Skip to content
Stackship documentation Svenska

Access controlAdministrators

Boundary trusts

Let the workload identities of one boundary be given roles in a boundary that belongs to another tenant.

Requires: rbac/boundaryTrusts/admin

A managed identity or service account belongs to the boundary it was created for, and can be given roles in the boundaries of that boundary's tenant only. A boundary trust from a source boundary into a target boundary lets the source's workload identities be given roles in the target, even when the two belong to different tenants — see Tenants and guests.

A trust works in one direction only. It does not grant anything by itself: an owner of the target still assigns the roles. Trusts are managed through the API by a holder of rbac/boundaryTrusts/admin at the root — Platform Owner. There is no portal page for them.

Create a trust

bash
stsh api POST /admin/boundary-trusts --body '{
  "sourceBoundaryId": "<source-boundary-id>",
  "targetBoundaryId": "<target-boundary-id>",
  "reason": "The reporting job in Analytics reads the Sales vault"
}'

The reason is required, up to 500 characters. A second trust between the same two boundaries in the same direction is refused.

List and remove trusts

bash
stsh api GET /admin/boundary-trusts
stsh api GET "/admin/boundary-trusts?boundaryId=<boundary-id>"
stsh api DELETE /admin/boundary-trusts/<trust-id>

With boundaryId, the list holds the trusts in which that boundary is the source or the target. Removing a trust stops new assignments; assignments already made under it stay until an owner of the target removes them.