Multi-tenancy is how you sell capacity nobody has contracted. It pays off only when every tenant gets an environment you can put in a contract: a boundary their auditor can verify, performance you can commit to, and dedicated hardware where the deal demands it. All inside one cluster.
You commit per tenant environment inside a cluster, and Genesis Grid holds the line underneath. We commit what the software can hold: control plane, portal and meter. Availability of a tenant environment is a product of your facility, your hardware and this software, so it is agreed per deployment against the estate we survey with you.
availability Genesis commits for control plane, portal and meter
control plane, portal and metering downtime during a platform upgrade
notice before a node is cordoned for maintenance
It cannot. Each tenant runs against a committed quota and bursts only into headroom nobody reserved, never into capacity another tenant is guaranteed. The oversubscribing tenant queues or buys more, and the others see nothing.
By partition keys — and what decides whether that is hard is who may set them. A boundary that holds only while the tenant behaves is not a boundary, so where enforcement sits — adapter, switch port, subnet manager — is all three: the subnet manager assigns, adapter and switch port enforce, and your network team gets it in writing before anything is signed. The subnet manager itself runs on management nodes inside your control plane, never on tenant nodes. It surprised NVIDIA's own engineers when we showed them.
By namespace. Ceph and VAST each carry per-tenant namespaces, and every tenant gets its own credentials and quotas against them. That is what the platform enforces, across block, object and file. Anything beyond it — key management, encryption, retention — is a choice you make on top and should describe to your tenants as your own, not as something the stack does for you.
What differs between tenants is what they bought. For reserved capacity the accelerator is assigned whole and the quota is committed; for inference sold per token the service level is stated in latency percentiles. The scheduler reserves against the guarantee rather than the average, so a busy cluster does not change what a tenant contracted for.
The contract with your tenant stays yours, and Genesis Grid gives you the enforcement and the evidence underneath it. Platform commitments are agreed per deployment, so you never promise upward more than the stack below holds.