Skip to content
Stackship documentation Svenska

BoundariesUsers

Boundaries

A boundary is an isolated environment that holds resource groups, decides who has access to them and keeps its workloads apart from everyone else's.

A boundary is the outermost container on the platform. Everything you run lives in a resource group, and every resource group belongs to one boundary. The boundary decides three things for all of it: who has access, which clusters it runs on, and what its workloads can reach over the network.

What a boundary holds

  • Resource groups. A resource group becomes a Kubernetes namespace on the boundary's clusters, and every resource lives in one. See Resource groups.
  • Projections. A boundary runs on the clusters it is projected into. Platform administrators add projections; see Projections.
  • Role assignments. A role assigned on the boundary applies to every resource group and resource in it. See Members and tenants.
  • Network rules. Workloads in the same boundary reach each other freely. Workloads in another boundary reach them only through what is published, such as an app's web address or a load-balancer endpoint. See Network isolation.
  • Crosslink (optional). Makes selected services reachable across the boundary's clusters. See Crosslink.

Names

A boundary has a display name, shown in the portal, and a slug, derived from the display name when the boundary is created: accents are removed, letters are lowercased, every run of other characters becomes one hyphen, and the result is cut to 63 characters. Svensk Fågel becomes svensk-fagel. The slug is unique on the platform and never changes. Its first nine characters appear in the namespace name of every resource group in the boundary.

Tenant

Every boundary belongs to a tenant: the customer that owns it. The tenant decides which people can be given access to the boundary and how they sign in. A new boundary gets a tenant of its own, and a platform administrator can move it into another. See Members and tenants.

Who creates boundaries

Creating, deleting and projecting boundaries, and moving them between tenants, are platform administrator tasks, done at the root of the platform:

A boundary Owner runs everything inside the boundary, including who has access to it.

Pages