infrastructure//cloud computing//multi-tenancy

Multi-tenancy is the arrangement in which one infrastructure or software system serves several independent customers, the **tenants**, while keeping each one's data, workloads and performance separate from the others, and it is the economic foundation of cloud computing: hardware and operations shared across many customers cost each of them less than a dedicated copy would. A virtualised server hosting VMs from five companies, a database storing rows for thousands of SaaS customers, and a Kubernetes cluster running several teams' services are all multi-tenant.


Multi-tenancy is the arrangement in which one infrastructure or software system serves several independent customers, the tenants, while keeping each one's data, workloads and performance separate from the others, and it is the economic foundation of cloud computing: hardware and operations shared across many customers cost each of them less than a dedicated copy would. A virtualised server hosting VMs from five companies, a database storing rows for thousands of SaaS customers, and a Kubernetes cluster running several teams' services are all multi-tenant.

Its whole difficulty is isolation. Tenants must not read each other's data, must not be able to escalate from their share into another's, and should not suffer when a neighbour's workload spikes. Each layer offers its own tools: hypervisors for whole machines (virtual machine), kernel features for processes (container), row-level permissions for shared databases (RLS), and identity and access policies above all of it (IAM).

The noisy neighbour is the everyday failure. Isolation of data is enforced strictly; isolation of performance often is not. Two tenants sharing a physical host also share its memory bandwidth, caches, disks and network, so one tenant's heavy job raises the others' latency, and for a GPU training job that waits on the slowest member, one slow host slows everything.

The security failure is rarer and worse. A flaw in the isolation layer (a hypervisor bug, a sandbox escape, a side channel through a shared cache) lets one tenant reach another, which is why sensitive workloads are sometimes placed on single-tenant hardware.

Multi-tenant and bare metal are not opposites. A provider can run a multi-tenant platform in which each customer receives whole dedicated physical machines: the platform (network, storage, control plane) is shared while the servers are not.