Process information about this architecture is provided in the surrounding paragraphs.

This image shows a single tenancy and compartment encompassing two regions, each with a single virtual cloud network (VCN). The London region is used for data science and the Frankfurt region is used for machine learning. The regions are connected by using remote peering.

The tenancy provides object storage and storage buckets for experimental systems for both regions. The tenancy also provides Oracle Cloud Infrastructure Identity and Access Management, policies, groups, a route table, security lists, logging, firewall, DNS, and container registry services.

Both VCNs provide the following gateways:
  • NAT gateway: Enables private resources in a VCN to access hosts on the internet, without exposing those resources to incoming internet connections.
  • Service gateway: VCNs communicate with services such as object storage over the Oracle network fabric without traversing the internet.
  • Dynamic routing gateway (DRG): Provides private connectivity for remote peering.
  • Remote Peering: Allow subnet resources in different regions to communicate using private IP addresses without routing the traffic over the internet or through your on-premises network.

The London (data science) region connects to the customer premises equipment and users by using a site-to-site VPN. The VCN provides the following subnets arranged as functional tiers. Each subnet provides a security list and route table:

The Frankfurt (machine learning) region provides similar support services, but a different production flow and resources: