Skip to content

PointSav Documentation

The engineering library for the PointSav platform — operating systems and services for regulated businesses that own their data, their AI, and their record-keeping outright. Where the monorepo holds the code, this wiki holds the reasoning: architecture, services, security, and the governance commitments that bind future development.

Configure a tenant namespace

Prerequisites

  • Administrator access to the machine running service-vm-tenant (default port 9221)
  • A tenant ID: a stable, lowercase ASCII string identifying the customer (e.g., acme-corp)
  • Quota values agreed with the tenant: maximum concurrent VMs, maximum RAM

Purpose

Add a tenant namespace to service-vm-tenant the way the service actually supports today — editing its environment configuration and restarting it. There is no runtime registration API; provisioning is config-driven.

Procedure

  1. Add the tenant to the allowlist. TENANT_IDS is a bare comma-separated list of tenant IDs — it carries no quota data itself:

    TENANT_IDS=acme-corp,existing-tenant
    
  2. Set the new tenant's quotas as separate, per-tenant environment variables, named by uppercasing the tenant ID:

    TENANT_ACME_CORP_MAX_VMS=10
    TENANT_ACME_CORP_MAX_RAM_MB=16384
    

    Both are optional — if omitted, they default to 5 VMs and 8192 MB.

  3. Set an authentication token for the tenant. service-vm-tenant uses a plain Bearer token, not a signed capability token:

    TOKEN_MAP=<a-generated-token>:acme-corp
    

    Warning: if TOKEN_MAP is left unset entirely, the service falls back to an explicitly-logged insecure mode where the bearer token literally is the tenant ID (Authorization: Bearer acme-corp authenticates as that tenant, no secret required). Set TOKEN_MAP for anything beyond local testing.

  4. Restart service-vm-tenant to load the new configuration. There is no hot-reload, no admin endpoint, and no signal-based config refresh — TENANT_IDS and the per-tenant variables are read exactly once, at process startup.

Expected outcome

service-vm-tenant recognizes requests bearing the new tenant's token, scopes every response to that tenant's own VMs automatically, and enforces the quotas you set.

Verification

Confirm the tenant is recognized and see its current usage in one call:

curl -s http://127.0.0.1:9221/v1/status \
  -H "Authorization: Bearer <acme-corp-token>"

This returns tenant_id, vms_running, ram_used_mb, max_vms, and max_ram_mb — a real, working quota-usage endpoint.

Confirm isolation by listing VMs — there is no client-supplied tenant filter; the server scopes results to whichever tenant the Bearer token authenticates as:

curl -s http://127.0.0.1:9221/v1/vms \
  -H "Authorization: Bearer <acme-corp-token>"

Confirm quota enforcement by attempting to exceed max_vms or max_ram_mb via POST /v1/vms. Both limits are enforced synchronously, before the request reaches the fleet controller, and return 429 Too Many Requests with a plain-text body describing the limit.

Rollback

Remove the tenant's ID from TENANT_IDS (and its TOKEN_MAP entry, if set) and restart the service. Existing VMs the tenant owns are not automatically destroyed — deallocate them explicitly first via DELETE /v1/vms/:vm_id if that's the intent, since a removed tenant simply loses the ability to authenticate, not its running resources.

Next steps

See also

Cite this record: /wiki/configure-tenant-namespace — revision 9b9339a2, last updated 6 August 2026.

Important Information

Corporate structure. PointSav Digital Systems ("PointSav") is currently a trade name of Woodfine Capital Projects Inc. ("Woodfine"), planned to become a wholly-owned Woodfine subsidiary upon incorporation. PointSav does not itself offer, sell, or solicit any security. Any securities offering associated with Woodfine's real-property direct-hold solutions is made exclusively by Woodfine, and only by means of the applicable Private Placement Memorandum.

No investment advice. This wiki's content is provided for engineering, operational, research, and development purposes. Nothing on this wiki constitutes investment advice or a solicitation to invest in any Woodfine partnership or direct-hold solution.

Intellectual property. The PointSav name, trade name, wordmark, and marks, together with all current and future PointSav- and Totebox-branded products, services, and offerings — and the software, source code, documentation, design system, and all related materials — are proprietary to Woodfine and its affiliates, except for components identified as open source. No rights are granted except as expressly set out in a written license or agreement. The full trademark notice appears in the footer of every page on this site.

Open source components. Portions of the platform are made available under permissive open-source licenses identified in the accompanying repository. Use of those components is governed by their respective license terms.

No warranty; informational use. Content on this wiki is provided for general informational purposes only and does not constitute a representation, warranty, or commitment with respect to product functionality, availability, pricing, or roadmap. Some articles describe planned or intended features, capabilities, and milestones — language such as "planned," "intended," "targeted," "may," and "expected" marks this forward-looking content, which is subject to change and does not constitute a commitment regarding future performance.

Confidentiality. Where an article describes an operational or deployment detail that is not intended for public disclosure, that article is not published on this wiki. Content here is general-purpose engineering documentation, not customer-specific configuration.

Jurisdiction. Woodfine Capital Projects Inc. is organized in British Columbia, Canada. References to the Sovereign Data Foundation on this wiki describe a planned or intended initiative only, not a current equity holder or active governance body.

Changes to this notice. PointSav may update this notice from time to time; the version posted on this page governs.

Not a filing system. This wiki is not a securities filing system, an electronic disclosure repository, or a substitute for SEDAR+ or any other regulatory filing system. Formal securities filings are made through the applicable regulatory filing system, not through this wiki.

Full disclaimer. This notice supplements, and does not replace, the full Disclaimers article. In the event of any conflict, the full Disclaimers article governs.

Read the full disclaimer →