Tenant Resource Quotas & Governance
Okustera enforces sovereign multi-tenant resource governance across physical and logical infrastructure planes. Every tenant project is bounded by an authoritative quota profile that regulates compute, storage, networking, database clusters, and serverless invocations.
Quotas prevent noisy-neighbor degradation, guarantee fair-share resource allocation across enterprise departments, and prevent financial runaway spend.
Architecture: Multi-Tenant Quota Governance
Quotas are centrally managed by platform operators in the Okustera Backoffice, evaluated in real time by the Platform Control Plane (omc-back-end), and presented with live telemetry in the Cloud Portal Dashboard:
The 9 Authoritative Quota Dimensions
Every tenant project is provisioned with default baseline allocations that can be dynamically scaled up by cloud administrators:
| Dimension | Quota Key | Default Allocation | Measured Unit | Enforcement Level |
|---|---|---|---|---|
| Compute vCPUs | vcpus_limit | 64 | vCPUs | Hard Limit (Nova Admission) |
| Compute Memory | ram_gb_limit | 256.0 | GB DDR5 RAM | Hard Limit (Nova Admission) |
| Persistent Storage | storage_tb_limit | 5.0 | TB Ceph NVMe/RBD | Hard Limit (Cinder / Ceph) |
| Virtual Machines | instances_limit | 10 | Nova KVM Instances | Hard Limit (Instance Count) |
| Block Volumes | volumes_limit | 10 | Persistent Volumes | Hard Limit (Volume Count) |
| Managed Databases | databases_limit | 10 | Database Clusters | Hard Limit (PostgreSQL, MySQL, MongoDB, Valkey) |
| Serverless Functions | serverless_functions_limit | 20 | OpenFaaS Functions | Hard Limit (gVisor Sandboxes) |
| Airflow DAGs | airflow_dags_limit | 10 | Scheduled Pipelines | Hard Limit (Active DAGs) |
| API Gateways | api_gateways_limit | 15 | APISIX Routes | Hard Limit (Ingress Route Rules) |
Inspecting Quotas via REST API
Tenants can query their live allocations and current utilization in real time:
Request
curl -X GET https://portal.okustera.com/api/v1/tenant/quota \
-H "Authorization: Bearer <YOUR_API_TOKEN>"
Response
{
"project_id": "tenant-enterprise-prod",
"tenant_name": "ACME Corporation",
"tenant_slug": "acme-corp",
"vcpus": {
"limit": 64.0,
"used": 16.0,
"available": 48.0,
"unit": "vCPUs"
},
"ram_gb": {
"limit": 256.0,
"used": 64.0,
"available": 192.0,
"unit": "GB"
},
"storage_tb": {
"limit": 5.0,
"used": 1.25,
"available": 3.75,
"unit": "TB"
},
"instances": {
"limit": 10.0,
"used": 4.0,
"available": 6.0,
"unit": "VMs"
},
"volumes": {
"limit": 10.0,
"used": 4.0,
"available": 6.0,
"unit": "Volumes"
},
"databases": {
"limit": 10.0,
"used": 3.0,
"available": 7.0,
"unit": "Clusters"
},
"serverless_functions": {
"limit": 20.0,
"used": 8.0,
"available": 12.0,
"unit": "Functions"
},
"airflow_dags": {
"limit": 10.0,
"used": 2.0,
"available": 8.0,
"unit": "DAGs"
},
"api_gateways": {
"limit": 15.0,
"used": 5.0,
"available": 10.0,
"unit": "Routes"
}
}
Quota Enforcement & Error Behavior
When an operation exceeds the allocated limit, the Control Plane rejects the transaction immediately before allocating underlying infrastructure:
Serverless Function Creation Breach
{
"detail": "Serverless functions quota exceeded: your project limit is 20. Request an administrative quota increase in Backoffice."
}
Database Cluster Provisioning Breach
{
"detail": "Database clusters quota exceeded: limit is 10, currently utilizing 10 clusters. Request an administrative quota increase in Backoffice."
}
FinOps Automated Quota Freeze (enable_quota_freeze)
In addition to static resource quotas, Okustera provides a FinOps Budget Quota Freeze mechanism to prevent accidental billing overages:
- Within the Billing Console (
/billing), tenants set a monthly spending cap (e.g.$1,000.00). - When
enable_quota_freeze: trueis configured:- The rating engine tracks real-time vCPU-hours, GB-hours, and S3 storage consumption.
- If Month-to-Date (MTD) spend reaches 100% of the budget, an automated soft quota freeze is enacted.
- Zero Interruption to Live Services: Existing production virtual machines, databases, and functions continue running without downtime.
- Provisioning Guard: Creation of new instances, volume expansions, or database scale-ups are blocked until an administrator raises the budget or adds credit balance.
Requesting a Quota Increase
Enterprise tenants requiring additional resources beyond the default baseline can request quota expansions:
- Self-Service Support Ticket: In the Cloud Portal, navigate to Support $\to$ Request Quota Increase, select the resource category, and state the technical justification.
- Administrative Override: Platform administrators update the tenant's profile via the Backoffice API:
curl -X PUT https://backoffice.okustera.com/api/v1/tenants/tenant-enterprise-prod/quota \-H "Authorization: Bearer <ADMIN_SESSION_TOKEN>" \-H "Content-Type: application/json" \-d '{"vcpus_limit": 128,"ram_gb_limit": 512.0,"storage_tb_limit": 10.0,"databases_limit": 25,"serverless_functions_limit": 50,"airflow_dags_limit": 20,"api_gateways_limit": 35}'
- Changes take effect instantly across all platform APIs without requiring node or service restarts.
Related Documentation
- Compute Instances (Nova VMs): Managing virtual machine sizing and vCPU/RAM flavor tiers.
- Managed Databases (DBaaS): High-availability database clusters and engine limits.
- Serverless Functions (OpenFaaS & gVisor): Function runtime specifications and execution quotas.
- FinOps, Metering & Billing: Transparent unit pricing and budget threshold configurations.