2 Overview of Oracle API Access Control
Learn how to classify and control access to critical OCI REST APIs
- What is Oracle API Access Control?
Oracle API Access Control enables customers to manage access to the REST APIs exposed by various database cloud services. - Database Control Plane APIs to Be Protected
You can use database control plane APIs to perform database and VM administration tasks. - Update API Attribute Groups
Some update operations in the OCI Console send related API attributes together in a single request. If any attribute in the request is protected by API Access Control, approval is required for all protected attributes included in that request, even if you modify only one attribute.
What is Oracle API Access Control?
Oracle API Access Control enables customers to manage access to the REST APIs exposed by various database cloud services.
By designating specific APIs as privileged, customers can ensure that invoking these APIs requires prior approval from an authorized group within their tenancy.
How it Works
- Mark APIs as Privileged: Identify critical APIs that could impact data integrity or service availability.
- Approval Workflow: Before a privileged API is invoked, the user intending to invoke the API must raise an Access Request with their OCI identity, and a different OCI identity that is authorized to approve Access Requests for the resource must approve the Access Request.
- Enhanced Security: This workflow helps to prevent unauthorized or accidental execution of sensitive actions, such as modifying or deleting databases, Grid Infrastructure, virtual machines, or network resources.
The workflow requires different identities to ask for access and approve access, including the cloud administrator account.
Key Benefits:
- Reduced Risk: Minimize accidental or malicious deletions of mission-critical database services.
- Separation of Duties: Ensure that API execution is distinct from approval, enhancing security and accountability.
Oracle API Access Control strengthens the security of OCI database cloud services by adding an extra authorization layer for critical operations. When enabled on Cloud Exadata Infrastructure, it extends protection to its associated Cloud VM Clusters and Container Databases.
Key functionalities:
- Enable Privileged API Protection: Customer Administrators can enable Oracle API Access Control for resources exposed by database cloud services.
- Designate Privileged APIs: Administrators can classify specific APIs as privileged, ensuring controlled access.
- Fine-Grained IAM Policies for Privileged API:
- Define which groups can approve API Access Requests.
- Grant separate permissions for creating and approving API Access Requests.
- Request and Approval Management:
- Administrators or designated groups can approve or reject API Access Requests.
- Users must submit detailed justifications for API access.
- Users can extend or close approved requests as needed.
- Approval Workflow Management:
- Manage workflows for approvals, including handling expiring or pending workflows.
- Send periodic reminders to approvers to act on pending requests that are left unattended.
Parent topic: Overview of Oracle API Access Control
Database Control Plane APIs to Be Protected
You can use database control plane APIs to perform database and VM administration tasks.
The following Database Cloud Service APIs will be secured under API Access Control protection. These APIs require prior approval before being invoked to ensure enhanced security and controlled access.
Exadata Database Service on Cloud@Customer
Backup APIs
DB Home APIs
Database APIs
- DeleteDatabase
- UpdateDataGuard
- SwitchOverDataGuard
- ReinstateDataGuard
- FailoverDataGuard
- CreatePluggableDatabase
- UpgradeDatabase
- UpdateDatabase
- RotateVaultKey
- RestoreDatabase
- MigrateVaultKey
Exadata Infrastructure APIs
- DeleteExadataInfrastructure
- UpdateExadataInfrastructure
- ChangeExadataInfrastructureCompartment
- AddStorageCapacityExadataInfrastructure
- GenerateRecommendedVmClusterNetwork
- CreateVmCluster
- CreateAutonomousVmCluster
- CreateVmClusterNetwork
Pluggable Database APIs
- DeletePluggableDatabase
- ConvertToRegularPluggableDatabase
- UpdatePluggableDatabase
- StartPluggableDatabase
- RefreshPluggableDatabase
- StopPluggableDatabase
VM Cluster APIs
- DeleteVmCluster
- RemoveVirtualMachineFromVmCluster
- CreateDbHome
- ChangeVmClusterCompartment
- AddVirtualMachineToVmCluster
- UpdateVmCluster
VM Cluster Network APIs
Virtual Machine APIs / DB Node APIs
Exadata Database Service on Dedicated Infrastructure
Backup APIs
DB Home APIs
Database APIs
- DeleteDatabase
- UpdateDataGuard
- SwitchOverDataGuard
- ReinstateDataGuard
- FailoverDataGuard
- CreatePluggableDatabase
- UpgradeDatabase
- UpdateDatabase
- RotateVaultKey
- RestoreDatabase
- EnableDatabaseManagement
- DisableDatabaseManagement
- ModifyDatabaseManagement
Cloud Exadata Infrastructure APIs
- DeleteCloudExadataInfrastructure
- UpdateCloudExadataInfrastructure
- ChangeCloudExadataInfrastructureCompartment
- AddStorageCapacityCloudExadataInfrastructure
- CreateCloudVmCluster
- CreateCloudAutonomousVmCluster
Pluggable Database APIs
- DeletePluggableDatabase
- ConvertToRegularPluggableDatabase
- UpdatePluggableDatabase
- StartPluggableDatabase
- RefreshPluggableDatabase
- StopPluggableDatabase
Cloud VM Cluster APIs
- DeleteCloudVmCluster
- RemoveVirtualMachineFromVmCluster
- CreateDbHome
- ChangeCloudVmClusterCompartment
- AddVirtualMachineToVmCluster
- UpdateCloudVmCluster
Virtual Machine APIs / DB Node APIs
Autonomous AI Database on Cloud@Customer
Autonomous VM Cluster APIs
Autonomous AI Database on Dedicated Infra (Public Cloud and Multi-Cloud)
Autonomous Cloud VM Cluster APIs
- CreateAutonomousContainerDatabase
- DeleteCloudAutonomousVmCluster
- RestartCloudAutonomousVmClusterOrds
- RotateCloudAutonomousVmClusterOrdsCerts
- RotateCloudAutonomousVmClusterSslCerts
- ChangeCloudAutonomousVmClusterCompartment
- UpdateCloudAutonomousVmCluster
- UpdateCloudAutonomousVmClusterDetails Reference
Autonomous AI Database on Dedicated Infrastructure (Public Cloud and Multi-Cloud) and Autonomous AI Database on Cloud@Customer
- Autonomous Container Database APIs
- CreateAutonomousDatabase
- TerminateAutonomousContainerDatabase
- RestartAutonomousContainerDatabase
- RotateAutonomousContainerDatabaseEncryptionKey
- ChangeAutonomousContainerDatabaseCompartment
- AddStandbyAutonomousContainerDatabase
- ConvertStandbyAutonomousContainerDatabase
- EditAutonomousContainerDatabaseDataguard
- FailoverAutonomousContainerDatabaseDataguard
- ReinstateAutonomousContainerDatabaseDataguard
- SwitchoverAutonomousContainerDatabaseDataguard
- UpdateAutonomousContainerDatabase
- UpdateAutonomousContainerDatabaseDetails Reference
- Autonomous AI Database
- DeleteAutonomousDatabase
- RestartAutonomousDatabase
- RestoreAutonomousDatabase
- StartAutonomousDatabase
- StopAutonomousDatabase
- RotateAutonomousDatabaseEncryptionKey
- ChangeAutonomousDatabaseCompartment
- RegisterAutonomousDatabaseDataSafe
- DeregisterAutonomousDatabaseDataSafe
- EnableAutonomousDatabaseManagement
- DisableAutonomousDatabaseManagement
- EnableAutonomousDatabaseOperationsInsights
- DisableAutonomousDatabaseOperationsInsights
- UpdateAutonomousDatabase
- UpdateAutonomousDatabaseDetails Reference
Parent topic: Overview of Oracle API Access Control
Update API Attribute Groups
Some update operations in the OCI Console send related API attributes together in a single request. If any attribute in the request is protected by API Access Control, approval is required for all protected attributes included in that request, even if you modify only one attribute.
When creating an API Access Control policy or requesting access, select all attributes in the applicable group shown in the following table.
- When using the OCI Console, request access to the entire attribute group.
- When using the CLI or API, include only the attributes that you intend to update.
Table 2-1 Update API Attribute Groups
| Update operation | Attribute group |
|---|---|
UpdateAutonomousVmCluster |
|
UpdateCloudAutonomousVmCluster |
|
UpdateAutonomousContainerDatabase |
|
UpdateAutonomousContainerDatabase |
|
For example, when you update dbSplitThreshold in the OCI Console, the request can also include vmFailoverReservation and distributionAffinity. If any of these attributes are protected by API Access Control, create the policy or request access for all protected attributes in the group.
This behavior applies only to the attribute groups listed in the preceding table. Other attributes on the same OCI Console page can be sent independently and do not require group-level approval.
Parent topic: Overview of Oracle API Access Control