- ODBネットワークの作成
- ODBネットワークの変更
- ODBネットワークの削除
- ODBピアリング接続の作成
- ODBピアリング接続の変更
- ODBピアリング接続の削除
|
AWS |
ネットワーキング管理者 |
AWS IAM: {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "OdbNetworkOperations",
"Effect": "Allow",
"Action": [
"odb:GetOciOnboardingStatus",
"odb:CreateOdbNetwork",
"odb:GetOdbNetwork",
"odb:ListOdbNetworks",
"odb:UpdateOdbNetwork",
"odb:DeleteOdbNetwork",
"odb:TagResource",
"odb:UntagResource",
"odb:ListTagsForResource",
"odb:GetResourcePolicy",
"odb:PutResourcePolicy",
"odb:DeleteResourcePolicy",
"odb:CreateOdbPeeringConnection",
"odb:DeleteOdbPeeringConnection",
"odb:GetOdbPeeringConnection",
"odb:ListOdbPeeringConnections",
"ec2:DescribeVpcs",
"ec2:DescribeAvailabilityZones",
"ec2:CreateOdbNetworkPeering",
"ec2:DeleteOdbNetworkPeering",
"ec2:ModifyOdbNetworkPeering",
"ec2:DescribeVpcEndpointAssociations",
"ec2:CreateVpcEndpoint",
"ec2:DeleteVpcEndpoints",
"ec2:DescribeVpcEndpoints",
"ec2:CreateTags",
"ec2:CreatePlacementGroup",
"ec2:DeletePlacementGroup",
"ec2:AttachResourcesToPlacementGroup",
"ec2:DetachResourcesFromPlacementGroup",
"vpc-lattice:CreateServiceNetwork",
"vpc-lattice:CreateServiceNetworkResourceAssociation",
"vpc-lattice:GetServiceNetwork",
"vpc-lattice:DeleteServiceNetwork",
"vpc-lattice:DeleteServiceNetworkResourceAssociation",
"vpc-lattice:GetServiceNetworkResourceAssociation",
"vpc-lattice:CreateResourceGateway",
"vpc-lattice:DeleteResourceGateway",
"vpc-lattice:GetResourceGateway",
"vpc-lattice:CreateServiceNetworkVpcEndpointAssociation",
"vpc-lattice:GetServiceNetworkResourceAssociation"
],
"Resource": "*"
},
{
"Sid": "AllowSLRActions",
"Effect": "Allow",
"Action": [
"iam:CreateServiceLinkedRole"
],
"Resource": "*",
"Condition": {
"StringEquals": {
"iam:AWSServiceName": [
"odb.amazonaws.com",
"vpc-lattice.amazonaws.com"
]
}
}
}
]
}
|
- Exadataインフラストラクチャの作成
- Exadataインフラストラクチャの変更
- Exadataインフラストラクチャの削除
|
AWS |
インフラストラクチャ管理者 |
AWS IAM: {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "ExaInfraOperations",
"Action": [
"odb:GetOciOnboardingStatus",
"odb:CreateCloudExadataInfrastructure",
"odb:ListDbSystemshapes",
"odb:ListDbServers",
"odb:GetCloudExadataInfrastructure",
"odb:ListCloudExadataInfrastructures",
"odb:DeleteCloudExadataInfrastructure",
"odb:ListCloudVmClusters",
"odb:TagResource",
"odb:UntagResource",
"odb:ListTagsForResource",
"ec2:DescribeAvailabilityZones",
"iam:CreateServiceLinkedRole",
"odb:UpdateCloudExadataInfrastructure",
"odb:GetDbServer"
],
"Effect": "Allow",
"Resource": "*"
}
]
}
|
|
|
AWS |
インフラストラクチャ管理者 |
所有者/信頼できるアカウント権限(組織を確認するため): {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "OrganizationPermissions",
"Effect": "Allow",
"Action": "organizations:DescribeOrganization",
"Resource": "*"
}
]
}
所有者アカウント権限(リソース共有を作成するには): {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "RamPermissions",
"Effect": "Allow",
"Action": [
"odb:ListCloudExadataInfrastructures",
"odb:ListOdbNetworks",
"odb:PutResourcePolicy",
"odb:GetResourcePolicy",
"odb:DeleteResourcePolicy",
"ram:CreateResourceShare",
"ram:AssociateResourceShare",
"ram:DisassociateResourceShare",
"ram:UpdateResourceShare",
"ram:DeleteResourceShare",
"ram:TagResource",
"ram:UntagResource",
"ram:GetResourceShares",
"ram:GetResourceShareAssociations",
"ram:GetResourceShareInvitations",
"ram:GetResourcePolicies",
"ram:EnableSharingWithAwsOrganization",
"ram:ListResources",
"ram:ListPrincipals",
"ram:ListResourceTypes",
"ram:ListPermissionAssociations",
"ram:AssociateResourceSharePermission",
"ram:GetPermission",
"ram:ListPermissions",
"ram:DisassociateResourceSharePermission",
"ram:ListResourceSharePermissions",
"ram:ListPermissionVersions",
"ram:ListPendingInvitationResources",
"ram:ListReplacePermissionAssociationsWork"
],
"Resource": "*"
}
]
}
信頼できるアカウント権限(リソース・アクセス・マネージャ(RAM)ポータルから共有リソースを表示し、Oracle AI Database@AWSからアカウントをアクティブ化): {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Sid": "RamPermissionsTrustedAccount",
"Action": [
"ram:GetResourceShares",
"ram:GetResourcePolicies",
"ram:ListResources",
"ram:ListResourceSharePermissions",
"ram:ListPrincipals",
"ram:GetResourceShareInvitations",
"odb:InitializeService",
"iam:CreateServiceLinkedRole",
"odb:GetOciOnboardingStatus"
],
"Resource": "*"
}
]
}
ノート:
- AWS RAMのフル・アクセスの管理対象ポリシーについては、AWS RAMのAWS管理ポリシーを参照してください
- 信頼できるアカウントからODBネットワーク、Exadataインフラストラクチャ、Exadata VMクラスタおよびAutonomous VMクラスタを管理するには、このページにリストされている各アクションについて、信頼できるアカウントからの権限の完全なリストへのアクセス権を付与する必要があります。
|
- Exadata VMクラスタの作成
- Exadata VMクラスタの変更
- Exadata VMクラスタの削除
|
AWS |
インフラストラクチャ管理者およびデータベース管理者 |
AWS IAM: {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "ExaVMClusterOperations",
"Action": [
"odb:GetOciOnboardingStatus",
"odb:CreateCloudVmCluster",
"odb:GetCloudVmCluster",
"odb:ListCloudVmClusters",
"odb:DeleteCloudVmCluster",
"odb:ListCloudExadataInfrastructures",
"odb:ListSystemVersions",
"odb:ListGiVersions",
"odb:ListDbServers",
"odb:ListDbSystemshapes",
"odb:ListDbNodes",
"odb:ListOdbNetworks",
"odb:TagResource",
"odb:UntagResource",
"odb:ListTagsForResource",
"iam:CreateServiceLinkedRole",
"odb:GetDbNode",
"odb:StartDbNode",
"odb:StopDbNode",
"odb:RebootDbNode",
"odb:CreateDbNode",
"odb:DeleteDbNode"
],
"Effect": "Allow",
"Resource": "*"
}
]
}
|
- Exadata Database (CDBおよびPDB)の作成
- Exadata Database (CDBおよびPDB)の変更
- Exadata Database (CDBおよびPDB)の削除
|
OCI |
データベース管理者 |
OCI IAM: ユーザーがOCIテナンシ管理者でない場合は、次のものの一部である必要があります:
- 次の事前作成済グループ:
aws-db-family-administrators
aws-exa-cdb-administrators
aws-exa-pdb-administrators
- 次のポリシー・ステートメントを持つその他のグループ:
Allow group <group-name> to manage db-homes in compartment id <MulticloudLink_AWS_timestamp_ocid>
Allow group <group-name> to manage databases in compartment id <MulticloudLink_AWS_timestamp_ocid>
Allow group <group-name> to manage pluggable-databases in compartment id <MulticloudLink_AWS_timestamp_ocid>
Allow group <group-name> to manage db-family in compartment id <MulticloudLink_AWS_timestamp_ocid>
|
- Autonomous VMクラスタの作成
- Autonomous VMクラスタの変更
- Autonomous VMクラスタの削除
|
AWS |
インフラストラクチャ管理者およびデータベース管理者 |
AWS:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "AutonomousVMClusterOperations",
"Action": [
"odb:ListAutonomousVirtualMachines",
"odb:CreateCloudAutonomousVmCluster",
"odb:DeleteCloudAutonomousVmCluster",
"odb:GetCloudAutonomousVmCluster",
"odb:ListCloudAutonomousVmClusters",
"odb:GetCloudExadataInfrastructureUnallocatedResources",
"odb:GetOciOnboardingStatus",
"odb:ListCloudExadataInfrastructures",
"odb:ListDbServers",
"odb:TagResource",
"odb:UntagResource",
"odb:ListTagsForResource"
],
"Effect": "Allow",
"Resource": "*"
}
]
}
|
- Autonomous AI Databaseの作成(サーバーレス)
- Autonomous AI Databaseの変更(サーバーレス)
- Autonomous AI Databaseの削除(サーバーレス)
|
AWS |
インフラストラクチャ管理者およびデータベース管理者 |
AWS IAM:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "AutonomousDatabaseOperations",
"Effect": "Allow",
"Action": [
"odb:CreateAutonomousDatabase",
"odb:GetAutonomousDatabase",
"odb:UpdateAutonomousDatabase",
"odb:DeleteAutonomousDatabase",
"odb:ListAutonomousDatabases",
"odb:StartAutonomousDatabase",
"odb:StopAutonomousDatabase",
"odb:RebootAutonomousDatabase",
"odb:ShrinkAutonomousDatabase",
"odb:RestoreAutonomousDatabase",
"odb:SwitchoverAutonomousDatabase",
"odb:FailoverAutonomousDatabase",
"odb:ListAutonomousDatabaseClones",
"odb:ListAutonomousDatabasePeers",
"odb:CreateAutonomousDatabaseWallet",
"odb:GetAutonomousDatabaseWalletDetails",
"odb:CreateAutonomousDatabaseBackup",
"odb:GetAutonomousDatabaseBackup",
"odb:UpdateAutonomousDatabaseBackup",
"odb:DeleteAutonomousDatabaseBackup",
"odb:ListAutonomousDatabaseBackups",
"odb:ListAutonomousDatabaseVersions",
"odb:ListAutonomousDatabaseCharacterSets",
"odb:TagResource",
"odb:UntagResource",
"odb:ListTagsForResource"
],
"Resource": "*"
},
{
"Sid": "UpdateEncryptionKey",
"Effect": "Allow",
"Action": [
"iam:PassRole",
"kms:DescribeKey",
"vpc-lattice:GetServiceNetworkResourceAssociation"
],
"Resource": "*"
}
]
}
|
- Autonomous AI Databaseの作成(専用)
- Autonomous AI Databaseの変更(専用)
- Autonomous AI Databaseの削除(専用)
|
OCI |
データベース管理者 |
OCI IAM: ユーザーがOCIテナンシ管理者でない場合は、次のものの一部である必要があります:
- 次の事前作成済グループ:
aws-autonomous-cdb-administrators
- 次のポリシー・ステートメントを持つその他のグループ:
Allow group <group-name> to manage autonomous-databases in compartment id <MulticloudLink_AWS_timestamp_ocid>
Allow group <group-name> to manage autonomous-backups in compartment id <MulticloudLink_AWS_timestamp_ocid>
Allow group <group-name> to manage autonomous-container-databases in compartment id <MulticloudLink_AWS_timestamp_ocid>
|