OKEãOCIRã使ãã¨ãã«æ¨©éå¶å¾¡ããããã®è¨å®ã¾ã¨ã
ãã®ã¨ã³ããªã¼ã¯Oracle Cloud ã¢ããã³ãã«ã¬ã³ãã¼ãã®2ã®22æ¥ç®ã§ãã
ä»åã¯Oracleãæä¾ããã³ã³ããé¢é£ã®ã¯ã©ã¦ããµã¼ãã¹ã§ãããOKEãOCIRã使ãä¸ã§ã®ãæºåã«å½ããä½æ¥ã®è©±ãæ¸ãããã¨æãã¾ãã
- OKE:
- Oracle Container Engine for Kubernetes
- Oracleãæä¾ããããã¼ã¸ãKubernetesãµã¼ãã¹
- OCIR
- Oracle Cloud Infrastructure Registry
- Oracleãæä¾ããã³ã³ããã¬ã¸ã¹ããªã®ããã¼ã¸ãã»ãµã¼ãã¹
ãããã使ãã«ã¯ãPolicyã¨å¼ã°ããã¢ã¯ã»ã¹æ¨©éã®è¨å®ãäºããã¦ããå¿ è¦ãããã¾ãã ãã®ã¨ã³ããªã¼ã§ã¯ããããå¿ è¦ãªæ¨©éå¨ãã®è¨å®ãæ´çãããã¨æãã¾ãï¼ä»ã®ã¨ã³ããªã¼ã§ã¯ãã®ã¨ã³ããªã¼ã§å¿ è¦ãªãã®ã ãæ¸ãã¦ããã®ã§ï¼ã
管çè 権éãæã¡è¾¼ãã°ããã«ä½¿ããããã«ã¯ãªãã¾ãããã¡ããã¨æ¨©éãåãããã¨ãã«ã¯ãã®æ å ±ãç®ç¨ãã¦ãã ããã
OKEã使ãããã«å¿ è¦ãªããªã·ã¼
注: in tenancy
ãin compartment [ã³ã³ãã¼ãã¡ã³ãå]
ã®ããã«ããã¨ã権éã®åã¶ç¯å²ãã³ã³ãã¼ãåã«çµãäºãã§ãã¾ãã
OKEã®PaaSã«ä¸ãã権éOKEã使ã¤ã¨ãã¯å¿ é
- Statement:
Allow service OKE to manage all-resources in tenancy
- 説æ:
- OKEã®PaaSã«æ¨©éãä¸ããããã®ç¹æ®ãªããªã·ã¼ãOKEã使ãã¨ãã¯ãããå¿ ãä½ããããããªãã¨å§ã¾ããªã
- Statement:
OKEã¯ã©ã¹ã¿ã¼ã¨Node Poolãæä½ãã権é
- Statement:
Allow group [ã°ã«ã¼ãå] to manage cluster-family in tenancy
Allow group [ã°ã«ã¼ãå] to inspect vcns in tenancy
Allow group [ã°ã«ã¼ãå] to inspect subnets in tenancy
- 説æ:
- OKEã®ã¯ã©ã¹ã¿ã¼ã¨Node Poodãæä½ãã権éï¼3ã¤ã»ããï¼ã3ã¤ã®ãã¡ä¸ã®ã®2ã¤ã¯ãã¯ã©ã¹ã¿ã¼ãä¾åããä¸åãã®ãããã¯ã¼ã¯ãåç §ããããã®ãã®ã
- ãã®ã»ããã«ã¯ä¸åãã®ãããã¯ã¼ã¯ãããã権éã¯å«ã¾ããªãï¼ä¾åãããããã¯ã¼ã¯ã¯ä½ææ¸ã¿ã®åæï¼
- Statement:
OKEã¯ã©ã¹ã¿ã¼ã¨Node Poolãæä½ãã権é + ãããã¯ã¼ã¯ã®æä½æ¨©é
- Statement:
Allow group [ã°ã«ã¼ãå] to manage cluster-family in tenancy
Allow group [ã°ã«ã¼ãå] to manage virtual-network-family in tenancy
- 説æ:
- OKEããããã¯ã¼ã¯ãå«ãã¦ä½ã£ããæä½ãããã¨ãã«å¿ è¦ãªæ¨©éã2ã¤ç®ã®æ¹ã¯ä¸åãã®ãããã¯ã¼ã¯ãæä½ããããã®ãã®
- OKEä½æã®ãã¤ã¢ãã°ã§
quick cluster
ã使ãã¨ãã«ã¯ãã®æ¨©éãå¿ è¦
- Statement:
OKEã¯ã©ã¹ã¿ã¼ãåç §ãã権é
- Statement:
Allow group [ã°ã«ã¼ãå] to inspect clusters in tenancy
- 説æ:
- OKEã®ã¯ã©ã¹ã¿ã¼ãåç §ãã権é
- Statement:
OKEã¯ã©ã¹ã¿ã¼ã®Node Poolãæä½ãã権é
- Statement:
Allow group [ã°ã«ã¼ãå] to use cluster-node-pools in tenancy
- 説æ:
- ä½ææ¸ã¿ã®OKEã¯ã©ã¹ã¿ã¼ã®Node Poolã追å ãåé¤ãã¢ãããã¼ãï¼æ§æå¤æ´ãªã©ï¼ãã権é
- Statement:
OKEã¯ã©ã¹ã¿ã¼ã¸ã®æä½ã®ç£æ»æ å ±ãåç §ãã権é
- Statement:
Allow group [ã°ã«ã¼ãå] to read cluster-work-requests in tenancy
- 説æ:
- OKEã¯ã©ã¹ã¿ã¼ã¸ã®æä½ã®ç£æ»æ å ±ãåç §ãã権é
- Statement:
OCIRã使ãããã«å¿ è¦ãªããªã·ã¼
以ä¸ã¯å ¨ã¦ãç¶²ç¾ ãããã®ã§ã¯ããã¾ããããã»ã¨ãã©ã®ã±ã¼ã¹ã¯ããããããã°å¤§ä¸å¤«ãã¨æãã¾ãã
ãªãã¸ããªã®é²è¦§æ¨©é
- Statement:
Allow group [ã°ã«ã¼ãå] to inspect repos in tenancy
- 説æ:
- OCIRã®ãªãã¸ããªã®é²è¦§æ¨©é
- Statement:
ã¤ã¡ã¼ã¸ã®åå¾æ¨©éï¼å ¨ã¦ã®ãªãã¸ããªï¼
- Statement:
Allow group [ã°ã«ã¼ãå] to read repos in tenancy
- 説æ:
- OCIRã®å ¨ã¦ã®ãªãã¸ããªã®ã¤ã¡ã¼ã¸ãpullãã権é
- Statement:
ã¤ã¡ã¼ã¸ã®åå¾æ¨©éï¼ãªãã¸ããªãéå®ï¼
- Statement:
Allow group [ã°ã«ã¼ãå] to read repos in tenancy where all { target.repo.name=/[ãªãã¸ããªå]/ }
- 説æ:
- OCIRã®æå®ããããªãã¸ããªã®ã¤ã¡ã¼ã¸ãpullãã権éã
/example-app*/
ã®ããã«æ£è¦è¡¨ç¾ã使ããã¨ãã§ãã模æ§
- OCIRã®æå®ããããªãã¸ããªã®ã¤ã¡ã¼ã¸ãpullãã権éã
- Statement:
ã¤ã¡ã¼ã¸ã®ç»é²æ¨©éï¼å ¨ã¦ã®ãªãã¸ããªï¼
- Statement:
Allow group [ã°ã«ã¼ãå] to use repos in tenancy
- 説æ:
- OCIRã®å ¨ã¦ã®ãªãã¸ããªã«ã¤ã¡ã¼ã¸ãpushãã権é
- Statement:
ã¤ã¡ã¼ã¸ã®ç»é²æ¨©éï¼ãªãã¸ããªãåå¨ããªãå ´åã«æ°ãã«ä½ã権éã追å ï¼
- Statement:
Allow group [ã°ã«ã¼ãå] to manage repos in tenancy where ANY {request.permission = 'REPOSITORY_CREATE', request.permission = 'REPOSITORY_UPDATE'}
- 説æ:
- OCIRã®å ¨ã¦ã®ãªãã¸ããªã«ã¤ã¡ã¼ã¸ãpushãã権éããªãã¸ããªãåå¨ããªãå ´åã«æ°ãã«ä½ã権éã追å ï¼
- Statement:
OCIRã¸ã®ãã«ã¢ã¯ã»ã¹
- Statement:
Allow group [ã°ã«ã¼ãå] to manage repos in tenancy
- 説æ:
- ããã³ãå ã®ãªãã¸ããªã«å¯¾ããå ¨æ¨©é
- Statement: