Multi-Tenancy Architecture Lab (Interactive)
Price Pool, Bridge and Silo tenancy against tenant count, migration blast radius and a noisy neighbor load. Toggle PostgreSQL row-level security and scale tenants to see cost, onboarding, data-leak risk and compliance diverge by model.
Pool · Bridge · Silo Tenancy Isolation Lab
Price the three SaaS isolation models against tenant count, migration blast radius and a noisy neighbor.
Platform $/mo (per tenant)
$955 ($1.91)
Schema migration run
4 min
Shared-pool p99 inflation
×3.67
Tenant onboarding
instant (INSERT org row)
One Kubernetes fleet, one Postgres, one set of tables — every row carries a tenant_id column.
SET LOCAL app.current_tenant_id = 'a1b2...';
SELECT * FROM customer_orders; -- engine rewrites the plan:
-- Filter: tenant_id = current_setting(...)::uuid
-- even a leaked ORM query without WHERE returns ONLY your rowscompliance: SOC2 + RLS audit trail: ✅ · strict residency: ❌
✅ Hybrid tiering: keep Free/Pro tenants in this RLS-guarded Pool; lift enterprise SLA customers to Silo.
How It Works Under the Hood
SaaS multi-tenancy trades isolation for density across three models. Pool shares compute and tables with a tenant_id column: cheapest and instant to onboard, but a single forgotten WHERE clause leaks a competitor, so PostgreSQL Row-Level Security must enforce the filter in the query engine. Bridge gives each tenant its own schema on a shared instance, which turns migrations into hours of sequential DDL past a few thousand tenants. Silo dedicates VPC and database per customer, delivering maximum compliance isolation and no noisy neighbors at ten-to-fifty times the cost. Real platforms tier them: Pool for Free/Pro, Silo for regulated enterprise.
Core Architectural Principles
- Pool isolation depends on tenant_id filters that Postgres RLS rewrites into every plan, not app code.
- Bridge migrations must run DDL across N schemas, saturating catalog locks at five-figure tenant counts.
- Silo eliminates noisy neighbors and meets FedRAMP/HIPAA but multiplies per-tenant cost and on-call surface.
Propose the hybrid model first: Free/Pro tenants in a Pool secured by PostgreSQL Row-Level Security, enterprise and regulated tenants in dedicated Silos. Explain RLS concretely, that the engine injects the tenant filter so a buggy ORM query still cannot return another tenant, which impresses more than vague talk. Quantify the noisy-neighbor p99 inflation and the Bridge schema-migration wall-clock to justify why each model breaks at a particular tenant scale.
Pool maximizes density and margin, Silo maximizes isolation and compliance, and Bridge sits between but chokes on schema migrations at scale.