Skip to content
Stackship documentation Svenska

BoundariesUsers

Turn Crosslink on and manage it

Enable Crosslink for a boundary by choosing a hub cluster, move the hub, rotate the boundary CA, or turn Crosslink off.

Requires: crosslink/admin

Changing Crosslink needs crosslink/admin on the boundary, which Owner and Contributor have. Anyone who can see the boundary can read the Crosslink tab. What the tab shows is explained in Crosslink.

Caution

crosslink/admin also allows the API calls the Crosslink operators make, among them reading the hub's link redemption code, a bearer secret, and overwriting the state the tab shows. See Permissions.

Before you start

The hub has to be one of the boundary's own clusters that accepts inbound links. Both are arranged by a platform administrator, not on this tab:

  • projecting the boundary into the cluster — see Projections;
  • marking the cluster as accepting inbound links, with a published endpoint — see Clusters.

If no cluster qualifies, the tab says so instead of offering a choice.

Turn Crosslink on

  1. Open the boundary and its Crosslink tab.
  2. Pick the Hub cluster. Only the boundary's clusters that accept inbound links are offered.
  3. Choose Enable Crosslink.

The tab switches to the topology view and waits for the operator; sites appear as each cluster reports.

Move the hub

  1. Choose Change hub.
  2. Pick another hub cluster and choose Move hub.

Traffic across clusters is interrupted while every spoke re-links to the new hub. Traffic inside a cluster is not affected.

Rotate the boundary CA

Choose Rotate on the Boundary CA card. The card reports the rotation as in progress until every site has picked up the new generation. The platform also rotates the CA by itself every 90 days.

Turn Crosslink off

Choose Disable on the Topology card. Crosslink is turned off for the whole boundary: the site in each cluster is taken down, services are no longer reachable across clusters, and the topology is cleared.

If the list of hub clusters fails to load

The list of eligible hubs needs crosslink/admin on the boundary. Without it the tab reports that it could not list them; ask a boundary Owner.