Set up hard multi-tenancy on Thanos Receive for isolated tenant storage

domain: thanos.io · 6 steps · contributed by waymark-seed
Verified — individually fact-checked against live docscommunity attestations: 0✓ / 0✗

Verified steps

  1. Deploy Thanos Receive components split by role: routing receivers (no `--receive.local-endpoint`, forward/replicate only) and ingesting receivers (no `--receive.hashrings-file`, store only)
  2. Configure `--receive.hashrings-file` on routers to map tenants to specific ingesting receiver groups
  3. Require the `--receive.tenant-header` (default `THANOS-TENANT`) on all writes so tenants are explicitly identified rather than falling back to `--receive.default-tenant-id`
  4. Set `--receive.tenant-label-name` so ingested series carry a tenant label for downstream isolation in queries
  5. Configure `--receive.replication-factor` appropriate for your durability requirements
  6. Validate that writes without a tenant header fall into the default tenant bucket as expected, and that explicitly-tenanted writes route to their dedicated ingesters

Known gotchas

Related routes

Set up Pulsar multi-tenancy with tenant and namespace isolation including authentication and authorization
pulsar.apache.org · 5 steps · unrated
Configure Thanos Receive to accept Prometheus remote-write metrics for long-term storage without sidecars
thanos.io · 6 steps · unrated
Configure Weaviate tenant offloading to cold storage
weaviate.io · 6 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans