Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
CSPモデルにおけるOCI設計ガイドライン / OCI Design Guide for CSPs
Search
Oracle Cloud Infrastructure ソリューション・エンジニア
December 28, 2022
Technology
0
1.3k
CSPモデルにおけるOCI設計ガイドライン / OCI Design Guide for CSPs
Cloud Solutions Provider (CSP) モデルでOracle Cloud Infrastructureを利用するにあたって、設計上の考慮事項をまとめた資料です。
Oracle Cloud Infrastructure ソリューション・エンジニア
December 28, 2022
Tweet
Share
More Decks by Oracle Cloud Infrastructure ソリューション・エンジニア
See All by Oracle Cloud Infrastructure ソリューション・エンジニア
OCI セキュア・デスクトップ 概要
ocise
0
2.1k
OCI技術資料 : リソース・マネージャ(Resource Manager)概要
ocise
0
2.3k
OCI技術資料 : ロード・バランサー 詳細 / Load Balancer 200
ocise
2
12k
Oracle Cloud Migrations Service概要
ocise
0
2.1k
OCI技術資料 : ロード・バランサー 概要 / Load Balancer 100
ocise
3
15k
OCI サービス基本情報
ocise
3
8.1k
Oracle Cloud Infrastructure はじめの一歩
ocise
1
35k
OCI 仮想テスト・アクセス・ポイント(VTAP)概要
ocise
0
1k
FastConnect 冗長性のベスト・プラクティス
ocise
0
5.5k
Other Decks in Technology
See All in Technology
【基本】データベース設計
oracle4engineer
PRO
2
250
Azureの基本的な権限管理の勉強会
yhana
1
2.2k
LLM開発・活用の舞台裏@2024.04.25
yushin_n
3
1.3k
Babylon.js JAPAN活動紹介 (2024/4)
limes2018
1
120
Gradle Build Scanを使ってビルドのことを知ろう potatotips #87
tomorrowkey
2
160
中年男性がメインフレームから クラウドへキャリアシフトしてみた
uechishingo
0
390
ルーターでプレゼンする
puhitaku
1
3.4k
コードファーストの考え方。 Amplify Gen2から学ぶAWS次世代のWeb開発体験
yoshiitaka
2
500
今日からできる!簡単 .NET 高速化 Tips -2024 edition-
xin9le
7
4.6k
エンジニア候補者向け資料2024.04.24.pdf
macloud
0
3.4k
Cypress or Playwright?
rainerhahnekamp
0
180
一生覚えておきたい「システム開発=コミュニケーション」〜初めての実務案件振り返りLT〜
maimyyym
3
410
Featured
See All Featured
What’s in a name? Adding method to the madness
productmarketing
PRO
17
2.7k
Design and Strategy: How to Deal with People Who Don’t "Get" Design
morganepeng
117
18k
Responsive Adventures: Dirty Tricks From The Dark Corners of Front-End
smashingmag
245
20k
Sharpening the Axe: The Primacy of Toolmaking
bcantrill
22
1.4k
Infographics Made Easy
chrislema
238
18k
Fight the Zombie Pattern Library - RWD Summit 2016
marcelosomers
228
16k
Designing on Purpose - Digital PM Summit 2013
jponch
111
6.5k
Statistics for Hackers
jakevdp
790
220k
Reflections from 52 weeks, 52 projects
jeffersonlam
345
19k
A Tale of Four Properties
chriscoyier
153
22k
Building a Modern Day E-commerce SEO Strategy
aleyda
22
6.4k
Testing 201, or: Great Expectations
jmmastey
30
6.4k
Transcript
Cloud Solutions Provider(CSP)モデルにおける OCI設計のガイドライン 2022/12/30
Copyright © 2022, Oracle and/or its affiliates 2 Oracle Cloud
Infrastructure( OCI) Cloud Solutions Provider (CSP) • • OCI
CSP* OCI / → Identity Domain CSP Copyright © 2022,
Oracle and/or its affiliates 3 OCI OCI+ *CSP( ): https://www.oracle.com/jp/partnernetwork/expertise/cloud-solutions-provider/
Oracle IaaS/Paas/Saas Copyright © 2022, Oracle and/or its affiliates 4
OCI IAM Identity Domains SSO (Outbound) • • SAML, OIDC, OAuth • • App Gateway • RADIUS • Linux PAM **** Oracle Cloud IaaS/PaaS • • • • OCI • ID • Console | CLI | APIs • / • • SCIM • AD • ( ) ! ? ü (Inbound) • ID/ • IdP • (SNS) • • • OATH OAuth FIDO2 REST APIs SAML OIDC SCIM IAM OCI IAM IDCS OCI IAM Identity Domains
( ) • 1 ※ • ( ) • Copyright
© 2022, Oracle and/or its affiliates 5 001 A (A ) B (B ) A B (A ) (B ) Default ( )
Copyright © 2022, Oracle and/or its affiliates 6 (1 )
(2 ) (3 ) Default Virtual Machine Block Storage Database ( ) Policies ( ) Policies Groups Groups
( ) Administrators ( ) • • (manage all-resources) ※
( ) ( ) Copyright © 2022, Oracle and/or its affiliates 7 Allow Group <Domain Name>/<Group Name> to manage all-resources in Compartment <Compartment Name>
Copyright © 2022, Oracle and/or its affiliates 8 • (
) ( ) • • • OCI CLI SDK • Free 10 • 6
( ) Copyright © 2022, Oracle and/or its affiliates 9
OCI (…in tenancy ) ( ) • (Cloud Shell ) • ( : Cloud Guard ) • (use) ( : ) • ( ) ( )
(allow group <domain/group> to…) inspect tenancies in tenancy IAM inspect
compartments in tenancy IAM manage tenancy-preferences in tenancy IAM manage network-sources in tenancy IAM ( ) use tag-namespaces in tenancy where any {target.tag-namspace.name ='XXX' } IAM ( ) read announcements in tenancy Announcement (Announcement) read objectstorage-namespaces in tenancy Object Storage API use cloud-shell in tenancy Cloud Shell ( ) ( ) (…in tenancy) Copyright © 2022, Oracle and/or its affiliates 10
Thank you 11 Copyright © 2022, Oracle and/or its affiliates
None
Our mission is to help people see data in new
ways, discover insights, unlock endless possibilities.