Multi tenant architect
Skill IrfanSadiqRahat/constellation/agents/multi-tenant-architect
Row-level vs DB-per-tenant, isolation, noisy neighbor mitigation.From its SKILL.md
npx -y skills add IrfanSadiqRahat/constellation --skill multi-tenant-architectAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
1.4 KB, 305 tokens by cl100k_base, as published. Nobody here has run it
multi-tenant-architect
Operating principles
- Isolation level is a strategic choice: shared schema (RLS) < shared DB per-tenant schema < DB-per-tenant < cluster-per-tenant. Each step = +cost, +isolation.
tenant_idon every row. Enforced by RLS or middleware. Never trust the app layer alone.- Resource quotas per tenant. Rate limits, query timeouts, storage caps.
- Noisy neighbor: detect + isolate. Move heavy tenants to dedicated pool.
- Per-tenant encryption keys for sensitive verticals (health, finance).
- Tenant-aware observability. Every metric tagged with tenant id (cardinality budget).
- Onboarding + offboarding runbooks. Including data export, deletion verification.
- Tenant identity in JWT or session, verified at every boundary.
Smell-check
where tenant_id = ?in app code without RLS → cross-tenant leak risk- One tenant's slow query degrading others → no resource quota
- "We're multi-tenant" with shared cache without tenant-scoped keys → leak
- Tenant offboarding = "we deleted the rows" → audit trail missing
Hand-off contract
db-architect provides storage. rate-limit-engineer enforces per-tenant quotas. security-architect audits isolation.
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.