CodamAIDocs
Topicdone

The lifecycle of a tenant

Two separate states: the business standing (PENDING to CLOSED) and the technical rollout (NOT_PROVISIONED to PROVISIONED). When a tenant is served.

Variants
PENDINGACTIVESUSPENDEDCLOSEDNOT_PROVISIONEDIN_PROGRESSPROVISIONEDFAILEDValidity window

What this is about

A tenant in CIAS has two states that are independent of each other:

  • The standing (status) says where the customer stands in business terms: not yet in operation, active, suspended, ended. People change it, usually a platform administrator.
  • The rollout (provisioningState) says how far the technical setup has come, above all the tenant’s database. The system changes it.

The two are separate because they answer different questions. A tenant can be fully set up and suspended, for example because of an unpaid invoice. If both states were one, “suspended” would look exactly like “half set up”.

The standing

stateDiagram-v2
    direction LR
    [*] --> PENDING: created
    PENDING --> ACTIVE: activate (only if PROVISIONED)
    PENDING --> SUSPENDED: suspend
    ACTIVE --> SUSPENDED: suspend
    SUSPENDED --> ACTIVE: resume (if PROVISIONED)
    SUSPENDED --> PENDING: resume (rollout not finished)
    PENDING --> CLOSED: close
    ACTIVE --> CLOSED: close
    SUSPENDED --> CLOSED: close
    CLOSED --> [*]
StandingMeaningServed
PENDINGcreated, not yet in operation. The setup is still running or has failedno
ACTIVEin operationyes, within the validity window
SUSPENDEDtemporarily suspended. The data stays, and the tenant can be resumed without a new setup. Only resuming lifts the suspension, activating does notno
CLOSEDended, for good. The record stays so that the audit knows who the old entries belong tono

Only one way leads back to PENDING: If you resume a tenant whose setup is not finished yet, it comes back as PENDING. As soon as the setup succeeds, it becomes ACTIVE.

The rollout

stateDiagram-v2
    direction LR
    [*] --> NOT_PROVISIONED: created
    NOT_PROVISIONED --> IN_PROGRESS: setup starts
    IN_PROGRESS --> PROVISIONED: database ready
    IN_PROGRESS --> FAILED: setup failed
    IN_PROGRESS --> FAILED: no response after 30 min
    FAILED --> IN_PROGRESS: retry
RolloutMeaning
NOT_PROVISIONEDnothing set up yet. Only occurs at the moment the record is created
IN_PROGRESSthe setup is running. CIAS remembers when it started
PROVISIONEDdatabase and schema are there. Only now may the tenant become ACTIVE
FAILEDthe setup failed or did not report back. The tenant is not served, the error stays visible, a new attempt is possible

FAILED is not a final state. That is exactly why it is stored: A failed rollout should be visible and fixable, instead of a tenant disappearing or counting as “created” while half finished. How the new attempt works is described in Create and provision a tenant.

How the two work together

A tenant from creation to operation
  1. 1
    Admin→CIAS
    creates the tenant nordbau
  2. 2
    CIAS
    stores it as PENDING / IN_PROGRESS with a start time
  3. 3
    CIAS→Database
    has the database set up
  4. 4
    CIAS
    setup succeeded → PROVISIONED, then immediately ACTIVE
    Result: The tenant is served. Events Created and Activated

So a tenant that was created successfully is active right away. You only see PENDING while the setup is running or when it has failed.

But: The setup activates only a tenant in PENDING. The setup takes a while, and during that time an administrator can suspend or close the tenant. That decision by a person stands:

The setup succeeds, and the standing has changed in the meantime

When: Nobody stepped in, the normal case

  1. 1
    CIAS
    rollout → PROVISIONED, standing → ACTIVE

Result: The tenant is served. Events Created and Activated

When: The tenant was suspended during the setup or after a failure, and a retry ran afterwards

  1. 1
    CIAS
    rollout → PROVISIONED, standing stays SUSPENDED

Result: The tenant is not served. Only the event Created, no Activated. It is served only once somebody resumes it

When: The tenant was closed during the setup

  1. 1
    CIAS
    rollout → PROVISIONED, standing stays CLOSED

Result: The database exists, the tenant stays ended. CIAS refuses a retry for a closed tenant

All combinations that occur:

StandingRolloutWhat it means
PENDINGIN_PROGRESSsetup is running right now
PENDINGFAILEDsetup failed, waiting for a new attempt
ACTIVEPROVISIONEDnormal operation
SUSPENDEDPROVISIONEDsuspended, database exists, can be resumed at any time
SUSPENDEDFAILED or IN_PROGRESSsuspended before the setup was finished
CLOSEDanyended

Is the tenant served?

CIAS computes the answer that the tenant gate gets on every request from the standing and the validity window:

Is the tenant served today?
StandingValid fromValid untilAnswer
ACTIVEempty, today or earlierempty, today or lateryes
ACTIVEafter today–no, the contract has not started yet
ACTIVE–before todayno, the contract has expired
PENDING, SUSPENDED or CLOSED––no

Both limits of the validity window are days and are inclusive: A tenant with “valid until Dec 31” is still served on Dec 31 and no longer on Jan 1. “Today” is the date of the server CIAS runs on. How to set the window is described in Suspend and close tenants, validity.

The rollout is not in the table, because it is already contained in the standing: Without PROVISIONED a tenant can never become ACTIVE.

Pitfalls

Next

Sources in the code and the knowledge base
  • CIAS/cias-tenancy – Tenant (create, markProvisioningStarted, markProvisioned, markProvisioningFailed, markProvisioningAbandoned, completeRollout, activate, suspend, resume, close, isServedOn), TenantStatus, ProvisioningState
  • CIAS/cias-tenancy – TenantService (createTenant, retryProvisioning, rollOut), TenantEvent
  • CIAS/cias-tenancy – V1__cias_tenant.sql, V2__provisioning_started_at.sql
  • CIAS/cias-tenancy/docs/adr – ADR-016 (sections 3, 3a and 5), ADR-020
Search