SaaS Factory (The Series) · Part 3 of 3
SaaS Factory (The Series) — Tenant Isolation: Tenant Isolation Architectures in SaaS (Part 3/3)
In this post, we continue our discussion of tenant isolation architectures, detailing each of the common solution components…
Keywords
In this post, we continue our discussion of tenant isolation architectures, detailing each of the common solution components, specifically: Configuration Management and Provisioning; Storage, Backup and Restore Capability; Tagging; and Metering and Billing.
Common components: Configuration Management and Provisioning
AWS offers several ways to automate solution deployments. You can bake some deployment tasks into your own AMIs, and you can automate more configurable or frequently changing items using a variety of other means: one-time tasks, such as hardening the operating system or setting up specific runtime versions that don't change without an application recertification process (such as a Java upgrade), or even time-consuming installations (such as middleware/database setup), can be included in the AMI itself.
To handle deployment aspects that change more often, such as code updates from a code repository, bootstrap tasks (such as joining a domain / cluster) and certain environment-specific settings (such as different parameters for dev / test / production), you can use custom scripts in the user data section of the EC2 instance, or AWS services such as AWS CodeCommit, AWS CodePipeline and AWS CodeDeploy.
For a complete stack spin-up, a higher level of automation can be achieved with AWS CloudFormation, which gives developers and system administrators an easy way to create and manage a collection of related AWS resources, and lets them provision and update those resources in an orderly and predictable fashion. Depending on your requirements, AWS Elastic Beanstalk and AWS OpsWorks can also help with fast deployments and automation.
Common components: Storage, Backup and Restore Capability
Most AWS services have backup mechanisms so you can roll back to a last known stable state if any more recent change needs to be reverted. Features including Amazon EC2 Snapshots (Amazon EBS, Amazon RDS and Amazon Redshift snapshots) can potentially support most backup requirements. However, there are advanced needs, such as having to quiesce a file system and then take a consistent snapshot of a live database such as Oracle or SQL Server. For those, third-party tools can be used to assist the process.
Common components: Tagging
To help you manage instances, images and other AWS resources, you can assign your own metadata to each resource in the form of tags. We recommend that you adopt a tagging strategy before you start deploying your SaaS solution. Each tag consists of a key and an optional value, both of which you define. You can also have multiple tags on a single resource. There are two main uses for tags:
- General resource management: tags let you categorize your AWS resources in different ways, such as by purpose, owner or environment;
- Billing segregation: tags enable cost allocation reports and let you segregate costs by a specific business unit or environment.
Common components: Metering and Billing
Another important aspect of a multi-tenant system is segregating costs across tenants based on their usage. From an AWS resource perspective, tags can be a great way to help you separate usage at a macro level. However, most SaaS solutions need finer-grained controls for usage monitoring, so we recommend building your own custom billing module as needed. Below we present one possible approach.
Every resource that is started, stopped and terminated is tracked, and the data is sent to an Amazon Kinesis stream. Granular measurements, such as the number of API requests made or the time taken to process any given request, are tracked and the data is fed into the Kinesis stream in real time.
Two kinds of consumer applications can process the data stored in Amazon Kinesis: a) a consumer fleet that generates real-time metrics on how the system is being used by the various tenants. This can help you make decisions such as throttling a given tenant's usage or taking other corrective actions based on real-time feeds; b) a second Kinesis consumer fleet could aggregate the continuous feed and generate monthly or quarterly usage reports for billing. It can also provide usage analytics for each tenant by processing the raw data and storing it in Amazon Redshift. For processing or transforming historical data, Amazon EMR can be used.

Metering model in SaaS
Specifically regarding metering, it is important to consider:
- Developing a tiered pricing model;
- Correlating pricing with broad cost tracking;
- Common patterns for pricing modeling;
- Using metering data to control resource utilization;
- Setting hard limits on consumption, encouraging and facilitating tier upgrades;
- Integrating with billing solutions;
- Configuring and enforcing billing plans.
General Considerations on Tenant Isolation
- SaaS requires a robust support solution;
- Implement tools that streamline the support lifecycle;
- Instrument applications, automatically integrated into the support flow;
- Map support SLAs to tiered pricing plans;
- Create a cohesive customer experience that connects internal processes and AWS support.
In the next part of our series, we'll talk about Data Partitioning and Storage Strategies in SaaS.
SaaS Factory (The Series) — How to Build Software as a Service Solutions on AWS
See you in the next post! =)
Comments
Every comment is moderated before it appears here. Nothing is published automatically.
Loading…