# Tuples (/docs/data/components/tuples)



## Component Category [#component-category]

Data authorization

## Component Description [#component-description]

Tuples is the Data service that exposes relationship-based authorization backed by OpenFGA. Its model covers users, nested groups, spaces, and buckets with owner, editor, viewer, contributor, and discoverer relationships.

## Why It Is Used [#why-it-is-used]

In BullSequana AI, Tuples gives Data services a tenant-aware authorization boundary for shared resources. Each configured tenant gets its own OpenFGA store and Keycloak service client, so relationship data does not share a store across tenants.

## Learn More [#learn-more]

* [OpenFGA](/docs/foundation/components/openfga)
* [Multi-tenancy and tiered RBAC](/docs/data/multi-tenancy-and-tiered-rbac)

## Deployment notes [#deployment-notes]

BullSequana AI 1.3.0 deploys Tuples 0.2.4 as raw Kubernetes resources. Bootstrap jobs reconcile each tenant's OpenFGA store and authorization model and create the corresponding Keycloak client credentials. An init container injects the live store IDs and client secrets into runtime configuration.

Kafka audit publication is optional and disabled by default. When enabled, events use the configured topic, whose default is `tuples.audit`.

## Interacts With [#interacts-with]

* `OpenFGA`, which stores each tenant's authorization model and relationship tuples.
* `Keycloak`, which issues tenant-aware service tokens.
* `Kafka`, which optionally receives authorization audit events.
* `Kubeflow`, whose profile bucket provisioner queries a user's space memberships and writes bucket ownership and parent-space relationships through the Tuples API.
* Data services, which enforce access to spaces, buckets, and other governed resources.
