Skip to content
Stackship documentation Svenska

FunctionsUsers

Create a function namespace

Create a function namespace in a resource group — every step of the wizard, what each setting does today, and what the namespace gets.

Requires: functions/write

Creating a function namespace needs functions/write in the resource group; the Owner, Contributor and Functions Operator roles have it.

Open the wizard

In the portal at https://portal.example.com, open Functions in the sidebar. The page lists your Function Namespaces; choose Create Function Namespaces. The wizard Create a new Function Namespace has five steps.

Basic Configuration

  • Function Namespace Name — 3 to 253 characters: lowercase letters, digits and hyphens, not starting or ending with a hyphen. Keep it to 55 characters or fewer. The platform names the namespace's proxy fnproxy-<name>, and Kubernetes refuses that name when it is longer than 63 characters: a longer namespace name is accepted and the namespace even reports Ready, but it gets no proxy and none of its functions can be reached.
  • The name is also the first part of the namespace's hostname, <name>.fn.apps.example.com. No other function namespace on the same cluster may use that hostname; if one does, creating the namespace is refused.
  • Boundary, Cluster and Resource group — where the namespace lives. Every function you add to it runs on the same cluster.

The name cannot be changed later.

Compute Plan

Choose one of the function compute plans, from Nano (0.1 CPU, 128 MB RAM) to 2XL (8 CPU, 8.0 GB RAM). Standard is selected to begin with. Plans your boundary's policy does not allow are shown but cannot be chosen.

Important

The plan is not applied today. It is not saved with the namespace — the Overview shows no compute plan — and every function gets 0.25 CPU and 256 MiB of memory whichever plan you choose. To give a function more, see Scaling and resources.

Scaling

  • Minimum Replicas — 0 to 20. 0, the default, lets functions scale to zero when they are idle.
  • Maximum Replicas — 1 to 50, and at least the minimum. The default is 10.
  • Cooldown Period (seconds) — 30 to 3600: how long an idle function keeps running before it scales to zero. The default is 300.

Important

These values are saved as the namespace's defaults and shown on its Overview, but functions do not use them today: every new function starts with a minimum of 0, a maximum of 10 and a cooldown of 300 seconds. See Scaling and resources.

Environment Variables

Add the variables every function in the namespace receives. Under Add New Environment Variable, type the key and the value and choose the add button.

  • A key is 1 to 100 characters: uppercase letters, digits and underscores, starting with a letter or an underscore. What you type is turned into capitals.
  • A value is at most 500 characters.
  • A function's own variable with the same name wins over the namespace's.
  • STACKSHIP_AUTH_ENABLED, STACKSHIP_OIDC_ISSUER and STACKSHIP_OIDC_AUDIENCE are reserved by the platform and never reach a function.

Keep credentials out of environment variables: reference vault secrets on the function instead — see Secrets and the managed identity.

Review & Create

Review & Create sums up the name, resource group, cluster, compute plan, scaling, resource limits and environment variables. Create the namespace; it appears in the list and is ready when its status is Ready.

What the namespace gets

  • The hostname <name>.fn.apps.example.com, served over HTTPS.
  • Its own proxy, fnproxy-<name>: one replica that requests 0.1 CPU and 128 MiB of memory, whether or not the namespace has functions. See How a request reaches a function.
  • A managed identity, shared by all its functions, with no roles yet — see Secrets and the managed identity.
  • A page with the tabs Overview — status, resource group, boundary, cluster, the scaling defaults and the Functions list — Configuration, Operations, Activity and Danger Zone. The page has no Access Control tab: give people roles on the resource group or the boundary — see Permissions.

Change or delete the namespace

  • Configuration → Environment Variables changes the variables all functions receive. Running functions pick the change up within about a minute; a function that is sleeping gets it the next time it is deployed or one of its settings is saved.
  • Configuration → Scaling and Configuration → Authentication hold defaults that functions do not use today — see Scaling and resources and Namespace defaults.
  • Danger Zone deletes the namespace together with all its functions, its proxy and its managed identity. Role assignments that named the identity are not removed with it.

With the CLI

bash
stsh functions ns list -g my-resource-group
stsh functions ns get my-namespace -g my-resource-group -o json
stsh functions ns delete my-namespace -g my-resource-group

Next steps