You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Implemented [JCS-13348] - Use RMS private endpoint in lieu of bastion
host
Tested following scenarios
New vcn/bastion - provisioning and scale out
Existing vcn/new subnets - provisioning and scale out
Existing vcn/existing subnets/new rms endpoint - provisioning and
scaleout
Existing vcn/existing subnets/existing rms endpoint - provisioning and
scale out
Existing vcn/existing subnets/both rms and bastion enabled -
provisioning and scale out
Existing vcn/existing subnets/ bastion and rms enabled - provisioning
and scale out
Existing vcn/existing subnets/ bastion and rms disabled - provisioning
and scale out
cli changes
Tested cli with bastion
Updated the builds for srg changes
Tested auto scaling with rms endpoint
async_prov_mode=!local.assign_weblogic_public_ip&&!var.is_bastion_instance_required?"Asynchronous provisioning is enabled. Connect to each compute instance and confirm that the file /u01/data/domains/${format("%s_domain", local.service_name_prefix)}/provCompletedMarker exists. Details are found in the file /u01/logs/provisioning.log.":""
107
+
async_prov_mode=!local.assign_weblogic_public_ip&&!var.is_rms_private_endpoint_required&&!var.is_bastion_instance_required?"Asynchronous provisioning is enabled. Connect to each compute instance and confirm that the file /u01/data/domains/${format("%s_domain", local.service_name_prefix)}/provCompletedMarker exists. Details are found in the file /u01/logs/provisioning.log.":""
Copy file name to clipboardExpand all lines: terraform/modules/policies/locals.tf
+2-2Lines changed: 2 additions & 2 deletions
Original file line number
Diff line number
Diff line change
@@ -35,7 +35,6 @@ locals {
35
35
apm_domain_policy_statement=var.use_apm_service?"Allow dynamic-group ${oci_identity_dynamic_group.wlsc_instance_principal_group.name} to use apm-domains in compartment id ${var.apm_domain_compartment_id}":""
36
36
# This policy with "use load_balancer" verb is needed to create load balancer for new vcn
37
37
lb_policy_statement=var.add_load_balancer?length(oci_identity_dynamic_group.wlsc_instance_principal_group) >0?"Allow dynamic-group ${oci_identity_dynamic_group.wlsc_instance_principal_group.name} to use load-balancers in compartment id ${var.network_compartment_id}":"":""
autoscaling_statement25=var.use_autoscaling?length(oci_identity_dynamic_group.wlsc_functions_principal_group) >0?"Allow dynamic-group ${oci_identity_dynamic_group.wlsc_functions_principal_group[0].name} to inspect dynamic-groups in tenancy":"":""
77
76
autoscaling_statement26=var.use_autoscaling?length(oci_identity_dynamic_group.wlsc_functions_principal_group) >0?"Allow dynamic-group ${oci_identity_dynamic_group.wlsc_functions_principal_group[0].name} to manage policies in tenancy":"":""
78
77
autoscaling_statement27=var.use_autoscaling?length(oci_identity_dynamic_group.wlsc_functions_principal_group) >0?"Allow dynamic-group ${oci_identity_dynamic_group.wlsc_functions_principal_group[0].name} to use tag-namespaces in tenancy":"":""
78
+
autoscaling_statement28=var.use_autoscaling?length(oci_identity_dynamic_group.wlsc_functions_principal_group) >0?"Allow dynamic-group ${oci_identity_dynamic_group.wlsc_functions_principal_group[0].name} to manage orm-family in compartment id ${var.network_compartment_id}":"":""
79
79
autoscaling_atp_policy_statement=(var.atp_db.is_atp&& var.use_autoscaling) ?length(oci_identity_dynamic_group.wlsc_functions_principal_group) >0?"Allow dynamic-group ${oci_identity_dynamic_group.wlsc_functions_principal_group[0].name} to inspect autonomous-transaction-processing-family in compartment id ${var.atp_db.compartment_id}":"":""
80
80
autoscaling_db_policy_statement=(local.is_oci_db&& var.use_autoscaling) ?length(oci_identity_dynamic_group.wlsc_functions_principal_group) >0?"Allow dynamic-group ${oci_identity_dynamic_group.wlsc_functions_principal_group[0].name} to inspect database-family in compartment id ${var.oci_db.compartment_id}":"":""
81
81
autoscaling_fss_mount_target_policy_statement=(var.add_fss&& var.use_autoscaling) ?length(oci_identity_dynamic_group.wlsc_functions_principal_group) >0?"Allow dynamic-group ${oci_identity_dynamic_group.wlsc_functions_principal_group[0].name} to manage mount-targets in compartment id ${var.mount_target_compartment_id}":"":""
0 commit comments