Skip to main content
Policies control what a tenant can use. With them, you can match each customer’s limits to their plan, for example five concurrent instances for a starter plan and more for enterprise customers, or expire a trial tenant after 30 days. This page covers reading a tenant’s policies, replacing them, and changing one setting while keeping the rest.

Credentials

Reading and writing policies use different credentials:
  • Writing policies uses a partner client, because the request names the tenant. The examples call it partnerClient.
  • Reading policies uses a tenant client, because the request has no tenant ID and applies to the tenant the token belongs to. The examples call it tenantClient.

How policies are stored

A tenant has a list of policies and a revision number. Every successful change replaces the whole list and increments the revision. The main policy is the usage policy, identified by namespace.cloud.compute.v1beta.UsagePolicy. Its settings are stored as a JSON string in the policy’s value:
A new tenant starts with an empty usage policy, whose value is {}, at revision 1.

Set a tenant’s policies

To give a tenant a fixed set of limits, for example when a customer picks a plan, send the complete policy list. It replaces whatever the tenant had before, so there is no need to read the current policies first.
Serializing the usage policy with its SDK type, rather than writing the JSON by hand, keeps field names and number formats correct.

Read a tenant’s policies

The response has the same shape as the example in How policies are stored.

Change one setting and keep the rest

Setting policies replaces the whole list, so changing one limit that way would drop every other setting. To change a single setting, read the current policies, change that setting, and write them back with the revision you read.
1

Read the current policies

2

Change the setting

Find the usage policy, parse its value, and change only the setting you need. This example raises the tenant’s CPU limit and leaves every other setting and policy as it was.
3

Write the policies back with the revision

The update only succeeds if the tenant’s revision still matches the one you read. If someone else changed the policies in the meantime, it fails with a FailedPrecondition error instead of overwriting their change. Read the policies again and repeat the change.Reading the policies again shows the new value and revision:
Output

Expire a tenant

An expiration policy sets a date when the tenant expires, which suits trial tenants. Add it to the policy list next to the usage policy:
To remove an expiration, send the expiration policy without expiresAt.

Usage policy settings

Next steps

Delete tenants

Remove a tenant when a customer leaves.

Resource limits

How limits apply to the compute a tenant runs.
Last modified on October 2, 2026