# BSQAI Tenant Operator (/docs/foundation/components/tenant-operator)



## Component Category [#component-category]

Tenant lifecycle

## Component Description [#component-description]

BSQAI Tenant Operator reconciles a cluster-scoped `PlatformTenant` resource into the Kubernetes and provider resources required by one tenant. Its status reports the overall phase plus namespace, identity, storage, and database conditions.

## Why It Is Used [#why-it-is-used]

In BullSequana AI, the operator makes tenant provisioning idempotent and observable. It creates the tenant namespace and quotas, a Keycloak Organization, optional S3 buckets, and an optional CloudNativePG database and role. Deletion runs those reconcilers in reverse and remains protected by a finalizer until cleanup succeeds.

## Lifecycle flow [#lifecycle-flow]

<Mermaid
  chart="flowchart TD
    ADMIN[&#x22;Platform administrator&#x22;] --> PORTAL[&#x22;Administration workspace&#x22;]
    PORTAL -->|create, inspect, or delete| API[&#x22;BSQAI API&#x22;]
    API -->|persist desired state| REG[&#x22;Tenant registry in PostgreSQL&#x22;]
    API -->|start or signal workflow| TMP[&#x22;Temporal tenant lifecycle workflow&#x22;]
    TMP -->|apply or delete| PT[&#x22;PlatformTenant resource&#x22;]
    PT --> OP[&#x22;BSQAI Tenant Operator&#x22;]

    OP --> NS[&#x22;Namespace, ResourceQuota, and LimitRange&#x22;]
    OP --> KC[&#x22;Keycloak Organization&#x22;]
    OP --> S3[&#x22;Optional S3 buckets&#x22;]
    OP --> CNPG[&#x22;Optional CloudNativePG database and role&#x22;]

    OP --> STATUS[&#x22;Phase, conditions, and service status&#x22;]
    STATUS --> TMP
    TMP --> REG
    REG --> API
    API --> PORTAL"
/>

## Learn More [#learn-more]

* [Administration and operations](/docs/administration)
* [Access and authentication](/docs/use/access)

## Deployment notes [#deployment-notes]

BullSequana AI 1.3.0 deploys operator version and chart 0.5.0 in `bsqai-system`. The operator has no public endpoint. It uses a Keycloak service account, provider-neutral S3 credentials, and the CloudNativePG `Database` and `DatabaseRole` APIs.

The immutable tenant slug names Kubernetes resources and the Keycloak Organization alias. The Organization UUID reported in status is the canonical runtime tenant identifier.

## Interacts With [#interacts-with]

* `BSQAI API` and `Temporal`, which accept and orchestrate tenant lifecycle requests.
* `Keycloak`, which stores the tenant Organization and compatibility groups.
* `CloudNativePG`, which creates optional tenant database resources.
* `Rook-Ceph` or external S3-compatible storage, which stores optional tenant buckets.
* `Kubernetes`, through namespaces, `ResourceQuota`, and `LimitRange` objects that enforce tenant compute boundaries when resource requests or limits are configured. The operator still reconciles empty quota and limit-range objects when no values are set.
