專用端點先決條件
若要使用專用端點佈建 Oracle Fusion Data Intelligence 執行處理,您必須已經建立下列資源:
- 您計畫在其中部署 Oracle Fusion Data Intelligence 的區域內的虛擬雲端網路 (VCN),以及 VCN 中的專用子網路 (可用性為 /28 (14 個 IP 位址) 以上的 IP 位址。您可以在啟動設定之後變更此設定。為避免建立執行處理失敗,請確定啟用下列選項:
- 在此 VCN 中使用 DNS 主機名稱選項,同時建立 VCN。
- 建立子網路時,在此子網路中使用 DNS 主機名稱選項。
Oracle Fusion Data Intelligence 需要這些選項,才能順利佈建執行處理及其元件。請參閱使用 VCN 和子網路。
備註:
當您自訂 DNS 解析器時,請務必以最高優先順序新增 Oracle Autonomous AI Database DNS 解析器。 - 設定安全性規則。您必須為傳入和傳出設定狀態性規則。請參閱狀態性與無狀態規則的比較。設定安全規則時,請確定下列項目:
- 來源 CIDR :必須是
0.0.0.0/0、<VCN CIDR>或<SUBNET CIDR>。 - IP 協定:
TCP或All Protocols。 - 來源港口範圍:
ALL - 目的地連接埠範圍:
ALL,或特別是1522和443。
備註:
為 Oracle Autonomous AI Lakehouse 指定連接埠 1522 的輸入和輸出流量,為 Oracle Analytics Cloud 指定連接埠 443,同時輸入網路安全群組或 VCN 的安全規則資訊。確定 VCN/SUBNET CIDR 區塊允許將規則中的傳入和傳出至連接埠 443 和 1522。使用專用端點的 Oracle Fusion Data Intelligence 執行處理必須同時使用這兩個連接埠。
fawag-ingress-rules-pvt-fdi-oak.png 圖解描述
fawag-egress-rules-pvt-fdi.png 圖解描述 - 來源 CIDR :必須是
- 如果您計畫使用網路安全群組規則限制流量 (傳入和傳出),則必須在建立 Oracle Fusion Data Intelligence 執行處理時這麼做。您最多可以指定 5 個網路安全性群組,以符合您的業務需求。請確定網路安全群組與您的 Oracle Fusion Data Intelligence 位於相同的 VCN 中。
- 確保您 (或任何計劃建立 Oracle Fusion Data Intelligence 執行處理的人員) 具備存取 VCN 的必要原則。
從下列選項中選擇最適合您的層次:
限制的資源存取原則
Allow any-user to manage network-security-groups in tenancy where request.principal.type = 'fawservice'-
Allow any-user to use vnics in tenancy where request.principal.type = 'fawservice' -
Allow any-user to read vcns in tenancy where request.principal.type = 'fawservice' -
Allow any-user to use private-ips in tenancy where request.principal.type = 'fawservice' -
Allow any-user to use subnets in tenancy where request.principal.type = 'fawservice'
如果您想要從 Oracle Cloud Infrastructure 主控台檢視及管理您的虛擬網路系列,您可以建立下列原則:
Allow group FAWAdmin.grp to manage network-security-groups <in compartment your-compartment or in tenancy>-
Allow group FAWAdmin.grp to read virtual-network-family <in compartment your-compartment or in tenancy> -
Allow group FAWAdmin.grp to manage vnics <in compartment your-compartment or in tenancy> -
Allow group FAWAdmin.grp to use subnets <in compartment your-compartment or in tenancy> -
Allow group FAWAdmin.grp to use private-ips <in compartment your-compartment or in tenancy>
廣泛的資源存取原則
Allow any-user to manage virtual-network-family in tenancy where request.principal.type = 'fawservice'若要從 Oracle Cloud Infrastructure 主控台檢視及管理您的虛擬網路系列,請建立此原則:Allow group FAWAdmin.grp to manage virtual-network-family <in compartment compartment-name or in tenancy>除此之外,您必須建立下列一般服務原則:
-
Allow group FAWAdmin.grp to manage analytics-warehouse <in compartment your-compartment or in tenancy> -
Allow group FAWAdmin.grp to read analytics-warehouse-work-requests <in compartment your-compartment or in tenancy> -
Allow group FAWAdmin.grp to manage autonomous-database-family <in compartment your-compartment or in tenancy> -
Allow group FAWAdmin.grp to manage analytics-instances <in compartment your-compartment or in tenancy> -
Allow group FAWAdmin.grp to read analytics-instance-work-requests <in compartment your-compartment or in tenancy>



