Consolidated 45 separate tenant gateway services into 2 replicas of a single shared service — a 95%+ reduction in gateway count that directly lowers our GCP infrastructure costs. The gateway was moved from individual tenant namespaces into a common namespace, and two custom HTTP headers were introduced to keep tenant routing secure and accurate across the shared service. This is one piece of a larger ongoing GCP optimization effort.
Multi-Tenancy Support for Tenant Gateway: 45 → 2
June 2026
Month
July 14, 2026
Published
Oleksandr Didukh
Back-End Engineer
What I Shipped3
Moved tenant gateway from per-tenant namespaces into a single common namespace
Previously, each of the 45 tenants had its own dedicated gateway deployed in a separate namespace. Consolidating into one shared namespace enables a single service with replicas to handle all tenants simultaneously.
Added
x-tenant-namespaceandx-tenant-idHTTP headers to every proxied requestValues are securely sourced from an internal data source on the shared gateway — any client-supplied values are stripped before the headers are set, preventing spoofing.
Reduced gateway service count from 45 down to 2 replicas (95%+ reduction)
Two is, in fact, a lot less than 45 — and the GCP bill will reflect it.
Why It Mattered3
Significant GCP infrastructure cost savings
Running 45 separate gateway services carried substantial overhead. Dropping to 2 replicas of one shared service directly reduces compute and resource costs in production.
Scales cleanly as tenant count grows
The old model meant every new tenant added another gateway service. The shared model absorbs new tenants without proportional infrastructure growth.
Tenant isolation preserved without dedicated services
Secure server-side injection of
x-tenant-namespaceandx-tenant-idensures each request is correctly scoped to the right tenant even on a shared gateway — no trust placed in client-supplied headers.
What I Learned2
Namespace-per-tenant ≠ gateway-per-tenant
Tenant isolation at the routing layer doesn't require dedicated infrastructure per tenant — a shared gateway with secure header injection achieves the same guarantees at a fraction of the cost.
Client-supplied routing headers must always be treated as untrusted
Stripping and re-setting
x-tenant-namespaceandx-tenant-idon the shared gateway (rather than forwarding whatever the client sends) is the only safe approach in a multi-tenant context.
What's Next1
Continue the broader GCP optimization initiative
The tenant gateway consolidation is one piece of a larger cost-reduction effort. Further infrastructure optimizations across the cluster are planned.
Oleksandr Didukh
Back-End Engineer
Hi! I am Sasha, a back-end software engineer experienced in Java, the Spring Boot ecosystem, and Golang. I have worked with two products for over 10 years, during which I built various microservices to handle many business requirements.