Adobe shares safer multi-tenant GPU metrics access for Kubernetes
Adobe engineers described an open-source approach giving teams self-service access to their own Prometheus metrics in multi-tenant Kubernetes clusters. A prom-label-proxy enforces namespace constraints on PromQL queries, and an optional per-tenant Prometheus cut stored series from 10,000 to about 300.
- Requests pass through NGINX and kube-rbac-proxy to a multi-tenant Prometheus proxy
- prom-label-proxy enforces a namespace constraint on incoming PromQL queries
- A MetricAccess custom resource lets teams declare the metrics they need
- One configuration reduced a tenant's stored series from 10,000 to roughly 300
Read next
Software