Enable and Manage Automatic Registration from a Database Console

Overview

In the Oracle Cloud Infrastructure console, you can enable Oracle Data Safe automatic registration for the pluggable databases (PDBs) in an ExaDB-D deployment when you create a new container database (CDB) or manage an existing one.

When you enable automatic registration for a CDB, Oracle Data Safe discovers eligible existing and future PDBs. Eligible PDBs are registered automatically. You can monitor registration progress and target status from the Registration policies and Target databases pages.

By default, automatic registration enables the following Oracle Data Safe features on the target databases:

  • Security and user assessment
  • Audit collection
  • Audit setting
  • Data discovery

Note

Note: You can enable the Data masking and SQL Firewall features after all the target databases are registered if needed. You cannot disable Security and user assessment. SQL Firewall management in Oracle Data Safe is only available for Oracle AI Database 26ai target databases.

Once a target database is associated with a registration policy, you cannot edit its connection details. If the target database is no longer part of a registration policy, you can edit its connection details.

Before enabling automatic registration, be sure to complete the necessary preregistration tasks. See Preregistration Tasks.

Preregistration Tasks

The following table lists tasks that you need to complete before you enable automatic registration on a CDB.

Task Number Task Links to Instructions
1 In Oracle Cloud Infrastructure Identity and Access Management (IAM), obtain permissions to automatically register your database. Permissions to Automatically Register PDBs in Oracle Exadata Database Service on Dedicated Infrastructure.
2 (Optional) If you plan to create an Oracle Data Safe private endpoint before creating a registration policy in Oracle Data Safe, make sure that the private endpoint can connect to the CDB and PDB listener endpoints. You are responsible for configuring required network security groups, security lists, route tables, firewalls, and other network controls. Oracle Data Safe does not modify these customer network resources automatically. Create an Oracle Data Safe Private Endpoint.

Enable Automatic Registration on a CDB that Supports Private Endpoint Only

  1. If you are creating a container database (CDB), in your database’s console, on the Create database panel, under Security, turn on Enable Data Safe. In the dialog box, confirm by selecting Enable.

  2. If you already have a CDB, in your database’s console, on the Database information page for your CDB, locate the Security section. Next to Data Safe, select Enable. In the dialog box, confirm by selecting Enable.

    A work request is started. You can monitor the work request on the Work requests tab.

    A registration policy in Oracle Data Safe is created for your CDB. Oracle Data Safe begins discovering and registering eligible PDBs in the background. It also creates the Oracle Data Safe service account on each PDB and enables the default Oracle Data Safe features.

  3. To go directly to the registration information for your target database in Oracle Data Safe, on the Database Information page next to Data Safe, select the three dots, and then select View details.

    The Target databases page in Oracle Data Safe opens. The registered CDB and its registered PDBs are listed. The registration policy’s background process takes affect a few minutes after the registration policy is created.

  4. Select a target database to view its information. Details relevant to automatic registration include Database and connection details and Feature grants.

Post Registration Tasks

The following table lists tasks that you need to complete after you enable automatic registration on a CDB.

Task Number Task Link to Instructions
1 (Optional) Modify which features are granted on your registered target databases. Edit Feature Grants in a Registration Policy
Edit Feature Grants on a Registered Target Database
2 Make sure to allow ingress traffic to your target database from the Oracle Data Safe private endpoint. (none)

Disable Automatic Registration for a CDB

Disabling automatic registration from the database console removes the registration policy resource from Oracle Data Safe. Oracle Data Safe no longer registers future PDBs, but previously registered target databases remain registered. To deregister these target databases, see Deregister a Target Database.

  1. On the Database information page for your CDB, locate the Security section.

  2. Next to Data Safe, select the three dots, and then select Disable.

    The Disable Data Safe panel opens.

  3. Turn off Enable Data Safe.

    If you do not have the necessary permissions, the message Must grant Data Safe permissions is displayed. Cancel the operation and review the required permissions in Preregistration Tasks.

  4. Select Save.

  5. (Optional) To monitor the operation, select the Work requests tab and view the Delete Data Safe Registration Policy operation.

  6. (Optional) To verify that the registration policy is removed in Oracle Data Safe, do the following:

    a. On the Database Information page, next to Data Safe, select the three dots, and then select View details.

    b. Under Target databases on the left, select Registration policies.

    c. Select your compartment and locate your registration policy. Its status is Deleting.