Skip to main content

Tenant Resource Quotas & Governance

Okustera enforces sovereign multi-tenant resource governance across physical and logical infrastructure planes. Every tenant project is bounded by an authoritative quota profile that regulates compute, storage, networking, database clusters, and serverless invocations.

Quotas prevent noisy-neighbor degradation, guarantee fair-share resource allocation across enterprise departments, and prevent financial runaway spend.


Architecture: Multi-Tenant Quota Governance​

Quotas are centrally managed by platform operators in the Okustera Backoffice, evaluated in real time by the Platform Control Plane (omc-back-end), and presented with live telemetry in the Cloud Portal Dashboard:


The 9 Authoritative Quota Dimensions​

Every tenant project is provisioned with default baseline allocations that can be dynamically scaled up by cloud administrators:

DimensionQuota KeyDefault AllocationMeasured UnitEnforcement Level
Compute vCPUsvcpus_limit64vCPUsHard Limit (Nova Admission)
Compute Memoryram_gb_limit256.0GB DDR5 RAMHard Limit (Nova Admission)
Persistent Storagestorage_tb_limit5.0TB Ceph NVMe/RBDHard Limit (Cinder / Ceph)
Virtual Machinesinstances_limit10Nova KVM InstancesHard Limit (Instance Count)
Block Volumesvolumes_limit10Persistent VolumesHard Limit (Volume Count)
Managed Databasesdatabases_limit10Database ClustersHard Limit (PostgreSQL, MySQL, MongoDB, Valkey)
Serverless Functionsserverless_functions_limit20OpenFaaS FunctionsHard Limit (gVisor Sandboxes)
Airflow DAGsairflow_dags_limit10Scheduled PipelinesHard Limit (Active DAGs)
API Gatewaysapi_gateways_limit15APISIX RoutesHard Limit (Ingress Route Rules)

Inspecting Quotas via REST API​

Tenants can query their live allocations and current utilization in real time:

Request​

curl -X GET https://portal.okustera.com/api/v1/tenant/quota \
-H "Authorization: Bearer <YOUR_API_TOKEN>"

Response​

{
"project_id": "tenant-enterprise-prod",
"tenant_name": "ACME Corporation",
"tenant_slug": "acme-corp",
"vcpus": {
"limit": 64.0,
"used": 16.0,
"available": 48.0,
"unit": "vCPUs"
},
"ram_gb": {
"limit": 256.0,
"used": 64.0,
"available": 192.0,
"unit": "GB"
},
"storage_tb": {
"limit": 5.0,
"used": 1.25,
"available": 3.75,
"unit": "TB"
},
"instances": {
"limit": 10.0,
"used": 4.0,
"available": 6.0,
"unit": "VMs"
},
"volumes": {
"limit": 10.0,
"used": 4.0,
"available": 6.0,
"unit": "Volumes"
},
"databases": {
"limit": 10.0,
"used": 3.0,
"available": 7.0,
"unit": "Clusters"
},
"serverless_functions": {
"limit": 20.0,
"used": 8.0,
"available": 12.0,
"unit": "Functions"
},
"airflow_dags": {
"limit": 10.0,
"used": 2.0,
"available": 8.0,
"unit": "DAGs"
},
"api_gateways": {
"limit": 15.0,
"used": 5.0,
"available": 10.0,
"unit": "Routes"
}
}

Quota Enforcement & Error Behavior​

When an operation exceeds the allocated limit, the Control Plane rejects the transaction immediately before allocating underlying infrastructure:

Serverless Function Creation Breach​

{
"detail": "Serverless functions quota exceeded: your project limit is 20. Request an administrative quota increase in Backoffice."
}

Database Cluster Provisioning Breach​

{
"detail": "Database clusters quota exceeded: limit is 10, currently utilizing 10 clusters. Request an administrative quota increase in Backoffice."
}

FinOps Automated Quota Freeze (enable_quota_freeze)​

In addition to static resource quotas, Okustera provides a FinOps Budget Quota Freeze mechanism to prevent accidental billing overages:

  • Within the Billing Console (/billing), tenants set a monthly spending cap (e.g. $1,000.00).
  • When enable_quota_freeze: true is configured:
    1. The rating engine tracks real-time vCPU-hours, GB-hours, and S3 storage consumption.
    2. If Month-to-Date (MTD) spend reaches 100% of the budget, an automated soft quota freeze is enacted.
    3. Zero Interruption to Live Services: Existing production virtual machines, databases, and functions continue running without downtime.
    4. Provisioning Guard: Creation of new instances, volume expansions, or database scale-ups are blocked until an administrator raises the budget or adds credit balance.

Requesting a Quota Increase​

Enterprise tenants requiring additional resources beyond the default baseline can request quota expansions:

  1. Self-Service Support Ticket: In the Cloud Portal, navigate to Support $\to$ Request Quota Increase, select the resource category, and state the technical justification.
  2. Administrative Override: Platform administrators update the tenant's profile via the Backoffice API:
    curl -X PUT https://backoffice.okustera.com/api/v1/tenants/tenant-enterprise-prod/quota \
    -H "Authorization: Bearer <ADMIN_SESSION_TOKEN>" \
    -H "Content-Type: application/json" \
    -d '{
    "vcpus_limit": 128,
    "ram_gb_limit": 512.0,
    "storage_tb_limit": 10.0,
    "databases_limit": 25,
    "serverless_functions_limit": 50,
    "airflow_dags_limit": 20,
    "api_gateways_limit": 35
    }'
  3. Changes take effect instantly across all platform APIs without requiring node or service restarts.