arXiv · 2609.34881
Monitoring and Verification of Multitenant Kubernetes Clusters using TLA+ Trace Checking
Abstract
In distributed systems, model checking is usually used at design time for specifying an abstract model of the system and then exhaustively checking all possible behaviors. TLA+ is commonly used in this way as a specification language, together with the TLC model checker. In this paper, we present a monitoring tool that, at its core, utilizes TLA+ specifications in a different way. The tool utilizes a TLA+ trace-checking specification to detect violations in behavior inferred from Kubernetes audit logs. Our primary use case focuses on multitenancy violations; however, the pipeline is not limited to that setting. Specifically, it demonstrates how formal reasoning can be incorporated into live Kubernetes environments to improve monitoring and correctness checking.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Ioana Silaş, Adrian Crăciun. 2026-09-28. Monitoring and Verification of Multitenant Kubernetes Clusters using TLA+ Trace Checking. https://doi.org/10.4204/eptcs.452.4
Cite the original work for its findings. Save a collection to share your selection of sources.