This image shows an Oracle Cloud Infrastructure Tenancy with compartments, Management Groups, and the following resources in the Tenancy (Root Compartment): Budget, Policies, IAM Events, Cloud Guard, Budget Events, Notifications, and Topic. Budget Events, Notifications, and Topic appear in a box with a dotted line. The following are in Management Groups: Cost Admins, Storage Admins, Cred Admins, Auditors, IAM Admins, Network Admins, Security Admins, App Admins, Database Admins, and Exadata Admins.

An Enclosing Compartment is located inside the Tenancy (Root Compartment) and contains Policies and the Security Zone. The following compartments reside within the Enclosing Compartment: Network, Security, App, Database, and Exadata. The template provisions Alarms, Events, Notifications, Topic, and Subscriber resources inside the Network, Security, App, Database, and Exadata compartments.

The Network compartment has two Virtual Cloud Networks (VCNs): A VCN and an Exadata VCN. By default, the template deploys a standard three-tier VCN with one regional public subnet and two regional private subnets. The VCN has a Web Subnet, App Subnet, and Database Subnet. The Exadata VCN has two regional private subnets: a Client Subnet and a Backup Subnet. It also has Alarms, Events, Notifications, Topic, and Subscriber resources.

The Security compartment is provisioned with Vault and Keys, Vulnerability Scanning, Logging, Service Connector Hub, Bastion, Object Storage Buckets, Alarms, Events, Notifications, Subscriber, and Topic resources.

The App Compartment is provisioned with Object Storage buckets, Alarms, Events, Notifications, Subscriber, and Topic resources. The App Compartment can contain other application-related resources that you might need in addition to those provisioned by the template. For example, the template does not provision the following resources: Functions, Container Engine for Kubernetes clusters, Compute instances, Block Storage, Streaming, and File Storage.

The Database Compartment is for any database resources that you want to provision. It is provisioned with Object Storage buckets, Alarms, Events, Notifications, Subscriber, and Topic resources. The template does not provision the databases, including Oracle Autonomous Transaction Processing (ATP), Oracle Autonomous Data Warehouse, VM Database, and Exadata Cloud Service.

Exadata Compartment is for Exadata resources, including the infrastructure, VM clusters and database systems. It is provisioned with Object Storage buckets, Alarms, Events, Notifications, Subscriber, and Topic resources. The template does not provision the Exadata System. Alternatively, these resources can be deployed in the Database compartment and managed by Database administrators.

The arrows at the top indicate overall admin permissions granted to management groups over resources across the compartments, as follows: