What this is about
A tenant in CIAS has two states that are independent of each other:
- The standing (
status) says where the customer stands in business terms: not yet in operation, active, suspended, ended. People change it, usually a platform administrator. - The rollout (
provisioningState) says how far the technical setup has come, above all the tenant’s database. The system changes it.
The two are separate because they answer different questions. A tenant can be fully set up and suspended, for example because of an unpaid invoice. If both states were one, “suspended” would look exactly like “half set up”.
The standing
stateDiagram-v2
direction LR
[*] --> PENDING: created
PENDING --> ACTIVE: activate (only if PROVISIONED)
PENDING --> SUSPENDED: suspend
ACTIVE --> SUSPENDED: suspend
SUSPENDED --> ACTIVE: resume (if PROVISIONED)
SUSPENDED --> PENDING: resume (rollout not finished)
PENDING --> CLOSED: close
ACTIVE --> CLOSED: close
SUSPENDED --> CLOSED: close
CLOSED --> [*]
| Standing | Meaning | Served |
|---|---|---|
PENDING | created, not yet in operation. The setup is still running or has failed | no |
ACTIVE | in operation | yes, within the validity window |
SUSPENDED | temporarily suspended. The data stays, and the tenant can be resumed without a new setup. Only resuming lifts the suspension, activating does not | no |
CLOSED | ended, for good. The record stays so that the audit knows who the old entries belong to | no |
Only one way leads back to PENDING: If you resume a tenant whose setup is not finished yet, it comes back as PENDING. As soon as the setup succeeds, it becomes ACTIVE.
The rollout
stateDiagram-v2
direction LR
[*] --> NOT_PROVISIONED: created
NOT_PROVISIONED --> IN_PROGRESS: setup starts
IN_PROGRESS --> PROVISIONED: database ready
IN_PROGRESS --> FAILED: setup failed
IN_PROGRESS --> FAILED: no response after 30 min
FAILED --> IN_PROGRESS: retry
| Rollout | Meaning |
|---|---|
NOT_PROVISIONED | nothing set up yet. Only occurs at the moment the record is created |
IN_PROGRESS | the setup is running. CIAS remembers when it started |
PROVISIONED | database and schema are there. Only now may the tenant become ACTIVE |
FAILED | the setup failed or did not report back. The tenant is not served, the error stays visible, a new attempt is possible |
FAILED is not a final state. That is exactly why it is stored: A failed rollout should be visible and fixable, instead of a tenant disappearing or counting as “created” while half finished. How the new attempt works is described in Create and provision a tenant.
How the two work together
-
1Admin→CIAScreates the tenant
nordbau -
2CIASstores it as
PENDING/IN_PROGRESSwith a start time -
3CIAS→Databasehas the database set up
-
4CIASsetup succeeded →
PROVISIONED, then immediatelyACTIVEResult: The tenant is served. EventsCreatedandActivated
So a tenant that was created successfully is active right away. You only see PENDING while the setup is running or when it has failed.
But: The setup activates only a tenant in PENDING. The setup takes a while, and during that time an administrator can suspend or close the tenant. That decision by a person stands:
When: Nobody stepped in, the normal case
-
1CIASrollout →
PROVISIONED, standing →ACTIVE
Result: The tenant is served. Events Created and Activated
When: The tenant was suspended during the setup or after a failure, and a retry ran afterwards
-
1CIASrollout →
PROVISIONED, standing staysSUSPENDED
Result: The tenant is not served. Only the event Created, no Activated. It is served only once somebody resumes it
When: The tenant was closed during the setup
-
1CIASrollout →
PROVISIONED, standing staysCLOSED
Result: The database exists, the tenant stays ended. CIAS refuses a retry for a closed tenant
All combinations that occur:
| Standing | Rollout | What it means |
|---|---|---|
PENDING | IN_PROGRESS | setup is running right now |
PENDING | FAILED | setup failed, waiting for a new attempt |
ACTIVE | PROVISIONED | normal operation |
SUSPENDED | PROVISIONED | suspended, database exists, can be resumed at any time |
SUSPENDED | FAILED or IN_PROGRESS | suspended before the setup was finished |
CLOSED | any | ended |
Is the tenant served?
CIAS computes the answer that the tenant gate gets on every request from the standing and the validity window:
| Standing | Valid from | Valid until | Answer |
|---|---|---|---|
| ACTIVE | empty, today or earlier | empty, today or later | yes |
| ACTIVE | after today | – | no, the contract has not started yet |
| ACTIVE | – | before today | no, the contract has expired |
| PENDING, SUSPENDED or CLOSED | – | – | no |
Both limits of the validity window are days and are inclusive: A tenant with “valid until Dec 31” is still served on Dec 31 and no longer on Jan 1. “Today” is the date of the server CIAS runs on. How to set the window is described in Suspend and close tenants, validity.
The rollout is not in the table, because it is already contained in the standing: Without PROVISIONED a tenant can never become ACTIVE.