Multi-Tenant Best Practices Can Backfire

  • by Derek Comartin
  • Published on Derek Comartin (CodeOpinion)
  • Curated on
  • Architecture
Multi-Tenant Best Practices Can Backfire - Derek Comartin (CodeOpinion)
Image: Derek Comartin (CodeOpinion)

You have a multi-tenant system, but you discover a pretty horrible bug. How can that be? You followed all the best practices!

Your HTTP API places a message on a queue to generate an invoice. A background process picks up that message and executes it. Everything looks like it worked. There were no exceptions, no failed database calls, and no errors in your logs.

However, something went horribly wrong.

The request was supposed to execute for tenant A, but what actually happened is that it executed for tenant B. The wrong tenant.

YouTube

Check out my YouTube channel, where I post all kinds of content on Software Architecture & Design, including this video showing everything in this post.

You likely tried to prevent this from ever happening in the first place. Maybe you made the design decision that you didn’t want the tenant ID littered everywhere and passed around from your HTTP API, to messages, to background tasks, to your database.…