Skip to content
Stackship documentation Svenska

BoundariesAdministrators

Create a boundary

Create a boundary from its display name, understand the slug and tenant it gets, and what isolation it provides before anything runs in it.

Requires: boundaries/create

Creating a boundary is a platform-level task. It needs boundaries/create granted at the root of the platform, which the Platform Owner and Platform Contributor roles have; a boundary Owner or Contributor cannot create boundaries. On a new installation the first-run wizard creates the first boundary — see Getting started.

Create it in the portal

  1. In the portal at https://portal.example.com, open Boundaries in the sidebar.
  2. Choose Create Boundary.
  3. Enter a Display Name, for example Production. It can be up to 128 characters.
  4. Choose Create Boundary. The portal opens the new boundary.

The sheet also has a Slug field, filled in as you type. The platform ignores it: the slug is always derived from the display name, as described below. Check the slug on the new boundary's Overview rather than trusting the field.

The slug

The platform derives the slug from the display name: accents are removed, letters are lowercased, every run of other characters becomes one hyphen, leading and trailing hyphens are dropped, and the result is cut to 63 characters. Svensk Fågel becomes svensk-fagel.

  • The slug must be unique. A display name whose slug is already taken is refused with a message saying that a boundary with that slug already exists; choose a different name.
  • The slug never changes, even if the display name is changed later.
  • Its first nine characters go into the namespace name of every resource group in the boundary, rg-<first nine characters>-<group name>. Boundaries whose slugs start with the same nine characters cannot both have a resource group with the same name, so a distinctive start saves trouble later.

The tenant

Every new boundary gets a tenant of its own, which contains only this boundary and no people yet. To put the boundary with the other boundaries of the same customer, so that they share people and single sign-on, move it into their tenant — see Move a boundary to another tenant. What a tenant is, is explained in Tenants.

What the boundary gives you

A boundary is Active the moment it is created, but it has nothing to run on yet. From the start it provides:

  • Its own access scope. Roles assigned on the boundary reach everything in it and nothing outside. Nobody is given a role on a new boundary: platform roles reach it through their root assignment, and everyone else needs an assignment on it.
  • Its own tenant, as above.
  • Network isolation for every resource group created in it, from the platform's next pass after the resource group is created: workloads in the boundary reach each other, other boundaries reach only what is published, and outbound traffic is limited to HTTPS and the few ports the platform itself needs. See Network isolation.

With the CLI

bash
stsh boundary create "Production"

The command prints the new boundary with the slug the platform derived.

Next steps

  1. Project the boundary into a cluster. Resource groups cannot be created until it has an active projection.
  2. Give people access on the boundary's Access Control tab — see Members and tenants.
  3. Create the first resource group.