Identity and Access Management - Compartments Flashcards
A unique feature wihin OCI
Compartment
A fancy name for an account
Tenancy
Logical construct where you can keep all of your cloud resources. (kitchen sink)
Root Compartment
Compartments come in different flavors and are created for isolating and controlling access.
Network / Storage
Best practice
Create dedicated compartments to isolate resources
Each resource that you create belongs to a
single compartment
If you create a vm it goes to Compartment A
It cannot go to Compartment B
To move it to compartment B
You will need delete it from compartment A and recreate it in
To limit access to compartments
write policies that allow limited access in individual compartments.
Do not put all of your resources in
the root compartment.
To create resource-specific compartments
to divide tenancies and put resources accordingly.
Resources in one compartment can interact with resources in
another compartment.
Compartments are global like everything in identity
so resources from multiple regions can be in the same compartment.
Nesting of compartments can be up to “ “ levels deep to mimic your current design or whether its your ID hierarchy
six
Cleaner
You can set quoatas and budgets
In compartments