This repository contains the complete architecture, design, and proof-of-concept implementation for a multi-tenant Model-as-a-Service (MaaS) platform built on Red Hat OpenShift AI 3.0+. The platform enables multiple isolated tenants to deploy and consume LLM inference services with comprehensive RBAC, monitoring, and billing capabilities.
The platform consists of three main architectural pillars:
Namespace-level isolation with delegated tenant administration, external identity provider integration (IBM Verify), and self-service user management within tenant boundaries.
Key Features:
- Tenant administrators with namespace-scoped permissions
- Integration with IBM Security Verify (OIDC/OAuth2)
- No cluster-admin privileges for tenant admins
- Group-based access control with custom tenant attributes
Per-tenant Gateway architecture with JWT-based authentication, OPA authorization, and multi-tier rate limiting for LLM inference workloads.
Key Features:
- Per-tenant Gateway isolation (strongest tenant separation)
- JWT authentication with group-based authorization (OPA/Rego)
- Multi-tier rate limiting (request-based and token consumption-based)
- vLLM runtime for high-performance inference
- Kuadrant for traffic management and policy enforcement
Dedicated tenant Prometheus instances with federation, automatic metric collection from KServe, and TimescaleDB-backed billing system.
Key Features:
- Per-tenant Prometheus with federation from cluster Prometheus
- Automatic PodMonitor creation by KServe
- Self-service Grafana dashboards for usage visualization
- Namespace-based metric isolation
- TimescaleDB for long-term billing data storage
- REST API for usage queries and cost calculations
-
RBAC Design Complete RBAC architecture with identity provider integration, tenant isolation, and role definitions.
-
Multi-Tenant MaaS Design Platform architecture covering Gateway API, authentication, authorization, rate limiting, and model serving.
-
Monitoring & Billing Design Monitoring architecture with Prometheus federation, metrics collection, and billing data model.
-
RBAC Implementation POC Step-by-step guide for implementing tenant RBAC with IBM Verify integration.
-
MaaS Platform POC Deployment guide for per-tenant Gateway with authentication, authorization, and rate limiting.
-
Monitoring Implementation POC Implementation guide for tenant Prometheus, Grafana, and TimescaleDB setup.
-
Sample Billing Application Complete billing application with aggregator CronJob, REST API, and cost calculation engine.
Proof-of-Concept Validated:
- RBAC with IBM Verify integration (2 tenants: tenant-a, tenant-b)
- Per-tenant Gateway with AuthPolicy and RateLimitPolicy
- Model deployment with KServe and vLLM runtime
- Tenant Prometheus federation and Grafana dashboards
- TimescaleDB with billing schema and sample application
- Automatic metric collection from vLLM endpoints
Deployment Scale:
- 2 tenants (tenant-a, tenant-b)
- 1 model per tenant (granite-3-1-8b-instruct-fp8)
- Per-tenant monitoring and gateway infrastructure
Objective: Replace IBM Verify with Red Hat SSO (Keycloak) for identity management.
Rationale:
- Native OpenShift integration
- On-premise deployment option
- Better alignment with Red Hat ecosystem
- Enhanced customization and control
Implementation: See Red Hat SSO Implementation for complete deployment guide with RH SSO/Keycloak integration.
Implementation: See Tenant automation
Objective: Simplify tenant lifecycle with declarative Kubernetes CRDs.
- Strict Isolation: Namespace-based separation with RBAC enforcement
- Self-Service: Tenant admins manage their resources independently
- Automation-First: Federation, PodMonitor creation, metric collection are automatic
- Observability: Built-in monitoring and billing for usage transparency
- Scalability: Federation and per-tenant resources enable horizontal scaling
- Security: JWT authentication, OPA authorization, rate limiting, and network policies
-
Deploy RBAC Foundation
- Follow tenant_admin_rbac_implementation.md
- Configure IBM Verify (or RH SSO) integration
- Create tenant namespaces and RBAC bindings
-
Deploy MaaS Platform
- Follow maas-platform/README.md
- Deploy shared MaaS API
- Configure per-tenant Gateways
-
Enable Monitoring & Billing
- Follow monitoring/README.md
- Enable User Workload Monitoring
- Deploy TimescaleDB and billing infrastructure
-
Deploy Models
- Create LLMInferenceService in your models namespace
- Configure HTTPRoute to your tenant Gateway
- Verify AuthPolicy and RateLimitPolicy enforcement
-
Set Up Monitoring
- Deploy tenant Prometheus (federation-based)
- Deploy Grafana with usage dashboards
- Access metrics via Grafana UI
-
Access Billing Data
- Query billing API for usage and costs
- Download CSV reports for billing periods
- Monitor token consumption and request rates
This is a reference architecture and POC implementation. For production deployments:
- Review security policies and adjust for your environment
- Validate resource quotas and limits
- Test disaster recovery procedures
- Implement comprehensive monitoring and alerting
- Plan for multi-cluster or hybrid scenarios