What is a tenant?
A tenant is an isolated space in Namespace that owns resources: instances, builds, volumes, caches, secrets, and the credentials that access them. The rest of Namespace calls the same thing a workspace. Tenants are isolated from each other:- Resources created in one tenant are invisible to every other tenant.
- A tenant’s credentials only work inside that tenant.
- Limits, such as how many instances can run at once, apply to each tenant separately.
How your platform and its tenants work together
Your platform manages tenants with partner credentials. With them, it can:- Create a tenant for each new customer.
- List and find the tenants it owns.
- Update a tenant’s name and labels.
- Set policies that limit what a tenant can use.
- Delete a tenant when a customer leaves.
- Issue tenant tokens that act inside a tenant.
- Run instances, builds, and other workloads.
- Use storage, such as cache volumes, the container registry, and secrets.
- Read the tenant’s policies.
- Create revokable tokens for systems outside your platform.
What a tenant looks like
Next steps
Quickstart
Create a tenant and act inside it with a tenant token.
Authentication
The credentials your platform and its tenants use.