Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
CSPモデルにおけるOCI設計ガイドライン / OCI Design Guide for CSPs
Search
Oracle Cloud Infrastructure ソリューション・エンジニア
December 28, 2022
Technology
0
1.4k
CSPモデルにおけるOCI設計ガイドライン / OCI Design Guide for CSPs
Cloud Solutions Provider (CSP) モデルでOracle Cloud Infrastructureを利用するにあたって、設計上の考慮事項をまとめた資料です。
Oracle Cloud Infrastructure ソリューション・エンジニア
December 28, 2022
Tweet
Share
More Decks by Oracle Cloud Infrastructure ソリューション・エンジニア
See All by Oracle Cloud Infrastructure ソリューション・エンジニア
OCI セキュア・デスクトップ 概要
ocise
0
2.6k
OCI技術資料 : リソース・マネージャ(Resource Manager)概要
ocise
0
2.6k
OCI技術資料 : ロード・バランサー 詳細 / Load Balancer 200
ocise
2
12k
Oracle Cloud Migrations Service概要
ocise
0
2.6k
OCI技術資料 : ロード・バランサー 概要 / Load Balancer 100
ocise
3
16k
OCI サービス基本情報
ocise
3
8.4k
Oracle Cloud Infrastructure はじめの一歩
ocise
1
36k
OCI 仮想テスト・アクセス・ポイント(VTAP)概要
ocise
0
1.1k
FastConnect 冗長性のベスト・プラクティス
ocise
0
6.2k
Other Decks in Technology
See All in Technology
フロントエンドの Monorepo をやめてリポジトリ分割したワケ / Why did we stop using Monorepo on the frontend and split the repository?
kaminashi
6
3.1k
初めましてが多いチームの形成期にEMが取り組んだ事
shoheimitani
1
120
What's is Bluesky
shinoharata
0
230
はてなのチーム開発一巡り / Hatena Engineer Seminar 30
daiksy
0
310
アジャイルの灯火を絶やさない! 社内アジャイルコミュニティ運営
hacomono
PRO
1
150
Copilot for Security を使った MDE / Sentinel のログ調査
sophiakunii
2
220
爆速開発文化を支えるProduct Engineerの 開発生産性向上の取り組み
shnjtk
8
3.3k
マイクロサービスの現場からプラットフォームエンジニアリングの可能性を探る!
abnoumaru
1
4.3k
Recap: Kotlin Language Features in 2.0 and Beyond (Michail Zarečenskij)
dalinaum
0
410
マルチエージェントで性能が上がったText-to-SQLのいま/Text-to-SQL
yoshidashingo
2
1.4k
私の推しサービス:Elastic Kubernetes Service(EKS)
daitak
1
210
awslim - Goで実装された高速なAWS CLIの代替品を作った/layerx.go#1
fujiwara3
1
260
Featured
See All Featured
Building Adaptive Systems
keathley
33
2k
Thoughts on Productivity
jonyablonski
62
4k
The Language of Interfaces
destraynor
151
23k
Raft: Consensus for Rubyists
vanstee
133
6.4k
Clear Off the Table
cherdarchuk
87
320k
The Brand Is Dead. Long Live the Brand.
mthomps
51
36k
Building a Modern Day E-commerce SEO Strategy
aleyda
22
6.6k
個人開発の失敗を避けるイケてる考え方 / tips for indie hackers
panda_program
73
15k
Keith and Marios Guide to Fast Websites
keithpitt
408
22k
Writing Fast Ruby
sferik
623
60k
The Invisible Customer
myddelton
115
13k
Code Reviewing Like a Champion
maltzj
516
39k
Transcript
Cloud Solutions Provider(CSP)モデルにおける OCI設計のガイドライン 2022/12/30
Copyright © 2022, Oracle and/or its affiliates 2 Oracle Cloud
Infrastructure( OCI) Cloud Solutions Provider (CSP) • • OCI
CSP* OCI / → Identity Domain CSP Copyright © 2022,
Oracle and/or its affiliates 3 OCI OCI+ *CSP( ): https://www.oracle.com/jp/partnernetwork/expertise/cloud-solutions-provider/
Oracle IaaS/Paas/Saas Copyright © 2022, Oracle and/or its affiliates 4
OCI IAM Identity Domains SSO (Outbound) • • SAML, OIDC, OAuth • • App Gateway • RADIUS • Linux PAM **** Oracle Cloud IaaS/PaaS • • • • OCI • ID • Console | CLI | APIs • / • • SCIM • AD • ( ) ! ? ü (Inbound) • ID/ • IdP • (SNS) • • • OATH OAuth FIDO2 REST APIs SAML OIDC SCIM IAM OCI IAM IDCS OCI IAM Identity Domains
( ) • 1 ※ • ( ) • Copyright
© 2022, Oracle and/or its affiliates 5 001 A (A ) B (B ) A B (A ) (B ) Default ( )
Copyright © 2022, Oracle and/or its affiliates 6 (1 )
(2 ) (3 ) Default Virtual Machine Block Storage Database ( ) Policies ( ) Policies Groups Groups
( ) Administrators ( ) • • (manage all-resources) ※
( ) ( ) Copyright © 2022, Oracle and/or its affiliates 7 Allow Group <Domain Name>/<Group Name> to manage all-resources in Compartment <Compartment Name>
Copyright © 2022, Oracle and/or its affiliates 8 • (
) ( ) • • • OCI CLI SDK • Free 10 • 6
( ) Copyright © 2022, Oracle and/or its affiliates 9
OCI (…in tenancy ) ( ) • (Cloud Shell ) • ( : Cloud Guard ) • (use) ( : ) • ( ) ( )
(allow group <domain/group> to…) inspect tenancies in tenancy IAM inspect
compartments in tenancy IAM manage tenancy-preferences in tenancy IAM manage network-sources in tenancy IAM ( ) use tag-namespaces in tenancy where any {target.tag-namspace.name ='XXX' } IAM ( ) read announcements in tenancy Announcement (Announcement) read objectstorage-namespaces in tenancy Object Storage API use cloud-shell in tenancy Cloud Shell ( ) ( ) (…in tenancy) Copyright © 2022, Oracle and/or its affiliates 10
Thank you 11 Copyright © 2022, Oracle and/or its affiliates
None
Our mission is to help people see data in new
ways, discover insights, unlock endless possibilities.