Delete a resource group
Delete a resource group and everything in it, and follow the deletion until the group is gone.
Requires: resourcegroups/delete
Deleting a resource group needs resourcegroups/delete; the Owner and Contributor roles have it.
Caution
Deleting a resource group deletes its namespace on every cluster, and with it every resource in the group. The group does not have to be empty, and the deletion cannot be undone.
resourcegroups/deleteon the group is the only permission checked: you need no rights on the resources inside it, and a deny assignment on one of them does not stop the deletion.
Note
The group's access goes with it. The role assignments, deny assignments, just-in-time requests and grants, and invitations made on the group or on a resource in it are removed as the last step of the deletion, so there is nothing to remove by hand first. Access given on the boundary is not affected. See Follow the deletion.
Delete it
- Open Resource Groups in the sidebar and find the group. Open it first if you want to see what is in it: its page lists every resource with its type and status.
- Choose the delete icon on the group's row.
- Type the group's name to confirm, and choose Delete.
With the CLI:
stsh rg delete my-group --boundary my-boundary --yesFollow the deletion
The group shows as Deleting while the platform asks each cluster to delete its namespace, and the deletion is recorded as an operation on the boundary's Operations tab. If a cluster cannot be reached, the platform keeps trying; the group stays Deleting until it succeeds.
As soon as every cluster has accepted the deletion, the platform removes the group's access, as the last step: the role assignments, deny assignments, just-in-time requests and grants, and invitations made on the group or on a resource in it. Then the group disappears from the list and the operation completes. Kubernetes removes the namespace and the resources in it in the background, which can take a while longer.
If the access cannot be removed, the group stays Deleting with a reason that starts with
RBAC cleanup failed (will retry): — stsh rg get <name> -o json shows it as statusReason.
The platform tries again every minute, and the group disappears from the list once it succeeds.
Using the name again
Once the group has disappeared from the list its name is free. A new group created with the same name starts without the old group's access, which was removed with it; only the access inherited from the boundary applies to it. Created straight away, it can show Failed for a while, because the old namespace is still being removed from the cluster; it turns Active by itself once the old one is gone.
Deleting the whole boundary
A boundary can only be deleted when it has no resource groups left. Deleting the boundary itself is a platform administrator task — see Delete a boundary.