Adobe Released Open-Source Tenant-Aware Prometheus Metrics

New proxy-based architecture enforces namespace constraints to secure multi-tenant metrics access in Kubernetes.

Updated on Sept. 29, 2026 in Data Centers

Isometric editorial illustration of a single industrial graphics processing unit in a server chassis, representing secure hardware monitoring architecture.
Adobe has released an open-source proxy-based architecture designed to enforce namespace isolation and secure metrics access within Kubernetes multi-tenant environments. AI Illustration. Upload story photo >

Live Poll

Do you trust that your employer monitors internal technical resources efficiently and transparently?

Adobe engineers described an open-source approach using a tenant-aware proxy to restrict Prometheus metric access. This mechanism enables teams to secure data while monitoring critical resources like GPU utilization within Kubernetes clusters.

Why it matters

Centralized Prometheus instances often pose data exposure and performance risks in multi-tenant environments. This approach allows organizations to curate metrics for specific users while identifying inefficient hardware allocation, such as GPUs left idle during active assignments.

The architecture uses a proxy to modify PromQL queries and a custom Kubernetes resource to define metric access via regex or exact selectors. This configuration enabled a reduction in stored series from over 10,000 to roughly 300 while exposing power and memory metrics.

The players

Adobe

A software enterprise specializing in digital media and experience cloud platforms that frequently contributes to open-source infrastructure projects.

Kubernetes

An open-source container orchestration platform that automates the deployment, scaling, and management of containerized applications.

Prometheus

An open-source monitoring and alerting toolkit widely used to track metrics and performance within cloud-native architectures.

The details

The design functions by intercepting traffic through a proxy layer that authenticates users via NGINX and kube-rbac-proxy. A component called prom-label-proxy then enforces namespace isolation by modifying PromQL queries to restrict data access. For further isolation, the system uses a MetricAccess custom resource to define allowed metrics and can remote-write curated data into tenant-specific instances.

Timeline

  1. September 29, 2026: Adobe engineers described the open-source metric approach.

The Tech Race

This development addresses the persistent challenge of multi-tenancy in cloud-native monitoring, where centralized architectures often force a trade-off between visibility and isolation. It provides a more surgical alternative to the heavy-handed federation patterns commonly used to manage metric access across large-scale infrastructure.

Platform engineers can now implement tighter security for shared monitoring dashboards without sacrificing deep-dive visibility into hardware performance. This setup is particularly relevant for teams managing high-cost GPU clusters, allowing them to identify and reallocate resources that remain unused for extended periods.

The takeaway

This architecture demonstrates a practical way to prune metric noise while securing multi-tenant data access. Organizations should monitor how this proxy-based method performs against emerging native multi-tenant features within the broader Prometheus ecosystem.

Further reading

Explore the latest infrastructure standards and management strategies in Data Centers.

Source note: This article includes information reported by InfoQ.

Live Poll

Do you trust that your employer monitors internal technical resources efficiently and transparently?

Adobe Released Open-Source Tenant-Aware Prometheus Metrics | Highwise Tech