Skip to Content
InsightcloudsecHIDDEN

Configuring Oracle Cloud Infrastructure (OCI)

The information on this page has moved

For the most up-to-date Oracle Cloud Infrastructure (OCI) content, see OCI Overview & Support.

Legacy Content

🚧 New Onboarding Process for Connecting Cloud Accounts

The following content is for our legacy onboarding process for connecting a cloud account. Beginning with our 23.4.11 release InsightCloudSec includes a new onboarding workflow - documentation on that workflow is available on the new Oracle Cloud Infrastructure (OCI) - Onboarding.

If you are have issues or need support related to onboarding reach out to your CSA or contact us through the Customer Support Portal with any questions.

After InsightCloudSec is successfully installed, you’re ready to start harvesting resources from your target Oracle Cloud Infrastructure (OCI) accounts. This documentation provides details on configuring OCI to “talk” with InsightCloudSec securely. Review the sections below to determine the best starting point for your environment.

As with all of our features, if you have questions or concerns reach out to us through the Customer Support Portal.

Prerequisites

In OCI, a tenant is the top level construct. It is analogous to a project in GCP or a subscription within Azure. There are several steps that must be taken within the Oracle console to enable InsightCloudSec to get access to a tenant, and this page outlines those steps.

Additional Resources on OCI include:

Permissions

You must have administrative level privileges to execute these steps. Check out our User Entitlements Matrix for more details on InsightCloudSec permissions and entitlements.

Refer to Oracle’s documentation for more details how OCI manages permissions/policies.

Policy Options

Read-Only Policy

The Read-Only policy contains only read permissions for the OCI resources that InsightCloudSec supports. The policy can be obtained from our public S3 bucket. Note: This policy will need to be updated any time InsightCloudSec supports a new OCI service.

Power User Policy

The Power User policy contains various read and manage permissions for the OCI resources that InsightCloudSec supports. The policy can be obtained from our public S3 bucket. Note: This policy will need to be updated any time InsightCloudSec supports a new OCI service.

OCI_create_policy.png

Connecting a Tenant (Steps in the Oracle Console)

Creating a Group

1. Login to the Oracle console using the tenant you would like to connect to InsightCloudSec.

2. From the main navigation menu icon at the top left (hamburger menu icon), click to expand and select “Identity & Security” and then select “Domains”.

OCI_identity_and_security_domains.png

3. Select your domain from the list.

OCI_domains_view.png

4. Select “Groups” from the side navigation and then select “Create group”.
- Groups are required because IAM permissions are linked to groups and not individual accounts.

OCI_groups_list.png

5. Give your group a name (For example: InsightCloudSec) then select “Create”.

OCI_create_group.png

6. Once created, you will be redirected to the newly-created Group page (shown in the example below).

OCI_group_page.png

Creating a User & Adding an API Key

1. Navigate to the main domain page in the console and select your domain.

DefaultDomainOCI.png

2. Under the Identity Domain Section, select “Users” and “Create user”.

OCI_users_list.png

3. Complete the required user as desired and ensure that the group you created earlier is selected, select “Create” when complete.

OCI_create_user.png

4. Once created, you will be redirected to the newly-created user’s page. From the new user page, select “API keys” and select “Add API key”.

OCI_user_api_keys.png

5. Select “Download private key” button, and then select “Add”.

OCI_add_api_key.png

6. In the Configuration file preview, copy the contents and save them in a safe location. You will need these details to connect your account.

OCI_configuration_file_preview.png

Creating a Policy

1. From the main menu icon at the top left select “Identity & Security” and then select “Policies”.

OCI_identity_and_security_policies.png

2. Select the “Create Policy” button.

OCI_policies.png

3. Complete the required policy details as desired, and ensure you’ve enabled “Show manual editor”.

4. Select “Create” to submit the completed form.

Connecting a Tenant (Steps in InsightCloudSec)

1. From your InsightCloudSec platform, navigate to “Cloud —> Clouds” and select “Add a Cloud”.

2. Select Oracle from the drop-down menu and complete the form.

3. You will need to provide the credentials obtained/created from the Oracle Console.

  • For the “Key Content” you will want to supply the certificate information in the PEM file that you downloaded.

4. Click “Add Cloud” to complete this process when you’ve filled out the form.

AddcloudOracleForm.png