Deploy an HCP Boundary cluster
HCP Boundary is a fully managed service that lets you deploy a production-ready Boundary cluster in minutes. Boundary enables secure, identity-based access to dynamic infrastructure without distributing credentials or exposing your network. By the end of this tutorial, you will have a running HCP Boundary cluster and an administrator account ready for the next steps in this series.
Prerequisites
- An HCP account to complete this tutorial.
- Boundary is installed.
Create a Boundary instance
Launch the HCP Portal and login.
From the Overview page, click Boundary in the left navigation menu.
Click Deploy Boundary.

In the Instance Name text box, provide a name for your Boundary instance.
Under Choose a tier, select the Standard tier to complete this collection of tutorials. If you plan on completing a session recording tutorial, select the Plus tier instead.
Under the Create an administrator account section, enter the Username and Password for the initial Boundary administrator account.
Click Deploy.
Wait for the instance to initialize before proceeding.
Open a new terminal and export an environment variable for the admin username.
$ export BOUNDARY_ADMIN=<actual-admin-username-created>
Boundary overview
When the HCP Boundary deployment completes, you will be redirected to the Boundary Overview page. The overview page provides details about instance.
- Instance details
- Instructions on connecting Boundary Desktop to the HCP Boundary instance.
- Session usage, including active and terminated sessions.

Knowledge checks
A quiz to test your knowledge.
What is the purpose of selecting the Plus tier instead of the Standard tier when deploying HCP Boundary?
🔘 The Plus tier provides a higher number of concurrent users for all Boundary features.
🔘 The Plus tier is required to deploy Boundary in a private network.
🔘 The Plus tier is required to complete session recording tutorials.
🔘 The Plus tier enables OIDC authentication for the admin account.
❌ The Plus tier provides a higher number of concurrent users for all Boundary features.
❌ The Plus tier is required to deploy Boundary in a private network.
✅ The Plus tier is required to complete session recording tutorials.
❌ The Plus tier enables OIDC authentication for the admin account.
Why does the tutorial recommend using a non-standard username and a strong password for the initial Boundary administrator account?
The HCP Boundary instance is publicly accessible, so using a non-standard username and strong password reduces the risk of unauthorized access through credential guessing or brute-force attacks.
What information does the Boundary Overview page display after the HCP Boundary deployment completes?
🔘 Deployment logs, version history, and network configuration.
🔘 Instance details, instructions for connecting Boundary Desktop, and session usage.
🔘 Active workers, pending upgrades, and storage metrics.
🔘 Auth methods, org list, and target inventory.
❌ Deployment logs, version history, and network configuration.
✅ Instance details, instructions for connecting Boundary Desktop, and session usage.
❌ Active workers, pending upgrades, and storage metrics.
❌ Auth methods, org list, and target inventory.
Next steps
You have successfully created a Boundary instance on the HashiCorp Cloud Platform. In the next tutorial you will learn how to connect to HCP Boundary through the Admin UI and Boundary CLI.