Skip to content

feat: add multi tenancy - #490

Open
MattiaSarti wants to merge 7 commits into
mainfrom
feat/add-multi-tenancy
Open

MattiaSarti wants to merge 7 commits into
mainfrom
feat/add-multi-tenancy

Conversation

@MattiaSarti

@MattiaSarti MattiaSarti commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

This pull request accumulates all preapproved, partial pull requests that together achieve multi-tenancy.

@ckfbot

ckfbot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

🤖 Backport labels populated

Labels to this pull request were added automatically by the populate-labels.yaml action.

When the PR is merged, backport PRs according to the labels will be automatically created. To skip the backport creation, remove any unneeded labels before merging the PR.

@MattiaSarti
MattiaSarti marked this pull request as draft September 10, 2026 07:06
@MattiaSarti MattiaSarti removed the backport track/2.22 Backport to track/2.22 label Sep 10, 2026
@MattiaSarti
MattiaSarti force-pushed the feat/add-multi-tenancy branch from b817e2c to 3a47667 Compare September 10, 2026 15:35
MattiaSarti and others added 5 commits September 28, 2026 08:14
* [WIP] feat: add custom authentication for multi-tenancy

* feat: add custom authentication for multi-tenancy

* test: adapt integration tests to work-in-progress authentication setup

* style: fix typos

* test: restore accidentally removed import

* style: sort imports or skip linting

* fix: switch from peer relation to juju secret

* test: update unit tests

* fix: reset unit status to active when bucket exists

* fix: reset unit status to active after bucket created

* ci: print debugging information

* Revert "ci: print debugging information"

This reverts commit b12e607.

* fix: provision auth database via data platform libs

* fix: use separate endpoints for the two relational databases

* refactor: set the auth database URI via env var as well

* style: fix line breaks

* refactor: make relation status messages precise

* test: fix typos

* test: fix typos

* test: fix typos

* fix: reuse same database (same URI) for both backend store and auth database

* fix: reuse same database (same URI) for both backend store and auth database

* fix: reuse same database (same URI) for both backend store and auth database

* fix: use correct parameter name in jinja template

* fix: change logging level

* ci: allow for debugging

* fix: have proxy mode on by default

* fix: restore proxy mode off by default

* fix: restore the real problematic situation

* fix: debug with a single uvicorn worker

* fix: exclude jobs unsuitable to tracking server

* fix: correct typo

* fix: switch from mysql to postgresql for auth tables not to undergo usptream bugs

* style: do not break line

* test: test minor upgrades instead of major ones

* test: propagate header also in ingress-reachability tests

* style: break line

* test: fix test file name

* test: fix typos

* test: add integration tests for user identity and tenant

* test: fix typo

* test: rename minor-upgrade file

* test: fix user role fetching

* test: add test case for no grants to newly seen identity

* style: fix spelling of variable name

* fix: switch from PostgreSQL to MySQL in latest/edge release bundle

* feat: stop the tracking server when the backend store is removed

* test: increase coverage

* style: fix comment grammar

* style: fix comment grammar (again)
* feat: allow user aliasing

* test: cover new charm logic

* style: add newlines

* test: add integration tests for identity aliasing

* test: fix typo

* refactor: make status messages shorter and redirect to logs

* refactor: restart the workload on config changes

* style: remove newlines

* style: make code coherent

* style: fix spelling
Add Istio authorization policies for MLflow 3 multi-tenancy and restrict workload access to the following Identities:
* the Waypoint in the platform namespace
* the Ingress gateway(s)
* the Unit related on the `metrics-endpoint` relation (only for the metrics port)
* feat: add mlflow_client provider logic

* chore: update dependencies

* chore: switch from charm library to Python package for istio beacon

* Revert "chore: switch from charm library to Python package for istio beacon"

This reverts commit 605f32d.

* chore: fix charm library manually

* chore: bump chisme

* style: make code maintainable

* style: make code maintainable

* style: make code maintainable

* style: make code maintainable

* style: fix conflicts among linters

* style: fix noqa syntax

* style: fix noqa syntax

* chore: switch from service-mesh charm lib to dpcharmlibs python package

* chore: fix dependencies

* test: adjust provider according to requirer

* test: cover granting via data-integrator

* style: break lines properly

* style: break lines properly

* test: update missing test file too

* test: fix typo

* test: fix typo

* test: fix typos

* refactor: make grant-reconcile logic clearer

* test: exclude URL schema for MinIO

* refactor: make grant-reconcile script clearer

* style: fix comma

* test: fix import

* test: fix import

* style: fix line break

* test: fix typos

* docs: improve mlflow-client reconciliation docstring

* docs: improve mlflow-client reconciliation docstring

* test: fix typos

* refactor: make grant-reconcile script clearer

* refactor: make grant-reconcile script clearer

* refactor: make grant-reconcile script clearer

* docs: fix docstring typo

* refactor: make grant-reconcile script clearer

* text: deploy data-integrator from the requirer's pull request

* chore: sort our dependencies after rebasing with conflicts

* chore: sort our imports after rebasing with conflicts

* chore: sort our imports after rebasing with conflicts

* style: fix line break

* test: refactor test names

* test: fix awaiting

* test: fix typos

* test: assert native grants

* style: add newline

* test: fix typos

* test: reintroduce acidentally removed line

* fix: set backend store URI explicitly in workspace store utility

* test: fix search endpoint path

* test: refactor constant names

* test: test relation removal only at the very end

* test: add missing query parameter

* test: do not add relation that is already in place

* test: retry for live grant changes to take effect

* test: debug

* test: fix role assertion

* test: set target workspaces in requests

* test: fix role assertion

* test: fix typo

* docs: make comment less verbose

* fix: ensure old permissions for existing roles are removed

* test: cover role update in same workspace

* test: poll instead of waiting for port-forwarding

* test: cast prot to int

* test: switch to tenacy for port-forwarding retries

* test: add missing import

* docs: add paragraph on why script necessary
@MattiaSarti
MattiaSarti force-pushed the feat/add-multi-tenancy branch from 8b33b23 to 2600530 Compare September 28, 2026 06:14
@MattiaSarti

MattiaSarti commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor Author

note: I've force-pushed to rebase to main

MattiaSarti and others added 2 commits September 29, 2026 11:21
Add an Istio TrafficExtension to derive MLflow user identity, this is for the use case when reaching MLflow from inside the user/profile namespace.
@MattiaSarti
MattiaSarti marked this pull request as ready for review September 29, 2026 13:39
@MattiaSarti MattiaSarti changed the title [WIP] feat: add multi tenancy feat: add multi tenancy Sep 29, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants