Adobe Released Open-Source Tenant-Aware Prometheus Metrics
New proxy-based architecture enforces namespace constraints to secure multi-tenant metrics access in Kubernetes.
Updated on Sept. 29, 2026 in Data Centers

Live Poll
Do you trust that your employer monitors internal technical resources efficiently and transparently?
Adobe engineers described an open-source approach using a tenant-aware proxy to restrict Prometheus metric access. This mechanism enables teams to secure data while monitoring critical resources like GPU utilization within Kubernetes clusters.
Why it matters
Centralized Prometheus instances often pose data exposure and performance risks in multi-tenant environments. This approach allows organizations to curate metrics for specific users while identifying inefficient hardware allocation, such as GPUs left idle during active assignments.
The architecture uses a proxy to modify PromQL queries and a custom Kubernetes resource to define metric access via regex or exact selectors. This configuration enabled a reduction in stored series from over 10,000 to roughly 300 while exposing power and memory metrics.
The players
Adobe
A software enterprise specializing in digital media and experience cloud platforms that frequently contributes to open-source infrastructure projects.
Kubernetes
An open-source container orchestration platform that automates the deployment, scaling, and management of containerized applications.
Prometheus
An open-source monitoring and alerting toolkit widely used to track metrics and performance within cloud-native architectures.
The details
The design functions by intercepting traffic through a proxy layer that authenticates users via NGINX and kube-rbac-proxy. A component called prom-label-proxy then enforces namespace isolation by modifying PromQL queries to restrict data access. For further isolation, the system uses a MetricAccess custom resource to define allowed metrics and can remote-write curated data into tenant-specific instances.
Timeline
September 29, 2026: Adobe engineers described the open-source metric approach.
The Tech Race
This development addresses the persistent challenge of multi-tenancy in cloud-native monitoring, where centralized architectures often force a trade-off between visibility and isolation. It provides a more surgical alternative to the heavy-handed federation patterns commonly used to manage metric access across large-scale infrastructure.
Platform engineers can now implement tighter security for shared monitoring dashboards without sacrificing deep-dive visibility into hardware performance. This setup is particularly relevant for teams managing high-cost GPU clusters, allowing them to identify and reallocate resources that remain unused for extended periods.
The takeaway
This architecture demonstrates a practical way to prune metric noise while securing multi-tenant data access. Organizations should monitor how this proxy-based method performs against emerging native multi-tenant features within the broader Prometheus ecosystem.
Further reading
Explore the latest infrastructure standards and management strategies in Data Centers.
Source note: This article includes information reported by InfoQ.
Live Poll
Do you trust that your employer monitors internal technical resources efficiently and transparently?







