What is the cheap way to build a multi-customer platform?
Put every customer in the same database, add a customer column to every table, and filter by it everywhere. One application, one database, one upgrade. It is cheap to run, and most multi-customer software is built this way.
What goes wrong with it?
Four things:
- One missing filter shows one customer another's records. The boundary between customers is a line of code, repeated in every query, forever.
- One busy customer slows every other. They share the same database and the same application.
- Leaving is an export of rows. A customer that leaves takes a filtered extract, not its system.
- The answer to "where is my data?" is "mixed in with everyone else's". That is a hard sentence to say to a customer.
What do we do instead?
We give every customer organization its own workspace:
- Every customer organization's workspace runs in its own Kubernetes namespace, with its own resource quota.
- Every customer organization's workspace has its own PostgreSQL database cluster. No database is shared between organizations.
- Every customer organization's workspace has its own sign-in realm, so its users and roles are kept apart from every other organization's.
- Every customer organization's workspace runs its own ERP instance, built on Moqui and MarbleERP. No ERP is shared between organizations.
The boundary between two customers is then not a filter in our code. There is no shared table to filter. Each workspace is created by a Kubernetes operator from one definition, running the same steps in the same order every time.
What does that cost us?
Memory, mostly. A separate ERP instance per customer uses far more than a few rows in a shared table. The platform runs on a single server today, with no second region and no uptime commitment. That limits how many workspaces we can run today, and it is one reason the pilot is small.
What about an agency's clients?
An agency is one customer organization, so it gets one workspace. Its clients are planned as business profiles inside that workspace. A profile separates a client's records inside the agency's ERP instance: a lighter boundary than a separate workspace, which we will not ship until it is enforced. (Roadmap) A separate environment for each of an agency's clients is also planned. (Roadmap)
What have we not done yet?
Customer organizations share the server, the identity server (each organization with its own realm on it) and the web edge. Scheduled backups with tested restores are not in place yet. (Roadmap)
If that trade sounds right, see what an agency gets in the pilot.