Skip to content

Commit db8c38b

Browse files
committed
Initial review
1 parent d240582 commit db8c38b

File tree

11 files changed

+295
-0
lines changed

11 files changed

+295
-0
lines changed
Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
# Exadata Cloud@Customer
2+
3+
Reviewed: 24.06.2024
4+
5+
# Useful Links
6+
7+
- [Main Oracle Product Page](https://www.oracle.com/uk/engineered-systems/exadata/cloud-at-customer/)
8+
9+
- [Oracle Exadata Database Service on Cloud@Customer X10M datasheet](https://www.oracle.com/a/ocom/docs/engineered-systems/exadata/exadb-cc-x10m-ds.pdf)
10+
11+
- [Documentation Home](https://docs.oracle.com/en/engineered-systems/exadata-cloud-at-customer/)
12+
13+
- [What’s New in Oracle Exadata Database Service on Cloud@Customer Gen2](https://docs.oracle.com/en-us/iaas/exadata/doc/ecc-whats-new-in-exadata-cloud-at-customer-gen2.html)
14+
15+
- [What’s New in ADB-D on Exadata Cloud@Customer](https://docs.oracle.com/en-us/iaas/exadata/doc/adb-okv-integration.html)
16+
17+
![Alt text](Specialistdivider1small.jpg?raw=true "Subsections")
18+
19+
- [ExaCC Infra](https://github.com/oracle-devrel/technology-engineering/tree/main/data-platform/exadata-cloud-at-customer/exacc-infra)
20+
21+
- [ExaCC Network](https://github.com/oracle-devrel/technology-engineering/tree/main/data-platform/exadata-cloud-at-customer/exacc-network)
22+
23+
- [ExaCC Security](https://github.com/oracle-devrel/technology-engineering/tree/main/data-platform/exadata-cloud-at-customer/exacc-security)
24+
25+
- [ExaCC Value](https://github.com/oracle-devrel/technology-engineering/tree/main/data-platform/exadata-cloud-at-customer/exacc-value)
26+
27+
# License
28+
29+
Copyright (c) 2024 Oracle and/or its affiliates.
30+
31+
Licensed under the Universal Permissive License (UPL), Version 1.0.
32+
33+
See [LICENSE](https://github.com/oracle-devrel/technology-engineering/blob/main/LICENSE) for more details.
8.93 KB
Loading
Lines changed: 49 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,49 @@
1+
# Exadata Cloud@Customer Infrastructure
2+
3+
Reviewed: 24.06.2024
4+
5+
# Useful Links
6+
7+
- [Main Oracle Product Page](https://www.oracle.com/uk/engineered-systems/exadata/cloud-at-customer/)
8+
9+
- [Oracle Exadata Database Service on Cloud@Customer X10M datasheet](https://www.oracle.com/a/ocom/docs/engineered-systems/exadata/exadb-cc-x10m-ds.pdf)
10+
11+
- [Documentation Home](https://docs.oracle.com/en/engineered-systems/exadata-cloud-at-customer/)
12+
13+
- [Oracle Exadata Configuration Assistant (OECA)](https://www.oracle.com/database/technologies/oeca-download.html)
14+
15+
## Useful Documentation
16+
- [Managing VM Clusters](https://docs.oracle.com/en/engineered-systems/exadata-cloud-at-customer/ecccm/ecc-manage-vm-clusters.html)
17+
18+
- [Creating DB Homes](https://docs.oracle.com/en/engineered-systems/exadata-cloud-at-customer/ecccm/ecc-create-db-homes.html)
19+
20+
- [Managing Oracle Databases](https://docs.oracle.com/en/engineered-systems/exadata-cloud-at-customer/ecccm/ecc-manage-databases.html)
21+
22+
- [Managing Backups Destinations](https://docs.oracle.com/en/engineered-systems/exadata-cloud-at-customer/ecccm/ecc-manage-db-backup-and-recovery.html)
23+
24+
- [Policy details for Exadata Cloud @ Customer](https://docs.oracle.com/en/engineered-systems/exadata-cloud-at-customer/ecccm/ecc-policy-details.html)
25+
26+
- [Using the Dbaascli Utility](https://docs.oracle.com/en/engineered-systems/exadata-cloud-at-customer/ecccm/ecc-using-dbaascli.html)
27+
28+
- [Monitoring and managing storage servers with ExaCLI](https://docs.oracle.com/en/engineered-systems/exadata-cloud-at-customer/ecccm/ecc-using-exacli.html)
29+
30+
- [Rest API](https://docs.oracle.com/en/engineered-systems/exadata-cloud-at-customer/rest.html)
31+
32+
- [Exadata Cloud API/CLI Alignment Matrix (Doc ID 2768569.1)](https://support.oracle.com/epmos/faces/DocumentDisplay?id=2768569.1)
33+
34+
- [Enhanced Infrastructure Maintenance Controls for Oracle Exadata Database Service on Cloud@Customer](https://blogs.oracle.com/database/post/enhanced-infrastructure-maintenance-controls-for-oracle-exadata-database-service-on-cc)
35+
36+
## Snapshot Technologies
37+
[Setting up Oracle Exadata Storage Snapshots](https://docs.oracle.com/en/engineered-systems/exadata-database-machine/sagug/exadata-storage-server-snapshots.html#GUID-3147A414-3657-4B6C-B22E-A5F5869574C2)
38+
39+
[Oracle ACFS Snapshots](https://docs.oracle.com/en/database/oracle/oracle-database/19/ostmg/understand-acfs-concepts.html#GUID-5A3EF695-A795-4FEA-8BE2-AF657BD2238C)
40+
41+
[Oracle ACFS Snapshot Use Cases on Exadata (Doc ID 2761360.1)](https://support.oracle.com/epmos/faces/DocumentDisplay?_afrLoop=274346774362287&id=2761360.1&_afrWindowMode=0&_adf.ctrl-state=jgdocci36_4)
42+
43+
# License
44+
45+
Copyright (c) 2024 Oracle and/or its affiliates.
46+
47+
Licensed under the Universal Permissive License (UPL), Version 1.0.
48+
49+
See [LICENSE](https://github.com/oracle-devrel/technology-engineering/blob/main/LICENSE) for more details.
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
# Exadata Cloud@Customer Single Node VM Cluster
2+
3+
With this enhancement, you can deploy and run multiple single-instance databases in a single-node cluster without RAC licenses being required.
4+
5+
Please note. This functionality should only be used in non-production environments where the customer does not have RAC licenses.
6+
7+
The lack of RAC licenses means that the customer is unable to easily instantiate the DB instance on another DB Server in the ExaDB infrastructure. This means that during maintenance, there will ALWAYS be an outage of the DB service unless the customer moves the service to the DR environment.
8+
9+
Single Node VM Cluster provides ZERO capability for local failover for either planned or unplanned outages.
10+
11+
For customers who do have a RAC license, but want to run Single Node instances, the preferred mechanism is to use clusters, as outlined in the following deck: SIDB on ExaDB
12+
13+
The Single Node VM Cluster implementation is rolled out only to the MTY region. It will be rolled out to other regions in a phased manner
14+
15+
Reviewed: 24.06.2024
16+
17+
# Useful Links
18+
19+
- [About Single-Node VM Cluster](https://docs.oracle.com/en-us/iaas/exadata/doc/ecc-manage-vm-clusters.html#GUID-F528AA9C-2130-4E15-B8DE-DF65FD580789)
20+
21+
- [Using the Console to Create a Single-Node VM Cluster](https://docs.oracle.com/en-us/iaas/exadata/doc/ecc-manage-vm-clusters.html#GUID-6F475E61-176B-481D-92B9-5FD93326C7AA)
22+
23+
- [Using the Console to View Single-Node VM Cluster Details](https://docs.oracle.com/en-us/iaas/exadata/doc/ecc-manage-vm-clusters.html#GUID-CEDD32D1-3309-4ED3-BB28-335348CDE790)
24+
25+
26+
# License
27+
28+
Copyright (c) 2024 Oracle and/or its affiliates.
29+
30+
Licensed under the Universal Permissive License (UPL), Version 1.0.
31+
32+
See [LICENSE](https://github.com/oracle-devrel/technology-engineering/blob/main/LICENSE) for more details.
Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,28 @@
1+
# Exadata Cloud@Customer VM Serial Console Access
2+
3+
Announcing the General Availability (GA) of VM Serial Console Access for Exadata Cloud@Customer. With this new feature, customers can:
4+
5+
- Enable a serial console connection to each individual VM
6+
- Access the virtual serial console via SSH (via proxy and hypervisor)
7+
- Terminate the serial console connection when the required actions have been completed
8+
9+
Reviewed: 24.06.2024
10+
11+
# Key Benefit
12+
13+
This new feature allows customers to access the serial console of their Virtual Machines in case a need arises for emergency debugging. Use cases include accessing GRUB to fix boot issues or accessing the VM when SSH access is unavailable. Typical reasons for this access include accidentally changing or deleting keys, killing or a processes is in a tucked state, and having firewall issues on the VM, among many others.
14+
15+
# Additional Links:
16+
17+
- [What's New announcement in product documentation](https://docs.oracle.com/en/engineered-systems/exadata-cloud-at-customer/ecccm/ecc-whats-new-in-exadata-cloud-at-customer-gen2.html#GUID-303FAF7D-A607-4D3F-95BB-25A477E3F09A)
18+
19+
- Proper OCI user permissions are required to create a serial console connection - see [product documentation](https://docs.oracle.com/en/engineered-systems/exadata-cloud-at-customer/ecccm/ecc-policy-details.html#GUID-CBEEA1B3-8CFC-4E9C-ACA8-6675F4582920) for details
20+
21+
22+
# License
23+
24+
Copyright (c) 2024 Oracle and/or its affiliates.
25+
26+
Licensed under the Universal Permissive License (UPL), Version 1.0.
27+
28+
See [LICENSE](https://github.com/oracle-devrel/technology-engineering/blob/main/LICENSE) for more details.
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
# Exadata Cloud@Customer VM Serial Console History and Cloud Shell Integration
2+
3+
Announcing the General Availability (GA) of Serial Console History and Cloud Shell Integration for Exadata Database Service on Cloud@Customer. These features expand upon the functionality of the serial console access features that we had announced previously. With these new features, customers can easily connect to the serial console of their VMs in order to perform corrective actions and can review/audit previous activities carried out via the serial console by users.
4+
5+
Reviewed: 24.06.2024
6+
7+
# Key Benefits
8+
These features automate certain common administrative tasks related to the usage of the VM serial console for simplicity and convenience, saving precious time and reducing guesswork for our users.
9+
10+
# Console History
11+
Customers can now conveniently audit administrative activities undertaken via the serial console. The console history information is available directly from the OCI console by any tenancy user who has been granted the proper permissions. This will simplify auditing and allow customers to easily comply with internal security audit policies.
12+
13+
# Cloud Shell integration
14+
Cloud Shell integration for the serial console allows users who have been granted proper permissions to easily connect to the VM Serial Console directly from the OCI Cloud Shell. This feature simplifies access and eliminates the need for a user to connect from their local system via SSH to OCI. Some customers have network policies that block such access without granting exceptions. Now, with OCI Cloud Shell integration, customers can easily connect "at-a-click" from the OCI Console without having to work around any networking restrictions manually.
15+
16+
# Additional Links:
17+
18+
[What's New announcement in product documentation](https://docs.oracle.com/en/engineered-systems/exadata-cloud-at-customer/ecccm/ecc-whats-new-in-exadata-cloud-at-customer-gen2.html#GUID-2A3DD1C7-D1D7-4288-A1AA-19334C0516B4)
19+
20+
[Networking Requirements](https://docs.oracle.com/en/engineered-systems/exadata-cloud-at-customer/ecccm/ecc-network-requirements.html#GUID-F06BD75B-E971-48ED-8699-E1004D4B4AC1) in product documentation (especially Table 3-2)
21+
22+
OCI Cloud Shell [product documentation](https://docs.oracle.com/en-us/iaas/Content/API/Concepts/devcloudshellintro.htm)
23+
24+
25+
26+
# License
27+
28+
Copyright (c) 2024 Oracle and/or its affiliates.
29+
30+
Licensed under the Universal Permissive License (UPL), Version 1.0.
31+
32+
See [LICENSE](https://github.com/oracle-devrel/technology-engineering/blob/main/LICENSE) for more details.
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
# Exadata Cloud@Customer Networking
2+
3+
Reviewed: 24.06.2024
4+
5+
# Useful Links
6+
7+
- [Network Requirements for Oracle Exadata Database Service on Cloud@Customer](https://docs.oracle.com/en/engineered-systems/exadata-cloud-at-customer/ecccm/ecc-network-requirements.html#GUID-F06BD75B-E971-48ED-8699-E1004D4B4AC1)
8+
9+
- [Connecting to a Compute Node with SSH](https://docs.oracle.com/en-us/iaas/exadata/doc/eccconnecting.html)
10+
11+
- [Exadata Cloud API/CLI Alignment Matrix (Doc ID 2768569.1)](https://support.oracle.com/epmos/faces/DocumentDisplay?id=2768569.1)
12+
13+
- [Using Data Guard](https://docs.oracle.com/en/engineered-systems/exadata-cloud-at-customer/ecccm/ecc-using-data-guard.html)
14+
15+
# License
16+
17+
Copyright (c) 2024 Oracle and/or its affiliates.
18+
19+
Licensed under the Universal Permissive License (UPL), Version 1.0.
20+
21+
See [LICENSE](https://github.com/oracle-devrel/technology-engineering/blob/main/LICENSE) for more details.
Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,39 @@
1+
# Exadata Cloud@Customer Enabling VPN Tunnel for CPS Connections
2+
3+
A number of customers have expressed a requirement that ALL traffic between the ExaC@C and Oracle be tunneled using IPSec VPN.
4+
5+
While the actual CPS connection uses secure mTLS web socket tunnels, as this does not adhere to the security standards of some customers, it is possible to tunnel these tunnels using standard OCI connectivity methods.
6+
7+
We can use either IPSec Site-to-Site VPN or Fastconnect to establish a permanent secure tunnel between the customer DC and OCI. Then we simply route the CPS traffic via this connection. As far as the ExaC@C CPS servers are concerned, it is simply an IP route it uses to get to the Internet and access the OCI services. It connects and communicates with the OCI Service endpoints in exactly the same way, except that all traffic is routed through the Site-to-site VPN tunnel.
8+
9+
If you want to do this, then you must raise a Technical Exception to ensure that Cloud Ops and Engineering are aware of any special setup required.
10+
11+
The first thing the customer needs to do is create a Private VPN Tunnel between their DC and Oracle. The details of this are here: Site-to-Site VPN Overview
12+
13+
Then the VCN needs to be configured with a Service Gateway, which allows the customer's internal network to access public Oracle services without going out to the internet. This is described here: Access to Oracle Services: Service Gateway
14+
15+
The list of services is here: Service Gateway Supported Cloud Services
16+
17+
You can see that Exadata Cloud@Customer Gen2 is listed.
18+
19+
All the customer has to do is ensure that this config is in place, and then ensure that the CPS network is routed via the customer's CPE for all outgoing traffic.
20+
21+
End result is that ALL traffic to and from the CPS to Oracle is tunneled in the VPN.
22+
23+
Reviewed: 24.06.2024
24+
25+
# Useful Links
26+
27+
- [Overview](https://docs.oracle.com/en-us/iaas/Content/Network/Tasks/overviewIPsec.htm)
28+
29+
- [Steps to create](https://docs.oracle.com/en-us/iaas/Content/Network/Tasks/settingupIPsec.htm)
30+
31+
- [Troubleshooting](https://www.ateam-oracle.com/post/oracle-cloud-vpn-connect-troubleshooting)
32+
33+
# License
34+
35+
Copyright (c) 2024 Oracle and/or its affiliates.
36+
37+
Licensed under the Universal Permissive License (UPL), Version 1.0.
38+
39+
See [LICENSE](https://github.com/oracle-devrel/technology-engineering/blob/main/LICENSE) for more details.
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
# Exadata Cloud@Customer Security
2+
3+
Reviewed: 24.06.2024
4+
5+
# Useful Links
6+
7+
- [Security Documentation](https://docs.oracle.com/en/engineered-systems/exadata-cloud-at-customer/ecccm/ecc-secguide.html)
8+
9+
- [Oracle Gen 2 Exadata Cloud@Customer Security Controls Technical Brief](https://www.oracle.com/a/ocom/docs/engineered-systems/exadata/exadata-cloud-at-customer-security-controls.pdf)
10+
11+
- [Operator Access Control Documentation](https://docs.oracle.com/en/cloud/paas/operator-access-control/exops/overview-of-operator-access-control.html)
12+
13+
- [Operator Access Control Technical Brief](https://www.oracle.com/uk/a/ocom/docs/engineered-systems/exadata/oracle-operator-access-control-tech-brief.pdf)
14+
15+
# License
16+
17+
Copyright (c) 2024 Oracle and/or its affiliates.
18+
19+
Licensed under the Universal Permissive License (UPL), Version 1.0.
20+
21+
See [LICENSE](https://github.com/oracle-devrel/technology-engineering/blob/main/LICENSE) for more details.
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
# Exadata Cloud@Customer Oracle Key Vault (OKV) integration
2+
3+
Oracle Key Vault is a full-stack, security-hardened software appliance built to centralize the management of keys and security objects within the enterprise.
4+
5+
Integrate your on-premises Oracle Key Vault (OKV) with Oracle Exadata Database Service on Cloud@Customer to secure your critical data on-premises. Oracle Key Vault integration enables you to take complete control of your encryption keys and store them securely on an external, centralized key management device.
6+
7+
Reviewed: 24.06.2024
8+
9+
# Useful Links
10+
11+
- [Integrating Exadata Cloud@Customer with OKV](https://docs.oracle.com/en-us/iaas/exadata/doc/adb-manage-keys-on-ext-dev.html#GUID-F231C91C-A36C-4EA8-B36F-7426F97826E3)
12+
13+
- [Customer-Managed Keys in Exadata Database Service on Cloud@Customer](https://docs.oracle.com/en-us/iaas/exadata/doc/manage-encryption-keys-on-external-devices.html#GUID-084AA149-AD28-43D5-AB7A-B5B8980810B2)
14+
15+
# License
16+
17+
Copyright (c) 2024 Oracle and/or its affiliates.
18+
19+
Licensed under the Universal Permissive License (UPL), Version 1.0.
20+
21+
See [LICENSE](https://github.com/oracle-devrel/technology-engineering/blob/main/LICENSE) for more details.

0 commit comments

Comments
 (0)