Resource groups
A resource group is the container every resource lives in. It belongs to one boundary, becomes a namespace on the boundary's clusters, and is a unit of access and of deletion.
Every app, function, database, vault, container instance and other resource belongs to exactly
one resource group, and every resource group belongs to one
boundary. Group the resources that belong together — one group per
environment (production, staging) or per system (shop-frontend, shop-api) — so that a
role assignment or a deletion lands on exactly what you mean.
A namespace on each cluster
A resource group becomes a Kubernetes namespace named
rg-<first nine characters of the boundary's slug>-<group name>. A group called web in the
boundary svensk-fagel gets the namespace rg-svensk-fa-web. The shape keeps every name inside
the 63-character limit Kubernetes sets while staying recognisable.
The namespace is created on every cluster the boundary is actively projected into when the group is created, and a resource you create in the group runs on one of those clusters. A cluster the boundary is projected into later does not get the existing groups; only groups created after that get a namespace there.
A unit of access
A role assigned on a resource group applies to every resource inside it, and to nothing outside. A role assigned on the boundary applies to every resource group in it. The resource-group list shows only the groups you can read. See Permissions.
A unit of deletion
Deleting a resource group deletes its namespaces and every resource in them, for good; Kubernetes finishes removing them in the background after the group has left the list. There is no requirement to empty it first. See Delete a resource group.
The group's access goes too: the role assignments, deny assignments and just-in-time grants made on the group or on a resource in it are removed as the last step of the deletion, so a new group with the same name starts without them — see Using the name again.
Networking
Workloads in the same boundary reach each other across its resource groups; the group is not a network wall. A database can be narrowed to accept connections only from its own resource group. See Network isolation.