one. In practice this is a scheduling problem more than a technical one. Anything you cannot measure here, you are deciding by taste, which is fine as long as everyone knows it.
A working checklist
If you want a quick read on where you stand, work through this. Anything you cannot answer confidently is where to start.
- Decide early whether tenants share a database or not
- Isolation is a security requirement, not a preference
- Noisy neighbours become a support problem before an engineering one
- Someone is named as the owner, not just assumed to be
- There is a date in the calendar to review it again
- The decision and the reasoning behind it are written down somewhere findable
- You could explain the current setup to a new hire in five minutes
What to watch for
The most common failure is not doing this badly. It is doing it once, during a launch, and never revisiting it. Circumstances move, the setup does not, and the gap widens quietly until something breaks or somebody notices the numbers.
- It was configured during a launch and has not been touched since
- Different people in the business believe different things are true about it
- There is no way to tell whether the last change helped or hurt
- The only person who understands it has left, or is about to
The right architecture for a team of three is the wrong one for a team of thirty, and vice versa. Small and consistent beats large and occasional here.
How we approach it
On our projects this gets handled during the build rather than added afterwards, because retrofitting it costs several times more than including it. We write down what was decided and why, so the next person to touch it is not guessing.
If you are working with someone else, the questions worth asking are simple: who owns this, how will we know it is working, and what happens when it needs to change?
A reasonable first step
Pick the single item from the checklist above that would cause the most trouble if it turned out to be wrong. Fix that one, confirm it worked, then move on. Pick the one that would hurt most if it failed, and start there.