将 Oracle Analytics 与 Oracle Cloud Infrastructure (OCI) 数据科学集成,在不需要数据科学家专业知识的情况下执行机器学习和人工智能。例如,对于医疗保健数据,可以使用预测模型确定风险因素并预测病人在出院后再入院的风险。
您需要满足以下先决条件才能将 OCI 数据科学与 Oracle Analytics 集成。
要将 Oracle Analytics 与 OCI 数据科学服务集成,请确保您具有所需的安全策略。
您在 Oracle Analytics Cloud 与 OCI 租户的连接中指定的 OCI 用户必须对您要使用的 OCI 资源所在的区间具有读取、写入和删除权限。确保该 OCI 用户所属的用户组至少具有以下 OCI 安全策略。从 Oracle Analytics 连接到 OCI 租户时,可以使用 OCI API 密钥或资源主体。
注:
Oracle Cloud ID (OCID) 是 OCI 中使用的资源标识符。注:
对于资源主体,要将所有分析实例包含在一个区间下,请指定{request.principal.type='analyticsinstance', request.principal.compartment.id='<compartmentA_ocid>'}
而非 {request.principal.id='<analytics_instance_ocid>'}
。API 密钥策略 | 资源主体策略 |
---|---|
Allow group <group_name> to read data-science-projects in compartment <compartment_name> |
Allow any-user to read data-science-projects in compartment <compartment_name> where all {request.principal.id='<analytics_instance_ocid>'} |
Allow group <group_name> to read data-science-models in compartment <compartment_name> |
Allow any-user to read data-science-models in compartment <compartment_name> where all {request.principal.id='<analytics_instance_ocid>'} |
Allow group <group_name> to manage data-science-jobs in compartment <compartment_name> |
Allow any-user to manage data-science-jobs in compartment <compartment_name> where all {request.principal.id='<analytics_instance_ocid>'} |
Allow group <group_name> to inspect instance-family in compartment <compartment_name> |
Allow any-user to inspect instance-family in compartment <compartment_name> where all {request.principal.id='<analytics_instance_ocid>'} |
Allow group <group_name> to manage data-science-job-runs in compartment <compartment_name> |
Allow any-user to manage data-science-job-runs in compartment <compartment_name> where all {request.principal.id='<analytics_instance_ocid>'} |
Allow group <group_name> to inspect virtual-network-family in compartment <compartment_name> |
Allow any-user to inspect virtual-network-family in compartment <compartment_name> where all {request.principal.id='<analytics_instance_ocid>'} |
Allow service datascience to use virtual-network-family in compartment <compartment_name> |
Allow service datascience to use virtual-network-family in compartment <compartment_name> |
Allow group <group_name> to manage log-groups in compartment <compartment_name> |
Allow any-user to manage log-groups in compartment <compartment_name> where all {request.principal.id='<analytics_instance_ocid>'} |
Allow group <group_name> to read buckets in compartment <compartment_name> |
Allow any-user to read buckets in compartment <compartment_name> where all {request.principal.id='<analytics_instance_ocid>'} |
Allow group <group_name> to manage objects in compartment <compartment_name> where target.bucket.name='<staging_bucket_name>' |
Allow any-user to manage objects in compartment <compartment_name> where all {request.principal.id='<analytics_instance_ocid>', target.bucket.name='<staging_bucket_name>'} |
Allow group <group_name> to read objectstorage-namespaces in compartment <compartment_name> |
Allow any-user to read objectstorage-namespaces in compartment <compartment_name> where all {request.principal.id='<analytics_instance_ocid>'} |
动态组策略 | 说明 |
---|---|
Allow dynamic-group <dynamic_group> to read data-science-models in compartment <compartment_name> |
提供对数据科学作业运行的数据科学模型访问。 |
Allow dynamic-group <dynamic_group> to manage objects in compartment <compartment_name> where target.bucket.name='<staging_bucket_name>' |
提供对数据科学作业运行的对象存储访问。 |
Allow dynamic-group <dynamic_group> to use log-content in compartment <compartment_name> |
提供对数据科学作业运行的日志访问。 |
注:
指定<dynamic_group>
时,使用以下格式的匹配规则:all { resource.type='datasciencejobrun', resource.compartment.id='<compartment_ocid>' }
,其中 <compartment_ocid
> 是包含数据科学模型的区间的 Oracle Cloud ID。要使用 Oracle Cloud Infrastructure (OCI) 数据科学模型分析数据,应在 Oracle Analytics 中注册它们。