Why perimeters matter
Access to resources is inherited from access to a perimeter. A user who can access a perimeter can use the compute, packages, and models registered to it, while a user without access cannot. This keeps one team’s resources and workloads separate from another’s within the same platform.Perimeters and the data plane
The data plane is the part of the platform that runs in your cloud: the cluster where tasks execute and the storage where your data is kept. Creating a perimeter provisions a dedicated slice of the data plane for a team or project. Each perimeter has:- Its own namespace, where all of the perimeter’s tasks run
- Its own cloud identity (an IAM role or service account) that the perimeter’s tasks assume
- Its own database schema and artifact storage, holding the perimeter’s run metadata and results
- Its own set of secure package channels and policies, governing which packages are available to the perimeter’s workloads