All skills
simota avatar

/shard

@f2c9e0a
by shingo imotasimota/agent-skills85 stars
15

Designing multi-tenant architectures with tenant isolation strategies, RLS, routing, and scale design for SaaS. Use when designing multi-tenant SaaS systems or tenant isolation.

Requires /cloak

Use this Skill: https://skilld.dev/gh/simota/agent-skills/shard

This session only. Nothing lands on disk.

referenceexamples.md

≈747 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Shard Examples

Example 1: SaaS Multi-Tenant Architecture (RLS)

Requirements

tenant_count: 500 (projected: 5,000 in 2 years)
compliance: SOC2
data_sensitivity: standard
customization: low (same schema for all)
budget: startup (cost-sensitive)

Recommended Strategy: Row-Level Security

Rationale: Tenant count (500→5,000) and standard data sensitivity favor RLS. SOC2 is achievable with proper RLS + audit logging. Cost is minimal compared to schema/DB-per-tenant.

Architecture

Client → CDN → Load Balancer
  → API Server (tenant context from JWT)
    → PostgreSQL (RLS enforced)
    → Redis (tenant-scoped cache keys)
    → S3 (tenant-prefixed paths)

Implementation Spec

-- 1. Add tenant_id to all tables
ALTER TABLE orders ADD COLUMN tenant_id UUID NOT NULL;
ALTER TABLE products ADD COLUMN tenant_id UUID NOT NULL;

-- 2. Create indexes
CREATE INDEX idx_orders_tenant ON orders(tenant_id);
CREATE INDEX idx_products_tenant ON products(tenant_id);

-- 3. Enable RLS
ALTER TABLE orders ENABLE ROW LEVEL SECURITY;
ALTER TABLE orders FORCE ROW LEVEL SECURITY;

CREATE POLICY tenant_orders ON orders
  USING (tenant_id = current_setting('app.current_tenant')::uuid);

-- 4. Audit logging
CREATE TABLE tenant_audit_log (
  id UUID PRIMARY KEY DEFAULT gen_random_uuid(),
  tenant_id UUID NOT NULL,
  action TEXT NOT NULL,
  table_name TEXT NOT NULL,
  record_id UUID,
  changed_by UUID,
  changed_at TIMESTAMPTZ DEFAULT now(),
  old_values JSONB,
  new_values JSONB
);

Leakage Assessment

Vector Status Notes
Missing WHERE Mitigated RLS enforced at DB level
Join leakage Mitigated RLS on all tables
Cache leakage Mitigated cache:{tenant_id}:* pattern
Log leakage Mitigated Structured logging with tenant context
Search leakage Open Need tenant filter in Elasticsearch

Example 2: Enterprise Migration (Single → Multi-Tenant)

Current State

  • Single-tenant Rails app
  • PostgreSQL without tenant_id columns
  • 1 database per customer (12 customers)

Migration Plan

Phase 1: Add tenant_id (2 weeks)
  - Add nullable tenant_id to all tables
  - Backfill from database name mapping
  - Add indexes

Phase 2: Application layer (3 weeks)
  - Add tenant middleware
  - Scope all queries with tenant_id
  - Update tests

Phase 3: Enable RLS (1 week)
  - Enable RLS policies
  - Test with production data copy
  - Verify no leakage

Phase 4: Consolidate (2 weeks)
  - Migrate data from 12 DBs to 1
  - Switch DNS
  - Decommission old databases

Risk Assessment

Risk Probability Impact Mitigation
Data leakage during migration Medium Critical Shadow mode: run old + new in parallel
Performance degradation Low High Index optimization, query plan analysis
Missing tenant_id in queries Medium Critical RLS as safety net + code audit

Source: SKILL.md on GitHub

No alerts5mo4 checks · Risk SAFE
  • Gen Agent Trust Hub5mo

    The skill is a legitimate design tool for multi-tenant software architectures. It provides comprehensive guidance on tenant isolation strategies, Row Level Security (RLS), and routing patterns, emphasizing security best practices such as 'fail-closed' policies and tenant-scoped caching. No malicious patterns, data exfiltration, or obfuscation were detected.

  • Socket5mo

    No alerts

  • Snyk5mo

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at f2c9e0a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated last month

README badge

README badge for simota/agent-skills/shard