专用端点的先决条件

要使用专用端点预配 Oracle Fusion Data Intelligence 实例,必须已创建以下资源:

  1. 您计划在其中部署 Oracle Fusion Data Intelligence 的区域内的虚拟云网络 (VCN) 和 VCN 中的专用子网,其可用性为 /28(14 个 IP 地址)IP 地址或更多。您可以在预配后进行更改。
    为避免实例创建失败,请确保启用了以下选项:

    Oracle Fusion Data Intelligence 需要这些选项才能成功预配实例及其组件。请参阅使用 VCN 和子网

    注意:

    定制 DNS 解析器时,请确保添加了优先级最高的 Oracle Autonomous AI Database DNS 解析器。
  2. 设置安全规则。您必须为入站和出站配置有状态规则。请参见 Stateful Compared to Stateless Rules
    配置安全规则时,请确保以下各项:
    • 源 CIDR :必须为 0.0.0.0/0<VCN CIDR><SUBNET CIDR>
    • IP 协议TCPAll Protocols
    • 源端口范围ALL
    • 目标端口范围ALL,或者特别是 1522443

    注意:

    在为网络安全组或 VCN 输入安全规则信息时,您可以在端口 1522 上为 Oracle Autonomous AI Lakehouse 指定入站和出站流量;在端口 443 上为 Oracle Analytics Cloud 指定入站和出站流量。确保 VCN/SUBNET CIDR 块允许在规则中对端口 443 和 1522 进行入站和出站。具有专用端点的 Oracle Fusion Data Intelligence 实例的功能需要这两个端口。


    后面是 fawag-ingress-rules-pvt-fdi-oak.png 的说明
    插图 fawag-ingress-rules-pvt-fdi-oak.png 的说明


    后面是 fawag-egress-rules-pvt-fdi.png 的说明
    插图 fawag-egress-rules-pvt-fdi.png 的说明

  3. 如果您计划使用网络安全组规则限制流量(入站和出站),则必须在创建 Oracle Fusion Data Intelligence 实例时执行此操作。最多可以指定 5 个网络安全组以满足您的业务需求。确保网络安全组与 Oracle Fusion Data Intelligence 位于同一 VCN 中。
  4. 确保您(或计划创建 Oracle Fusion Data Intelligence 实例的任何人)具有访问 VCN 所需的策略。

    从以下选项中选择最适合您的级别:

    有限资源访问策略

    • Allow any-user to manage network-security-groups in tenancy where request.principal.type = 'fawservice'
    • Allow any-user to use vnics in tenancy where request.principal.type = 'fawservice'
    • Allow any-user to read vcns in tenancy where request.principal.type = 'fawservice'
    • Allow any-user to use private-ips in tenancy where request.principal.type = 'fawservice'
    • Allow any-user to use subnets in tenancy where request.principal.type = 'fawservice'

    如果要从 Oracle Cloud Infrastructure 控制台查看和管理虚拟网络系列,则可能需要创建以下策略:

    • Allow group FAWAdmin.grp to manage network-security-groups <in compartment your-compartment or in tenancy>
    • Allow group FAWAdmin.grp to read virtual-network-family <in compartment your-compartment or in tenancy>
    • Allow group FAWAdmin.grp to manage vnics <in compartment your-compartment or in tenancy>
    • Allow group FAWAdmin.grp to use subnets <in compartment your-compartment or in tenancy>
    • Allow group FAWAdmin.grp to use private-ips <in compartment your-compartment or in tenancy>

    广泛的资源访问策略

    Allow any-user to manage virtual-network-family in tenancy where
          request.principal.type = 'fawservice'
    如果要从 Oracle Cloud Infrastructure 控制台查看和管理虚拟网络系列,则可能需要创建以下策略:
    Allow group FAWAdmin.grp to manage virtual-network-family <in compartment compartment-name or in tenancy>

    除此之外,还必须创建以下一般服务策略:

    • Allow group FAWAdmin.grp to manage analytics-warehouse <in compartment your-compartment or in tenancy>
    • Allow group FAWAdmin.grp to read analytics-warehouse-work-requests <in compartment your-compartment or in tenancy>
    • Allow group FAWAdmin.grp to manage autonomous-database-family <in compartment your-compartment or in tenancy>
    • Allow group FAWAdmin.grp to manage analytics-instances <in compartment your-compartment or in tenancy>
    • Allow group FAWAdmin.grp to read analytics-instance-work-requests <in compartment your-compartment or in tenancy>