Skip to content
Stackship documentation Svenska

BoundariesUsers

Permissions

The actions that govern boundaries, which of them only count at the root of the platform, and the roles that hold them.

Actions on a boundary

Checked on the boundary, so a role assigned on the boundary or at the root grants them.

Action Allows
boundaries/read See the boundary, open its page and read its Crosslink state. Every built-in role for people includes it; the service roles the platform grants to its own components (Deployment Token Broker, Platform Alert Publisher, LLM Gateway Consumer) do not.
boundaries/projections/read See which clusters the boundary is projected into.
boundaries/network/read Use the Network tab: blocked connections, traffic and the reachability check.
boundaries/manage Change the boundary's display name.
crosslink/admin Turn Crosslink on and off, list the eligible hubs with their inbound endpoints, choose or move the hub, and rotate the boundary CA. It also gates the calls the Crosslink operators make; see the caution below.
rbac/members/read See the boundary's role assignments and its tenant's single sign-on card.
rbac/members/write Assign and remove roles on the boundary.
boundaries/members/read List the boundary's role assignments through the boundaries API (GET /boundaries/{id}/members), which also needs rbac/members/read.
boundaries/members/manage Assign roles on the boundary through the boundaries API (POST /boundaries/{id}/members) — a second way to assign them, under the same tenant rules; platform roles cannot be assigned this way. Removing an assignment through this API also needs rbac/members/write.
boundaries/invitations/read See the boundary's invitations.
boundaries/invitations/create Send, resend and revoke invitations to the boundary.

Caution

crosslink/admin also gates the API calls that the platform's Crosslink operators make on the boundary's behalf, so everyone who holds it, boundary Contributors included, can make them too:

  • read the hub's link redemption code and CA certificate (GET /boundaries/{id}/crosslink/access-grant) — a bearer secret: whoever has it can redeem it to link a site to the hub — and publish a replacement with POST on the same path;
  • list what the boundary's other clusters export (GET /boundaries/{id}/crosslink/inventory);
  • overwrite the site and exposure state the operators report (POST /boundaries/{id}/crosslink/status), which is what the Crosslink tab shows.

Treat crosslink/admin as access to the boundary's Crosslink network, not only to its settings.

Actions only granted at the root

These are checked at the root of the platform, /. A role assigned on the boundary never grants them, even when it lists the action.

Action Allows
boundaries/create Create boundaries.
boundaries/delete Delete empty boundaries.
boundaries/projections/manage Project a boundary into a cluster.
boundaries/tenant/admin Move a boundary to another tenant.

Roles

Role See, network Rename, Crosslink Assign roles, invite Create, project Delete, move tenant
Reader Yes No No No No
Contributor Yes Yes No No No
Owner Yes Yes Yes No No
Platform Reader Yes No No No No
Platform Contributor Yes Yes No Yes No
Platform Owner Yes Yes Yes Yes Yes

The platform roles are assigned at the root and reach every boundary. Owner, Contributor and Reader are assigned on a boundary, a resource group or a resource.