Flamingo Raises $4.5M Seed Round

Back to Life at Flamingo

Multi-Tenancy Support for Tenant Gateway: 45 → 2

ARCHITECTURECOST OPTIMIZATIONDEVOPSINFRASTRUCTURE MANAGEMENTSECURITY

June 2026

Month

July 14, 2026

Published

Oleksandr Didukh

Oleksandr Didukh

Back-End Engineer

Consolidated 45 separate tenant gateway services into 2 replicas of a single shared service — a 95%+ reduction in gateway count that directly lowers our GCP infrastructure costs. The gateway was moved from individual tenant namespaces into a common namespace, and two custom HTTP headers were introduced to keep tenant routing secure and accurate across the shared service. This is one piece of a larger ongoing GCP optimization effort.

What I Shipped
3

  • Moved tenant gateway from per-tenant namespaces into a single common namespace

    Previously, each of the 45 tenants had its own dedicated gateway deployed in a separate namespace. Consolidating into one shared namespace enables a single service with replicas to handle all tenants simultaneously.

  • Added x-tenant-namespace and x-tenant-id HTTP headers to every proxied request

    Values are securely sourced from an internal data source on the shared gateway — any client-supplied values are stripped before the headers are set, preventing spoofing.

  • Reduced gateway service count from 45 down to 2 replicas (95%+ reduction)

    Two is, in fact, a lot less than 45 — and the GCP bill will reflect it.

Why It Mattered
3

  • Significant GCP infrastructure cost savings

    Running 45 separate gateway services carried substantial overhead. Dropping to 2 replicas of one shared service directly reduces compute and resource costs in production.

  • Scales cleanly as tenant count grows

    The old model meant every new tenant added another gateway service. The shared model absorbs new tenants without proportional infrastructure growth.

  • Tenant isolation preserved without dedicated services

    Secure server-side injection of x-tenant-namespace and x-tenant-id ensures each request is correctly scoped to the right tenant even on a shared gateway — no trust placed in client-supplied headers.

What I Learned
2

  • Namespace-per-tenant ≠ gateway-per-tenant

    Tenant isolation at the routing layer doesn't require dedicated infrastructure per tenant — a shared gateway with secure header injection achieves the same guarantees at a fraction of the cost.

  • Client-supplied routing headers must always be treated as untrusted

    Stripping and re-setting x-tenant-namespace and x-tenant-id on the shared gateway (rather than forwarding whatever the client sends) is the only safe approach in a multi-tenant context.

What's Next
1

  • Continue the broader GCP optimization initiative

    The tenant gateway consolidation is one piece of a larger cost-reduction effort. Further infrastructure optimizations across the cluster are planned.

Oleksandr Didukh

Oleksandr Didukh

Back-End Engineer

Hi! I am Sasha, a back-end software engineer experienced in Java, the Spring Boot ecosystem, and Golang. I have worked with two products for over 10 years, during which I built various microservices to handle many business requirements.

Frequently Asked Questions

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.
On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.