Creating an Application
Applications define managed runtime settings for hosted deployments, including scaling, managed storage, networking, and authentication. This task explains how to create an application by using the Oracle Cloud Console in the OCI Generative AI service.
On the Applications list page, select Create application. If you need help finding the list page, see Listing Applications.
Basic Information
Tags
- (Optional) Select Add tag and assign tags to this application. See Resource Tags.
- Select Create.
Scaling
Storage (Optional)
If deployments in the application need service-managed storage, you can enable OCI PostgreSQL, OCI Cache, or Oracle Autonomous AI Database.
Enable managed storage for hosted deployments associated with this application. Managed storage is created and managed by the service and is accessible only from the hosted deployment associated with this application. Connection details are provided to the container through environment variables.
- OCI PostgreSQL
Enable OCI PostgreSQL to provide a managed database for deployments in this application.
For this option:- Enter the environment variable name that receives the OCI PostgreSQL connection URI. The service adds the connection string to the specified environment variable.
- Storage: Select whether to create storage or use existing storage. If you select existing storage, the application shares the OCI PostgreSQL storage resource with other applications in the tenancy. Each application is assigned a dedicated database, and this application has permission to access only its dedicated database.
- OCI CacheEnable OCI Cache to provide a managed cache for deployments in this application. For this option:
- Enter the environment variable name that receives the OCI Cache connection URI.
- Storage: Select whether to create storage or use existing storage.
- Oracle Autonomous DatabaseEnable Oracle Autonomous AI Database to provide a managed database for deployments in this application. For this option:
- Enter the environment variable name that receives the Autonomous AI Database connection URI.
In addition to the connection string, the service mounts the database user credentials to the following local files in the container:/mnt/secrets/adb/username /mnt/secrets/adb/password
Environment
Networking (Optional)
Select how deployments in this application route outbound traffic, and how clients access the deployment endpoint.
Authentication
Select one of the following authentication methods:
- Identity domain bearer token: Uses an OAuth access token issued by an OCI IAM identity domain. The token is sent to the target service as a bearer token, and the service validates the token before accepting the request. As a prerequisite, perform the tasks in Setting Up Identity Domain Bearer Token Authentication.
- Identity domain browser session: Uses the OAuth 2.1 Authorization Code flow with Proof Key for Code Exchange (PKCE). Browser users are redirected to an OCI identity domain to sign in. The hosted application service obtains an access token on their behalf and establishes a browser session that uses a session cookie.
- OCI IAM: Uses OCI IAM request-signature authentication. Each request is cryptographically signed according to OCI API request-signing requirements.
When using the API, use CreateHostedApplication for either identity domain authentication method. In inboundAuthConfig, set inboundAuthConfigType to one of the following values:
IDCS_AUTH_CONFIG: Identity domain bearer token authentication.IDCS_SESSION_AUTH_CONFIG: Identity domain browser session authentication using the OAuth 2.1 Authorization Code flow with PKCE.
For either type, include idcsConfig with the required domainUrl and scope values. The API schema marks audience as optional. It also defines clientId and clientSecretVaultId as optional fields that apply only to IDCS_SESSION_AUTH_CONFIG. The clientSecretVaultId value is the OCID of an OCI Vault secret containing the OAuth client secret. For details, see InboundAuthConfig and IdcsAuthConfig.
Omitting inboundAuthConfig from an update leaves the application's current authentication configuration unchanged.
To create an application that uses OCI IAM authentication, use CreateHostedApplicationIam with CreateHostedApplicationIamDetails. The OCI IAM API doesn't require an OAuth or IDCS configuration.
Follow the steps for the authentication type that you select. Existing identity domain bearer token and OCI IAM authentication remain supported. After creating an application, you can select Edit on its detail page to change the authentication type.
Identity domain bearer token
Identity domain browser session
Obtain the identity domain URL, scope, audience, and client ID for the OAuth application configured for the Authorization Code flow with PKCE. Store the OAuth client secret in OCI Vault and record the secret's OCID for the Client secret vault ID field.
OCI IAM
Enable Application Logs
Enable resource logging to track application activity, troubleshoot issues, and collect operational insights for hosted deployments.
Review and Create
Review the application settings, then select Create application.
Application creation time depends on the resources that the service provisions for the application.
-
If managed storage is enabled, the service provisions a dedicated storage instance, which might take several minutes.
-
If custom networking is selected, the service provisions the required network bridging resources, which might also take several minutes.
After you create an application, you can view its details and perform other tasks, such as moving it to a different compartment, managing its tags, or deleting it. Use the in the Console to access these tasks. You can also create a deployment for the application from its detail page. For more information, see Listing Applications.