Skip to content
Stackship documentation Svenska

Resource groupsUsers

Resource groups

A resource group is the container every resource lives in. It belongs to one boundary, becomes a namespace on the boundary's clusters, and is a unit of access and of deletion.

Every app, function, database, vault, container instance and other resource belongs to exactly one resource group, and every resource group belongs to one boundary. Group the resources that belong together — one group per environment (production, staging) or per system (shop-frontend, shop-api) — so that a role assignment or a deletion lands on exactly what you mean.

A namespace on each cluster

A resource group becomes a Kubernetes namespace named rg-<first nine characters of the boundary's slug>-<group name>. A group called web in the boundary svensk-fagel gets the namespace rg-svensk-fa-web. The shape keeps every name inside the 63-character limit Kubernetes sets while staying recognisable.

The namespace is created on every cluster the boundary is actively projected into when the group is created, and a resource you create in the group runs on one of those clusters. A cluster the boundary is projected into later does not get the existing groups; only groups created after that get a namespace there.

A unit of access

A role assigned on a resource group applies to every resource inside it, and to nothing outside. A role assigned on the boundary applies to every resource group in it. The resource-group list shows only the groups you can read. See Permissions.

A unit of deletion

Deleting a resource group deletes its namespaces and every resource in them, for good; Kubernetes finishes removing them in the background after the group has left the list. There is no requirement to empty it first. See Delete a resource group.

The group's access goes too: the role assignments, deny assignments and just-in-time grants made on the group or on a resource in it are removed as the last step of the deletion, so a new group with the same name starts without them — see Using the name again.

Networking

Workloads in the same boundary reach each other across its resource groups; the group is not a network wall. A database can be narrowed to accept connections only from its own resource group. See Network isolation.

Pages