BSQAI Tenant Operator

Kubernetes operator that reconciles tenant identity, namespace, storage, database, and quota resources.

Agentic Friendly

Component Category

Tenant lifecycle

Component Description

BSQAI Tenant Operator reconciles a cluster-scoped PlatformTenant resource into the Kubernetes and provider resources required by one tenant. Its status reports the overall phase plus namespace, identity, storage, and database conditions.

Why It Is Used

In BullSequana AI, the operator makes tenant provisioning idempotent and observable. It creates the tenant namespace and quotas, a Keycloak Organization, optional S3 buckets, and an optional CloudNativePG database and role. Deletion runs those reconcilers in reverse and remains protected by a finalizer until cleanup succeeds.

Lifecycle flow

Learn More

Deployment notes

BullSequana AI 1.3.0 deploys operator version and chart 0.5.0 in bsqai-system. The operator has no public endpoint. It uses a Keycloak service account, provider-neutral S3 credentials, and the CloudNativePG Database and DatabaseRole APIs.

The immutable tenant slug names Kubernetes resources and the Keycloak Organization alias. The Organization UUID reported in status is the canonical runtime tenant identifier.

Interacts With

  • BSQAI API and Temporal, which accept and orchestrate tenant lifecycle requests.
  • Keycloak, which stores the tenant Organization and compatibility groups.
  • CloudNativePG, which creates optional tenant database resources.
  • Rook-Ceph or external S3-compatible storage, which stores optional tenant buckets.
  • Kubernetes, through namespaces, ResourceQuota, and LimitRange objects that enforce tenant compute boundaries when resource requests or limits are configured. The operator still reconciles empty quota and limit-range objects when no values are set.

On this page