STEP 1: LOG IN AND VERIFY
Log in to Cloud Security portal using your credentials :
https://acs-us.clouddefenseai.com/
After logging in, click on sidebar menu and open "Management" -> "Onboard Accounts" -> "Add New Account"
Click on "Oracle Cloud Infrastructure (OCI)"
STEP 2: BASIC INFORMATION
Start with giving it a name. You can give any name for your account. Labels help you to identify the account. Some examples of labels are: US PROD, Dev server, etc.
STEP 3: BUSINESS UNIT
Choose a Business Unit from the dropdown list or create a new business unit.
STEP 4: CHOOSE REGIONS
We will only scan the regions that you choose here. You can choose any specific region or all regions.
After this step, users will be able to onboard with their OCI.
The detailed instruction for OCI onboarding is given below.
OCI ONBOARDING INSTRUCTION FOR DETECTION AND REMEDIATION
USER WILL GET CHOICE LIKE GCP TO SELECT TYPE OF ONBOARDING
CloudDefense.AI supports following OCI onboarding:
Detection and Remediation
Users will select the onboarding type (similar to GCP) and follow the appropriate steps below.
STEP 1: CREATE A USER
Log in to OCI Console.
Navigate to Identity & Security > Users.
Click “Create User.“
Enter:
Name: CDOnboarding@clouddefense.ai
Description: User for CD onboarding
Click “Create Use
Fetch the User OCID
After creation, go to the User Details page
Copy the User OCID
STEP 2: CREATE A GROUP
Go to Identity & Security > Select Domain > Groups.
Click “Create Group.“
Enter the following:
Name: CDOnboardingGroup
Description: Group for CD onboarding users
Click “Create Group.“
STEP 3: ASSIGN THE USER TO THE GROUP
Navigate to Identity & Security > Select Domain > Groups.
Select CDOnboardingGroup.
Click Add User.
Select CDOnboarding@clouddefense.ai and click Add.
STEP 4: CREATE A POLICY (ADMIN ACCESS)
Go to Identity & Security > Policies.
Click “Create Policy“.
Enter the following details:
Name: CDOnboardingUserAdminAccess
Description: Admin access for CDOnboardingGroup
Policy Statements: “Allow group CDOnboardingGroup to manage all-resources in tenancy”
Click “Create“.
STEP 5: GENERATE API KEYS FOR THE USER
Navigate to Identity & Security > Users.
Click CDOnboarding@clouddefense.ai.
Navigate to the API Keys tab.
Click Add API Key.
Choose Generate Key Pair.
Download the Private Key (.pem) file.
Copy the Fingerprint.
STEP 6: FETCH REQUIRED DETAILS
User OCID: From Step 1
Tenant OCID: Go to Identity & Security > Tenancies. Copy the Tenancy OCID.
Home Region: From the Regions dropdown select the Home Region
STEP 7: CREATE A NOTIFICATION TOPIC
Navigate to Application Integration > Notifications > Topics.
Click “Create Topic“.
Enter:
Name: CDOnboardingTopic
Compartment: Select appropriate compartment
Click “Create“.
STEP 8: CREATE A SUBSCRIPTION TO THE WEBHOOK
Go to Notifications > Subscriptions.
Click Create Subscription.
Enter:
Topic: CDOnboardingTopic
Protocol: HTTPS
Endpoint: https://oci-event-handler-314466988480.us-west1.run.app/
Click Create Subscription.
Verify the subscription via the confirmation link sent to the webhook.
FINAL SUMMARY OF REQUIRED DETAILS
User OCID: xxxxxxxx
API Key Fingerprint: xxxxxxxx
Private Key File: oci_api_key.pem
Tenant OCID: xxxxxxxx
Home Region: us-ashburn-1 (example)
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article