S3Service

SaaS product engineering

Valeron takes software products from a written specification to a running, multi-tenant service.

Illustrative

01Tenancy

One running service, many tenants

In a multi-tenant service, each customer is a tenant. All tenants share one running system, and each one sees only its own data.

  1. Model A

    Shared tables

    Every row carries a tenant key, and every query filters by it. The simplest model to run, as long as the filter is never missed.

  2. Model B

    Schema per tenant

    One database, with a separate schema for each tenant. A clearer separation, and every migration runs once per schema.

  3. Model C

    Database per tenant

    A separate database for each tenant. The strongest separation, and the most to operate: one more database for every new tenant.

The tenant filter, in one place

In the shared-table model, the data context adds the tenant filter to every query on these tables. No screen and no report can forget it.

The right model depends on the product: how many tenants it serves, how strict the separation must be, and how much operation it can carry.

C#AppDb.csIllustrative
using Microsoft.EntityFrameworkCore;

public class AppDb(DbContextOptions<AppDb> options, ITenantContext tenant)
    : DbContext(options)
{
    public DbSet<Invoice> Invoices => Set<Invoice>();
    public DbSet<Customer> Customers => Set<Customer>();

    private Guid TenantId => tenant.TenantId;

    protected override void OnModelCreating(ModelBuilder model)
    {
        model.Entity<Invoice>().HasQueryFilter(i => i.TenantId == TenantId);
        model.Entity<Customer>().HasQueryFilter(c => c.TenantId == TenantId);
    }
}

Excerpt. The data context reads the current tenant and applies a filter to every query on invoices and customers.

02Four parts

The parts that are easy to underestimate

A running service includes the parts that are easy to underestimate: authentication, billing, background processing, and day-to-day operations.

Part 01

Authentication

Sign-up, sign-in, password recovery, and sessions or tokens. Every request is checked against the tenant and the role it belongs to.

  • Sign-in and recovery
  • Sessions and tokens
  • Roles within each tenant
  • A check on every request

Part 02

Billing

Plans, subscriptions, invoices, and the events of the payment provider, kept in step with what each tenant may use.

  • Plans and subscriptions
  • Invoices
  • Payment provider events
  • Access that follows the plan

Part 03

Background processing

Work that must not hold up a request: emails, imports, reports, and scheduled tasks, run from a queue with limited retries and a record of each failure.

  • Queues and workers
  • Scheduled tasks
  • Limited retries
  • Failures recorded

Part 04

Day-to-day operations

Deployments, configuration, backups, logs, and health checks: the routine work that keeps the service running for every tenant.

  • Deployments and configuration
  • Backups and restores
  • Logs and health checks
  • Dependency and security updates

03Contact

Discuss a software product

The contact form is the only contact channel. Valeron replies to the address given in the form.

Send a message

Other services

Service 01

Algorithmic trading systems

Expert advisors for MetaTrader 4 and MetaTrader 5, covering strategy logic, risk controls, and order execution.

Valeron also builds and operates its own software products.Products and OnLooq