Boundaries
A boundary is an isolated environment that holds resource groups, decides who has access to them and keeps its workloads apart from everyone else's.
- API reference — Every HTTP endpoint of the boundaries module: authentication, IAM action, parameters, bodies and status codes.
- The boundary page — What each tab of a boundary's page shows and who sees it, the statuses a boundary can have, and the CLI commands for boundaries.
- Configuration reference — Configuration keys of the boundaries module: sections, environment variables, types and defaults.
- Create a boundary — Create a boundary from its display name, understand the slug and tenant it gets, and what isolation it provides before anything runs in it.
- Crosslink — How Crosslink makes a service in one of a boundary's clusters reachable from its other clusters under the same name, and what the Crosslink tab reports.
- Turn Crosslink on and manage it — Enable Crosslink for a boundary by choosing a hub cluster, move the hub, rotate the boundary CA, or turn Crosslink off.
- Delete a boundary — Delete an empty boundary, what is removed with it, and what to do when a deletion stops partway.
- Boundaries — A boundary is an isolated environment that holds resource groups, decides who has access to them and keeps its workloads apart from everyone else's.
- Members and tenants — Who counts as a member of a boundary, how the boundary's tenant limits who can be given access, and what guests are.
- Move a boundary to another tenant — Move a boundary into a new tenant of its own or into a tenant that already owns another boundary, and read what the move carried across.
- Boundary networks for operators — How the platform keeps boundary network rules in place, the module settings that shape them, and how to turn on the traffic records behind the Network tab.
- Find out why a connection is blocked — Use the boundary's Network tab to see what was blocked and why, and to ask whether a connection would be allowed before you depend on it.
- Network isolation — The network rules every boundary gets, what they allow and block, and why a blocked connection hangs instead of failing.
- Network rules and reasons — Every network grant a boundary gets, with the name the portal shows for it, and every reason code the Network tab and the API give for a blocked connection.
- Permissions — The actions that govern boundaries, which of them only count at the root of the platform, and the roles that hold them.
- Projections — A projection makes a boundary available on a cluster. How to add one, what its statuses mean, and what happens to resource groups when a boundary spans more clusters.
- Tenants — What a tenant is, how it relates to boundaries and the identity provider's organizations, and what moving a boundary to another tenant carries across.