Delete a boundary
Delete an empty boundary, what is removed with it, and what to do when a deletion stops partway.
Requires: boundaries/delete
Deleting a boundary needs boundaries/delete at the root of the platform, which only the
Platform Owner role has.
Empty it first
Only an empty boundary can be deleted: one with no resource groups. A request for a boundary that still has any is refused with a message naming them, and nothing is changed. Delete the resource groups first — each deletion removes everything in the group, and is done on its own by someone who can see what is in it. See Delete a resource group.
A namespace that is still labelled for the boundary on one of its clusters also blocks the deletion, and the refusal names it too. Right after the last resource group is deleted, its namespace can still be named for several minutes, until it is gone from the cluster and the platform has noticed; try again then.
Delete it
- Open Boundaries in the sidebar.
- Choose the delete icon on the boundary's row.
- Type the boundary's slug to confirm, and choose Delete boundary.
With the CLI:
stsh boundary delete my-boundary --yesWhat is removed
- the boundary's
Boundaryresource on every cluster it was projected into; - its role assignments, deny assignments, invitations and requests for temporary access;
- its projections and its Crosslink state;
- the boundary itself.
The boundary's tenant is not removed: the tenant's members and single sign-on stay, and so do its other boundaries. The deletion is recorded as an operation.
If the deletion stops partway
The boundary is marked Deleting before anything is removed, and the boundary itself is removed last. If a cluster cannot be reached or the role assignments cannot be removed, the deletion stops, the boundary stays Deleting, and the message says what was left. Every step tolerates having already run, so deleting again finishes the job.