Boundary trusts
Let the workload identities of one boundary be given roles in a boundary that belongs to another tenant.
Requires: rbac/boundaryTrusts/admin
A managed identity or service account belongs to the boundary it was created for, and can be given roles in the boundaries of that boundary's tenant only. A boundary trust from a source boundary into a target boundary lets the source's workload identities be given roles in the target, even when the two belong to different tenants — see Tenants and guests.
A trust works in one direction only. It does not grant anything by itself: an owner of the target
still assigns the roles. Trusts are managed through the API by a holder of
rbac/boundaryTrusts/admin at the root — Platform Owner. There is no portal page for them.
Create a trust
stsh api POST /admin/boundary-trusts --body '{
"sourceBoundaryId": "<source-boundary-id>",
"targetBoundaryId": "<target-boundary-id>",
"reason": "The reporting job in Analytics reads the Sales vault"
}'The reason is required, up to 500 characters. A second trust between the same two boundaries in the same direction is refused.
List and remove trusts
stsh api GET /admin/boundary-trusts
stsh api GET "/admin/boundary-trusts?boundaryId=<boundary-id>"
stsh api DELETE /admin/boundary-trusts/<trust-id>With boundaryId, the list holds the trusts in which that boundary is the source or the target.
Removing a trust stops new assignments; assignments already made under it stay until an owner of
the target removes them.