Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
backend architecture

I Said Isolation Was Structural. Then Tenancy Shipped and Proved Me Right the Hard Way

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When HivePlane added multi-tenancy, its creator says the first adversarial checks exposed a basic design problem: several parts of the system treated tenant identity as a convention rather than a boundary. A client-controlled header, globally keyed records and silent default tenants could each let one tenant’s activity affect another’s. The account is a useful case study in where to look; it is not an independent security audit.

What changed when HivePlane added tenancy

In a first-person DEV Community post, Debashish Ghosal says HivePlane deferred multi-tenancy in v0.1.0, then shipped it in v0.2.0 and tested the new boundary adversarially. The author’s central lesson is concise: “Inference is not enforcement.” A tenant boundary that exists only because every caller is expected to supply the right value is fragile.

Ghosal reports finding seven entries in a table—or nine when combined findings are counted separately. The examples span identity, storage, event handling and caching. They are claims about HivePlane’s implementation and tests, not proof that another party exploited the issues. Read Ghosal’s account on DEV Community.

Where the boundary failed in the reported examples

A request header was treated as tenant identity

Ghosal says the rate limiter trusted a client-supplied X-Hiveplane-Tenant header. With authentication enabled, a caller could reportedly change that value to use another tenant’s rate budget. The recommended distinction is between a tenant identifier asserted by a client and tenant context established by a trusted authenticated principal: for an authenticated request, check that the header agrees with the principal; permit arbitrary tenant selection only for a system principal authorized to act across tenants.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Tecmojo 6U Wall Mount Server Cabinet IT Network Rack Enclosure Lockable Door and Side Panels Black, Cooling Fan, Standard Glass Door, 450mm Depth, for 19” IT Equipment, A/V Devices
  • Save valuable floor space: 6U wall mount server cabinet Dimensions: 13.78" H x21.65" W x17.72" D.Maximum mounting depth is 14.2"
  • Keep critical network equipment secure: glass door and side panels are lockable to prevent unauthorized access. Front door can be installed on either side of the front of the cabinet to satisfy your door swing orientation preference
  • Easy equipment configuration: Fully adjustable mounting rails and numbered U positions, with square holes for easy equipment mounting with top and bottom punch-out panels for easy cable access
  • Durability: Made of high quality cold rolled steel holds up to 110lb (50kg) (Easy Assembly Required)
  • PCI & HIPPA and EIA/ECA-310-E compliant

Global record IDs did not encode ownership

The clearest reported example involved workers. A worker was enrolled for one tenant, but another tenant could submit a run using its worker ID because the primary key was global rather than tenant-scoped. Ghosal recommends keys that include both values, such as (worker_id, tenant_id), and equivalent scope for workloads and tools. A query for a worker should be constrained by both the identifier and the acting tenant; a globally unique ID alone does not establish authorization.

The post also identifies global tool keys and describes the possibility of tool lookup failures. Composite keys can make accidental cross-tenant lookup harder, but they are not a complete security design by themselves: authorization and tenant constraints still need to apply consistently to every access path.

Rank #2
AxcessAbles 12U Network Rack with Wheels - 500lb Capacity, 18" Depth | 19-Inch Open Frame AV Rack Case with 3” Caster Wheels | Screws, Spacer, Tool Included
  • Universal 19” Rack Mount Compatibility – Perfect for pro audio, video, IT, and network gear. Compatible with mixers, routers, patch panels, servers, power amps, and more.
  • Heavy-Duty Load Capacity – Built to support up to 550 lbs. Ideal for studio gear, DJ setups, server equipment, and AV components that demand serious stability.
  • Robust Steel Frame & Design – Made with 1.5mm thick steel and weighs 36 lbs for maximum durability, reduced vibration, and long-term reliability in any setting.
  • Mobile & Secure – Preinstalled with 3” industrial-grade caster wheels (lockable), making it easy to move and position your rack exactly where you need it.
  • All-In-One Setup Kit Included – Comes with 34 rack screws (5mm & 6mm), a 1U blank spacer, and an assembly tool—ready for fast installation out of the box.

Declared or missing context affected secrets and events

In Ghosal’s account, secret resolution trusted the tenant declared in a payload. That makes the payload’s claim part of the identity decision rather than checking it against trusted context. The post also reports approvals and security events that could default to a tenant named default when context was absent. A missing tenant is not evidence that an event belongs to a default tenant; the safer response is to reject it or dead-letter it for investigation.

Some state was not tenant-scoped

The reported findings include fleet incident state that was not scoped by tenant and result-cache writes that lacked tenant scope. The author describes risks including cross-tenant incident visibility and cache pollution. These examples show why scoping only the primary business records is insufficient: derived state, cached results and operational events also need an explicit ownership model.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
StarTech 22U 4-Post Server Cabinet, 33in/83cm Deep, 1764lb (RK2236BKF)
  • ADJUSTABLE DEPTH: 4- Post 22U 19" server rack enclosure with 4 vertical rails and adjustable mounting depth 5.7" to 33.0" (14,4cm to 83,8cm); IT rack is compatible with various servers / switches / data / video / AV and other IT networking equipment
  • EASY SHIPPING AND ASSEMBLY: Enclosed 22U data rack cabinet ships compact flat-packed to avoid damage and facilitate installation; Include wheels & levelling feet to offer more stability; Home server rack cabinet is only 46.6in (118,3cm) in height
  • DESIGN AND VENTILATION: Half height server rack cabinet has lockable and removable door and side panels with vented top allowing airflow; 4 Post 19" rack with 1764lb (800kg) weight capacity (stationary); Computer cabinet rack is EIA/ECA-310-E Compliant
  • HARDWARE INCLUDED: Rolling home network rack includes rack mounting and equipment mounting hardware, such as 20 M6 cage nuts / screws, PVC cup washers; Front/rear doors and side panels Keys, 2x allen keys; Rack assembly hardware; Casters and leveling feet
  • THE IT PRO'S CHOICE: Designed and built for IT Professionals, this 22U IT Server Cabinet is backed for life, including free lifetime 24/5 multi-lingual technical assistance

Design the boundary around trusted identity and durable scope

The case suggests a practical way to inspect a multi-tenant system: follow the tenant identity from authentication through storage and into asynchronous or cached state. Ask whether each boundary enforces the scope or merely assumes callers will preserve it.

Design question Risky pattern in the reported case Safer direction described by the author
Where does tenant identity come from? A client-controlled header or payload field is trusted. Derive tenant context from the authenticated principal and check any supplied tenant field against it; reserve arbitrary tenant selection for an authorized system principal.
How are records addressed? Global worker or tool identifiers are used without tenant scope. Include tenant identity in durable keys and constrain lookups by the acting tenant.
What happens when context is missing? Records or events silently fall into a default tenant. Fail or dead-letter unattributed events, and monitor the count rather than silently assigning ownership.
What does a cross-tenant request reveal? A lookup may return another tenant’s record or disclose that it exists. Make a cross-tenant read appear as “not found” to the acting tenant; reject a cross-tenant write with a scope error.

These are lessons from one project’s account, not a universal prescription that a composite key alone secures every architecture. The underlying requirement is consistent enforcement: every read, write, event, cache entry and secret lookup must use tenant context derived from a trusted source.

Rank #4
NavePoint 12U Server Rack Enclosure with Glass Door, Cooling Fan, Locks, & Removable Side Panels - 12U Wall Mount Network Cabinet 19 Inch Rack 17.7" Deep (450mm)
  • DURABLE BUILD: Constructed from high-quality Cold Rolled Steel, the NavePoint Consumer Series 12U network cabinet boasts a sturdy, welded frame. Fitting EIA standard 19” networking equipment, this server cabinet confidently supports up to 110 lbs, providing a resilient base for your vital IT gear and equipment
  • CONVENIENT DESIGN: This 12U cabinet features a reinforced, heat-treated, tempered glass front door with a security lock. Perfect for applications requiring both security and accessibility, its compact design of 17.72"L x 21.65"W x 24.42"H offers a practical solution for space-constrained settings.
  • EASY & CUSTOMIZABLE EQUIPMENT SET UP - The 12U IT cabinet, with removable side panels and security locks, offers customization at its finest. Whether it's for an efficient device or cable management, this data cabinet ensures secure, adaptable configurations that suit your networking server requirements
  • ENHANCED VENTILATION & SECURITY - Built-in fans and flow-through ventilation work to prevent overheating, ensuring optimal operation of your equipment. The reinforced, lockable tempered glass front door not only boosts security but also facilitates easy monitoring of installed equipment.
  • SAFETY & COMPLIANCE - All NavePoint products are built to industry standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Test tenant isolation as an adversarial boundary

Happy-path tests show that a tenant can access its own records. They do not show that it cannot access another tenant’s. Ghosal argues for deliberately testing the boundary at each relevant interface, including attempts to substitute tenant identifiers, reuse another tenant’s record ID, omit context, or write state under an unintended scope.

  • Authenticate as tenant A and try to use tenant B’s header or declared payload tenant.
  • Attempt to read and write a worker, workload or tool owned by another tenant.
  • Submit approvals, security events and incident updates with tenant context omitted.
  • Exercise secret resolution and result-cache paths with mismatched tenant context.
  • Check that unauthorized reads do not reveal record existence, while writes fail with a scope error.
  • Track unattributed events; the author says that counter should be zero.

Ghosal says HivePlane’s v0.2.0 field test covered 34 release gates and cites a field-test score of 36/36. Those are author-reported figures; the post does not independently establish the test method or results. They should not be read as an external audit or a general measure of multi-tenant security.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the migration account establishes

Ghosal says the v0.1.0-to-v0.2.0 migration is forward-only, numbered 0003, and advises backing up first. The migration guide was not independently confirmed here, so operators should check the current HivePlane documentation before applying it. A forward-only migration deserves particular care: confirm the backup and recovery plan before running it, rather than assuming the change can be rolled back.

The useful question for any platform

Ghosal’s account ends with a question that applies beyond HivePlane: where does a platform infer tenancy instead of enforcing it? Look especially for places where a client-supplied field becomes identity, where a global identifier substitutes for ownership, or where missing context is quietly converted into a default. As the author puts it, “isolation is structural or it’s imaginary.”

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.