Skip to content
Stackship documentation Svenska

Resource groupsUsers

Create a resource group

Create a resource group in a boundary, choose a name that works, and understand where it is placed and who can use it.

Requires: resourcegroups/write

Creating a resource group needs resourcegroups/write in the boundary; the Owner and Contributor roles have it.

Before you start

The boundary needs at least one Active projection — a cluster to put the group on. Check the boundary's Projections tab. A boundary without one refuses the new group with No active clusters found for boundary., and adding a projection is a platform administrator task; see Projections.

Warning

A group refused for this reason is still listed afterwards, as Provisioning, and keeps its name taken. Delete it before you create it again.

Create it in the portal

  1. In the portal at https://portal.example.com, open Resource Groups in the sidebar.
  2. Choose Create Resource Group.
  3. Check the Boundary; the one you are working in is chosen for you.
  4. Enter the Resource Group Name.
  5. Choose Create.

There is no cluster to choose: the group is placed on the boundary's clusters, as described under Where it is placed.

Choose the name

  • 3 to 50 characters: lowercase letters, digits and hyphens.
  • It must start with a letter or a digit. End it with one too: a name ending in a hyphen is accepted, but Kubernetes refuses the namespace and the group ends up Failed.
  • It must be unique in the boundary.
  • The namespace name built from it, rg-<first nine characters of the boundary slug>-<name>, must be unique on the platform. If another boundary whose slug starts with the same nine characters already has a group of that name, the new one is refused with a message that the namespace already exists; pick another name.
  • A resource group cannot be renamed.

Where it is placed

The group gets its namespace on every cluster the boundary is actively projected into at this moment. Resources you create in it later run on one of those clusters. If the boundary is projected into another cluster afterwards, this group is not added to it.

Wait for it to become Active

The group appears as Provisioning while the platform creates its namespaces, then turns Active; that normally takes seconds. Creating the group is also recorded as an operation on the boundary's Operations tab. If it turns Failed instead, see When a group is Failed.

Who can use it

Everyone with a role on the boundary has the same role in the new group. For access to this group only, assign a role at the resource group's scope — see Role assignments.

A group that reuses the name of a deleted group does not get the old group's access: that was removed when the old group was deleted — see Using the name again.

With the CLI

bash
stsh rg create my-group --boundary my-boundary
stsh rg get my-group --boundary my-boundary -o json

The second command shows the group's status, the reason when it failed as statusReason, and its namespace name as kubernetesNamespace. --boundary takes the boundary's slug or its id.

Next steps