For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex Cloud Runtime

Oracle Cloud Infrastructure (OCI) provider permissions

List of Oracle Cloud Infrastructure provider permissions for use during Cortex Cloud onboarding to enable continuous monitoring in your cloud environment.

The following reference tables are organized by capability and then the list of the CSP permissions being requested.

Discovery Engine

"Discovery Engine" read only access. Grants read-only access to OCI tenancy and resources.

Agentless Disk Scanning (ADS)

Permission
Module
Scope
Purpose

Admit group CortexOutpostGroup of tenancy CortexOutpost to use volumes in tenancy

ADS

In tenancy

Allow creation of backups from volumes

Admit group CortexOutpostGroup of tenancy CortexOutpost to use key-delegate in tenancy

ADS

In tenancy

Re-encrypt backups during copy/restore operations

Admit group CortexOutpostGroup of tenancy CortexOutpost to associate keys in tenancy with volumes in tenancy CortexOutpost

ADS

Volumes in tenancy

Associate encryption keys with volumes during backup/restore

Admit group CortexOutpostGroup of tenancy CortexOutpost to use tag-namespaces in tenancy

ADS

In tenancy

Enable tagging for permission scoping, resource tracking, and cost visibility

Admit group CortexOutpostGroup of tenancy CortexOutpost to manage boot-volume-backups in tenancy where request.operation != 'DeleteBootVolumeBackup'

ADS

Excludes delete

Allow full management of boot volume backups except deletion

Admit group CortexOutpostGroup of tenancy CortexOutpost to manage boot-volume-backups in tenancy where target.resource.tag.cortex_m-o-lcaas_id.panw_capability = 'cortex-scan-platform'

ADS

Only boot-volume-backups tagged with panw_capability = cortex-scan-platform

Restrict deletion to Cortex scan-related resources only

Admit group CortexOutpostGroup of tenancy CortexOutpost to read all-resources in tenancy

ADS

In tenancy

Read-only access to all resources

Registry Scan

Dynamic group permissions

Permission
Scope
Purpose

Allow dynamic-group registry-scan to manage buckets in tenancy

Tag-scoped (project_id)

Manage Object Storage buckets for scan artifacts/results

Allow dynamic-group registry-scan to manage objects in tenancy

Tag-scoped (project_id)

Upload/download image layers, manifests, and reports

Allow dynamic-group registry-scan to read secret-bundles in tenancy

Tag-scoped (project_id)

Retrieve registry credentials from OCI Vault

Endorse dynamic-group registry-scan to read repos in any-tenancy

Cross-tenancy

Allow cross-tenancy image pulls for scans

Inherited base permissions for registry scanning

Permission
Scope
Purpose

Allow any-user to manage buckets in tenancy

Tag-scoped (project_id)

Create/manage buckets for scan data

Allow any-user to manage objects in tenancy

Tag-scoped (project_id)

Read/write objects (artifacts, logs, results)

Allow any-user to use keys in tenancy

Tag-scoped (project_id)

Decrypt secrets for registry access

Allow any-user to manage secret-versions in tenancy

Tag-scoped (project_id)

Rotate credentials and manage secret versions

Allow any-user to manage secrets in tenancy

Tag-scoped (project_id)

Create/update secrets for scanners

Allow any-user to manage secret-family in tenancy

Tag-scoped (project_id)

Broader secret-management rights

Allow any-user to manage vaults in tenancy

Tag-scoped (project_id)

Create/administer Vaults for key and secret storage

Allow any-user to inspect tag-family in tenancy

Global

Discover tag namespaces/definitions

Allow any-user to use tag-family (namespace=cortex_cloud, managed_by=PANW)

Restricted

Restrict tag usage to Palo Alto-managed groups

Endorse any-group to use tag-namespaces in any-tenancy

Cross-tenancy

Allow tag namespace usage across tenancies

Last updated

Was this helpful?