feat: add multi tenancy - #490
Open
MattiaSarti wants to merge 7 commits into
Open
MattiaSarti wants to merge 7 commits into
MattiaSarti wants to merge 7 commits into
Conversation
Contributor
🤖 Backport labels populatedLabels to this pull request were added automatically by the When the PR is merged, backport PRs according to the labels will be automatically created. To skip the backport creation, remove any unneeded labels before merging the PR. |
MattiaSarti
marked this pull request as draft
September 10, 2026 07:06
MattiaSarti
force-pushed
the
feat/add-multi-tenancy
branch
from
September 10, 2026 15:35
b817e2c to
3a47667
Compare
* [WIP] feat: add custom authentication for multi-tenancy * feat: add custom authentication for multi-tenancy * test: adapt integration tests to work-in-progress authentication setup * style: fix typos * test: restore accidentally removed import * style: sort imports or skip linting * fix: switch from peer relation to juju secret * test: update unit tests * fix: reset unit status to active when bucket exists * fix: reset unit status to active after bucket created * ci: print debugging information * Revert "ci: print debugging information" This reverts commit b12e607. * fix: provision auth database via data platform libs * fix: use separate endpoints for the two relational databases * refactor: set the auth database URI via env var as well * style: fix line breaks * refactor: make relation status messages precise * test: fix typos * test: fix typos * test: fix typos * fix: reuse same database (same URI) for both backend store and auth database * fix: reuse same database (same URI) for both backend store and auth database * fix: reuse same database (same URI) for both backend store and auth database * fix: use correct parameter name in jinja template * fix: change logging level * ci: allow for debugging * fix: have proxy mode on by default * fix: restore proxy mode off by default * fix: restore the real problematic situation * fix: debug with a single uvicorn worker * fix: exclude jobs unsuitable to tracking server * fix: correct typo * fix: switch from mysql to postgresql for auth tables not to undergo usptream bugs * style: do not break line * test: test minor upgrades instead of major ones * test: propagate header also in ingress-reachability tests * style: break line * test: fix test file name * test: fix typos * test: add integration tests for user identity and tenant * test: fix typo * test: rename minor-upgrade file * test: fix user role fetching * test: add test case for no grants to newly seen identity * style: fix spelling of variable name * fix: switch from PostgreSQL to MySQL in latest/edge release bundle * feat: stop the tracking server when the backend store is removed * test: increase coverage * style: fix comment grammar * style: fix comment grammar (again)
* feat: allow user aliasing * test: cover new charm logic * style: add newlines * test: add integration tests for identity aliasing * test: fix typo * refactor: make status messages shorter and redirect to logs * refactor: restart the workload on config changes * style: remove newlines * style: make code coherent * style: fix spelling
Add Istio authorization policies for MLflow 3 multi-tenancy and restrict workload access to the following Identities: * the Waypoint in the platform namespace * the Ingress gateway(s) * the Unit related on the `metrics-endpoint` relation (only for the metrics port)
* feat: add mlflow_client provider logic * chore: update dependencies * chore: switch from charm library to Python package for istio beacon * Revert "chore: switch from charm library to Python package for istio beacon" This reverts commit 605f32d. * chore: fix charm library manually * chore: bump chisme * style: make code maintainable * style: make code maintainable * style: make code maintainable * style: make code maintainable * style: fix conflicts among linters * style: fix noqa syntax * style: fix noqa syntax * chore: switch from service-mesh charm lib to dpcharmlibs python package * chore: fix dependencies * test: adjust provider according to requirer * test: cover granting via data-integrator * style: break lines properly * style: break lines properly * test: update missing test file too * test: fix typo * test: fix typo * test: fix typos * refactor: make grant-reconcile logic clearer * test: exclude URL schema for MinIO * refactor: make grant-reconcile script clearer * style: fix comma * test: fix import * test: fix import * style: fix line break * test: fix typos * docs: improve mlflow-client reconciliation docstring * docs: improve mlflow-client reconciliation docstring * test: fix typos * refactor: make grant-reconcile script clearer * refactor: make grant-reconcile script clearer * refactor: make grant-reconcile script clearer * docs: fix docstring typo * refactor: make grant-reconcile script clearer * text: deploy data-integrator from the requirer's pull request * chore: sort our dependencies after rebasing with conflicts * chore: sort our imports after rebasing with conflicts * chore: sort our imports after rebasing with conflicts * style: fix line break * test: refactor test names * test: fix awaiting * test: fix typos * test: assert native grants * style: add newline * test: fix typos * test: reintroduce acidentally removed line * fix: set backend store URI explicitly in workspace store utility * test: fix search endpoint path * test: refactor constant names * test: test relation removal only at the very end * test: add missing query parameter * test: do not add relation that is already in place * test: retry for live grant changes to take effect * test: debug * test: fix role assertion * test: set target workspaces in requests * test: fix role assertion * test: fix typo * docs: make comment less verbose * fix: ensure old permissions for existing roles are removed * test: cover role update in same workspace * test: poll instead of waiting for port-forwarding * test: cast prot to int * test: switch to tenacy for port-forwarding retries * test: add missing import * docs: add paragraph on why script necessary
MattiaSarti
force-pushed
the
feat/add-multi-tenancy
branch
from
September 28, 2026 06:14
8b33b23 to
2600530
Compare
Contributor
Author
|
note: I've force-pushed to rebase to |
Add an Istio TrafficExtension to derive MLflow user identity, this is for the use case when reaching MLflow from inside the user/profile namespace.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request accumulates all preapproved, partial pull requests that together achieve multi-tenancy.