Prerequisites

1: Permissions for Onboarding and Provisioning

Many of the tasks you perform during Oracle Database@Google Cloud onboarding require permissions in either Google Cloud or the OCI cloud.

For details on the permissions you need for each task of the onboarding process, and for provisioning operations after you onboard, see Permissions Information by User Persona for Oracle Database@Google Cloud.

Identifying Individuals with Permissions

Before you begin onboarding, identify the individuals in your organization with the permissions in the following section and ensure they're available to complete the corresponding steps.

Granting OCI IAM Permissions for Oracle Database@Google Cloud

For the OCI tenancy, users who are tenancy administrators don't need extra permissions for the tasks listed in the table in this topic. Users who aren't tenancy administrators need to be part of a group that's assigned the policy statements in the table.

To grant users the required permissions:

  1. Create a new group in the default domain, or use an existing group. See Creating a Group for more information.
  2. Create a policy in the root compartment with the required policy statements, specifying the group created in the previous step in the policy statements. See Creating a Policy for more information.
  3. Add users to the group. See Adding Users to a Group for more information.

Permissions Information by User Persona for Oracle Database@Google Cloud

Task Cloud Personas Permissions
Request Offer - private offer Google Cloud Google Cloud administrator Project owner or contributor
Public Offer (Pay As You Go) - Pay as You Go offer Google Cloud Google Cloud administrator Billing Account Owner, Contributor
Link an OCI Account Google Cloud and OCI

Google Cloud Persona: Google Cloud administrator

OCI Persona:
  • Existing tenancy: OCI Administrator

  • New tenancy: User performing onboarding becomes Owner / Administrator of new tenancy

Google Cloud Permissions: Project owner or editor

OCI Permissions: OCI Account Owner, OCI Administrator

Register with My Oracle Support OCI OCI Support Owner OCI Support Owner
Verify the Subscription, Limits, and Compartments in OCI OCI OCI Support Owner OCI Support Owner
Setup Role Based Access Control (RBAC) Google Cloud Google Cloud IAM & Admin administrator Google Cloud IAM & Admin: Groups Administrator, User Administrator
Identity Federation (optional) Google Cloud and OCI Google Cloud IAM & Admin administrator,OCI Identity Domain administrator Google Cloud IAM & Admin: External Identity Provider Administrator, Groups Administrator, User Administrator, OCI Identity Domain Administrator

2: Google Cloud Project and Billing Account

You need a Google Cloud project that you want to use when deploying Oracle Database@Google Cloud database resources.

The Google Cloud Billing account you select for onboarding with Oracle Database@Google Cloud becomes the primary Cloud Billing account for the offer that you buy and you can deploy Oracle Database@Google Cloud resources in the projects sharing the same Google Cloud Billing account. Your Google Cloud bill displays the total cost for Oracle Database@Google Cloud usage under the primary Billing account used for the offer.

3: An Oracle Cloud Infrastructure (OCI) Account

For private offer purchases, if you have an existing Oracle Cloud Infrastructure (OCI) account, you can connect it to Oracle Database@Google Cloud during in the onboarding process. Otherwise, you can create a new OCI account to link later in the process.

For public (Pay As You Go) offer purchases, you must create a new OCI account during onboarding.