Book Image

Oracle Cloud Infrastructure for Solutions Architects

By : Prasenjit Sarkar
Book Image

Oracle Cloud Infrastructure for Solutions Architects

By: Prasenjit Sarkar

Overview of this book

Oracle Cloud Infrastructure (OCI) is a set of complementary cloud services that enables you to build and run a wide range of applications and services in a highly available hosted environment. This book is a fast-paced practical guide that will help you develop the capabilities to leverage OCI services and effectively manage your cloud infrastructure. Oracle Cloud Infrastructure for Solutions Architects begins by helping you get to grips with the fundamentals of Oracle Cloud Infrastructure, and moves on to cover the building blocks of the layers of Infrastructure as a Service (IaaS), such as Identity and Access Management (IAM), compute, storage, network, and database. As you advance, you’ll delve into the development aspects of OCI, where you’ll learn to build cloud-native applications and perform operations on OCI resources as well as use the CLI, API, and SDK. Finally, you’ll explore the capabilities of building an Oracle hybrid cloud infrastructure. By the end of this book, you’ll have learned how to leverage the OCI and gained a solid understanding of the persona of an architect as well as a developer’s perspective.
Table of Contents (15 chapters)
1
Section 1: Core Concepts of Oracle Cloud Infrastructure
Free Chapter
2
Chapter 1: Introduction to Oracle Cloud Infrastructure
7
Section 2: Understanding the Additional Layers of Oracle Cloud Infrastructure

Accessing resources from compartments using a policy

A policy is an entity that specifies which groups can access specific resources, and in which ways. You tend to assign access at the compartment level, which indicates that all users in the group, to which the policy is assigned, can access all the resources within that compartment using the level of permission specified in the policy. Policies can also be applied at the tenancy level, and in such cases, the granted access is available to all compartments within the tenancy.

There are three requirements for a policy: an action or a verb, a resource type, and whether the policy is at the tenancy or compartment level. Furthermore, IAM allows granular policies, so they can be applied at either the aggregate level or the individual resource level. Polices can also include one more condition. Conditions such as any or all can be used. You can also use multiple conditions using logical OR and AND operators.

For conditions, you can...