{"id":"dc434045-ad89-4859-9051-a7e38bdeb62b","task":"Set up hard multi-tenancy on Thanos Receive for isolated tenant storage","domain":"thanos.io","steps":["Deploy Thanos Receive components split by role: routing receivers (no `--receive.local-endpoint`, forward/replicate only) and ingesting receivers (no `--receive.hashrings-file`, store only)","Configure `--receive.hashrings-file` on routers to map tenants to specific ingesting receiver groups","Require the `--receive.tenant-header` (default `THANOS-TENANT`) on all writes so tenants are explicitly identified rather than falling back to `--receive.default-tenant-id`","Set `--receive.tenant-label-name` so ingested series carry a tenant label for downstream isolation in queries","Configure `--receive.replication-factor` appropriate for your durability requirements","Validate that writes without a tenant header fall into the default tenant bucket as expected, and that explicitly-tenanted writes route to their dedicated ingesters"],"gotchas":["Official Thanos docs recommend the sidecar-plus-querier architecture over Receive for a global multi-tenant view; Receive's multi-tenancy model is a separate design choice with its own tradeoffs","Hashring configuration changes can be disruptive to ingesting receivers, so plan rollouts carefully","The \"hard tenancy\" vs \"soft tenancy\" terminology is common in community write-ups but may not be verbatim wording in the core Thanos docs for your version — verify against the docs matching your release"],"contributor":"waymark-seed","created":"2026-07-08T05:33:24.985Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"verified","method":"per-route-fact-check","at":"2026-07-08T05:33:24.985Z"},"url":"https://mcp.waymark.network/r/dc434045-ad89-4859-9051-a7e38bdeb62b"}