Introduction
Why use HashiCorp Validated Designs?
HashiCorp Validated Designs (HVD) provide practitioners with opinionated guidance for achieving production-grade deployments of HashiCorp products. These designs are purpose-built for delivering foundational use cases, with a baseline level of architectural and operational maturity. They draw on the field experiences of Solutions Engineers and Solutions Architects working with customers across a wide range of environments and organizational requirements.
Each guide provides access to an opinionated reference architecture, including key design decisions and the rationale behind them. Where applicable, guides identify modular design components that you can adjust to align with organizational or regulatory requirements without compromising the overall integrity of the implementation. For many deployments we include Terraform modules to automate large portions of infrastructure provisioning and software installation.
Audience
This document is primarily for practitioners (including platform, networking, identity, and information security teams) looking to deploy Boundary Enterprise clusters on-premises or in cloud infrastructure. After using this Installation Guide to deploy your Boundary Enterprise infrastructure, we recommend operators refer to the Boundary Administration Guide for day-2 operations and the Boundary User Guide to configure identity providers, secure user access, credential management, and other use cases.
Supported versions
This version of the guide relates to Boundary Enterprise 0.17.x+ent.
Language and definitions
This documentation intentionally uses technology agnostic terminology, however there are some terms which do not translate between the cloud providers. The following are the definitions of terms this document uses.
| Term | Definition |
|---|---|
| Region | A physical location in a distinct geographic area containing one or more availability zones (AZ). |
| Availability zone (AZ) | An availability zone (AZ) is a single network failure domain that hosts part or all of a Boundary Enterprise cluster. Examples of availability zones include: an individual datacenter, an air-gapped rack in a datacenter, an availability zone in AWS or Azure, or a zone in GCP. |
| Public subnet | A network accessible by users. |
| Private subnet | A network used by applications and services, but not directly accessible by users. |
Organizational requirements
We expect a single team, often referred to as the Platform Team, to handle the tasks in this guide. However, a successful Boundary Enterprise deployment requires collaboration across multiple organizational functions. The Platform Team needs to work with other teams, such as networking or security for tasks such as IP allocation or certificate management. If hosting infrastructure on a public cloud, consolidate these responsibilities within a unified cloud team. We recommend the platform team thoroughly review this Installation Guide to identify any teams they may rely on or need approval from for key deployment tasks. It is essential to designate a project lead to oversee the deployment process and ensure clear communication and coordination with all relevant teams and functions.