Publish a tenant document per namespace under a template
Once an hour a job reads each tenant’s groups under this template and writes a tenant document into the template’s
own namespace (acme/prod for acme/prod/*): id the tenant’s
namespace name, attributes.kind tenant, state.groups the
banded aggregates as their labels, state.source where they came
from (as_of), and state.published_at. Each
group in state.groups has all, its labels over all its key
values together, and, for a group listed in keys, keys, the
labels of each listed key value the tenant has. Only band labels
cross the boundary: never an aggregate’s value, and never a key
value you did not list. Define judgments, queries and subscriptions
on the template’s namespace over them like any documents. The
writes bill your organization as writes and stored bytes, named
tenant_summary in usage. A tenant that has published nothing has
no document. Every group named must exist on the template; every key
of bands names one of their aggregates; every key of keys names
one of the groups. Templates need the Team plan or above.
Authorizations
An organization API key. Keys carry a role (read_write or
read_only) and may be restricted to a namespace prefix such as
acme/*, or to one namespace such as acme/prod/tenant_1. A prefix
matches on a / boundary: acme/prod/tenant_1* covers
acme/prod/tenant_1 and everything under acme/prod/tenant_1/,
never acme/prod/tenant_12.
Headers
One key per logical request, reused only on its retries. A key
belongs to one request: within your organization, the same method,
path, query and body. For 24 hours after a successful response, a
request with the key and the same body gets that response back
verbatim, with Idempotent-Replayed: true, and runs nothing. Only a
successful response is kept, so the retry of a request that failed
runs again. While the first request runs or its response is kept,
the key with a different request is idempotency_key_reused (422).
A request sent while one with its key is still running is
rate_limited with Retry-After: 1, without running: retry it to
get the first one's response. In the rare case the key can't be
checked, the request runs as if it had none.
1 - 255Path Parameters
A template prefix ending in /*, with every / sent as %2F, such as acme%2Fprod%2F*.
A template prefix, a namespace path ending in /*, such as acme/prod/*. Up to 256 bytes.
3 - 256^[A-Za-z0-9._:/-]+/\*$Body
Which of the template's groups each tenant publishes, their bands, and the key values published one by one.
1 - 8 elementsA judgment, attribute or threshold name. Names are path segments in field references, so they never contain ..
1 - 128^[A-Za-z0-9_-]+$Bands for published aggregates, keyed <group>.<aggregate> as a
judgment names them, such as abuse_by_day.count or
by_plan.avg(state.mrr). A tenant document shows each as its band's
label only; the value itself is never published. An aggregate
without bands does not appear.
Key values a group publishes one by one, by group, such as
{"by_plan": ["free", "pro", "team"]}. A key value comes from the
tenant's attributes, so a tenant document names only the key values
listed here, under the group's keys. Every group publishes its
labels over all its key values together as all, listed or not.
Response
Created. The first run starts within the hour; until then every tenant is pending.
A template's tenant summary and a page of its tenants.
A template prefix, a namespace path ending in /*, such as acme/prod/*. Up to 256 bytes.
3 - 256^[A-Za-z0-9._:/-]+/\*$A judgment, attribute or threshold name. Names are path segments in field references, so they never contain ..
1 - 128^[A-Za-z0-9_-]+$Bands for published aggregates, keyed <group>.<aggregate> as a
judgment names them, such as abuse_by_day.count or
by_plan.avg(state.mrr). A tenant document shows each as its band's
label only; the value itself is never published. An aggregate
without bands does not appear.
Key values a group publishes one by one, by group, such as
{"by_plan": ["free", "pro", "team"]}. A key value comes from the
tenant's attributes, so a tenant document names only the key values
listed here, under the group's keys. Every group publishes its
labels over all its key values together as all, listed or not.
RFC 3339, UTC.
tenant_summary_failed: the template's namespace refused the last run's writes, such as over its limits with on_exceeded: reject; the events feed has namespace.tenant_summary_failed.
tenant_summary_failed When the last run finished; null before the first.