Skip to content

Commit 9637973

Browse files
authored
Merge pull request #59 from oracle-devrel/ci
[BTPM-272] policy update
2 parents 3579b6e + c22f83e commit 9637973

File tree

4 files changed

+10
-6
lines changed
  • oci-coderepo-examples
  • oci-pipeline-examples/oci-devops-graal-micronaut-deploy-to-instances

4 files changed

+10
-6
lines changed

oci-coderepo-examples/oci-devops-coderepo-with-bitbucketcloud/README.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -69,8 +69,9 @@ ALL {resource.type = 'devopsrepository', resource.compartment.id = 'COMPARMENT O
6969
- Create a policy (Ensure to create it under the ROOT of tenancy) for the dynamic groups with the below policy statement.
7070
7171
```
72-
Allow dynamic-group mr-devops-policy-checker-dg-connection to read secret-family in compartment <compartment name>
73-
Allow dynamic-group mr-devops-policy-checker-dg-connection to use ons-topics in compartment <compartment name>
72+
Allow dynamic-group <NAME OF THE DG> to read secret-family in compartment <compartment name>
73+
Allow dynamic-group <NAME OF THE DG> to use ons-topics in compartment <compartment name>
74+
Allow dynamic-group <NAME OF THE DG> to use devops-connection in compartment <compartment name>
7475
```
7576
7677
- Create a notification topic, that will be used for DevOps - https://docs.oracle.com/en-us/iaas/Content/Notification/Tasks/managingtopicsandsubscriptions.htm#createTopic

oci-coderepo-examples/oci-devops-coderepo-with-github/README.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -78,7 +78,8 @@ ALL {resource.type = 'devopsrepository', resource.compartment.id = 'COMPARMENT O
7878
- Create a policy (Ensure to create it under the **ROOT of tenancy**) for the dynamic groups with below policy statement.
7979
8080
```
81-
Allow dynamic-group mr-devops-policy-checker-dg-connection to read secret-family in compartment <compartment name>
81+
Allow dynamic-group <NAME OF THE DG> to read secret-family in compartment <compartment name>
82+
Allow dynamic-group <NAME OF THE DG> to use devops-connection in compartment <compartment name>
8283

8384
```
8485

oci-coderepo-examples/oci-devops-coderepo-with-gitlab/README.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -74,7 +74,8 @@ ALL {resource.type = 'devopsrepository', resource.compartment.id = 'COMPARMENT O
7474
- Create a policy (Ensure to create it under the ROOT of tenancy) for the dynamic groups with below policy statement.
7575
7676
```
77-
Allow dynamic-group mr-devops-policy-checker-dg-connection to read secret-family in compartment <compartment name>
77+
Allow dynamic-group <NAME OF THE DG> to read secret-family in compartment <compartment name>
78+
Allow dynamic-group <NAME OF THE DG> to use devops-connection in compartment <compartment name>
7879

7980
```
8081

oci-pipeline-examples/oci-devops-graal-micronaut-deploy-to-instances/README.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -59,10 +59,11 @@ All {instance.compartment.id = '<YOUR_COMPARMENT_OCID>'}
5959
```java
6060
Allow dynamic-group <YOUR_DynamicGroup_NAME-1> to read secret-family in compartment <YOUR_COMPARTMENT_NAME>
6161
Allow dynamic-group <YOUR_DynamicGroup_NAME-1> to manage ons-topics in compartment <YOUR_COMPARTMENT_NAME>
62-
Allow dynamic-group <YOUR_DynamicGroup_NAME-2> to use instance-agent-command-execution-family in compartment <YOUR_COMPARTMENT_NAME>
63-
Allow dynamic-group <YOUR_DynamicGroup_NAME-2> to manage objects in compartment <YOUR_COMPARTMENT_NAME>
62+
Allow dynamic-group <YOUR_DynamicGroup_NAME-2> to use instance-agent-command-execution-family in compartment <YOUR_COMPARTMENT_NAME>
6463
Allow dynamic-group <YOUR_DynamicGroup_NAME-2> to manage objects in compartment <YOUR_COMPARTMENT_NAME>
6564
Allow dynamic-group <YOUR_DynamicGroup_NAME-2> to manage all-artifacts in compartment <YOUR_COMPARTMENT_NAME>
65+
Allow dynamic-group <YOUR_DynamicGroup_NAME-1> to read instance-family in compartment <YOUR_COMPARTMENT_NAME>
66+
Allow dynamic-group <YOUR_DynamicGroup_NAME-1> to read vnics in compartment <YOUR_COMPARTMENT_NAME>
6667
```
6768

6869
### Create an artifact repo.

0 commit comments

Comments
 (0)