Oracle Cloud Infrastructure (OCI) provider permissions
List of Oracle Cloud Infrastructure provider permissions for use during Cortex Cloud onboarding to enable continuous monitoring in your cloud environment.
The following reference tables are organized by capability and then the list of the CSP permissions being requested.
Discovery Engine
"Discovery Engine" read only access. Grants read-only access to OCI tenancy and resources.
Agentless Disk Scanning (ADS)
Admit group CortexOutpostGroup of tenancy CortexOutpost to use volumes in tenancy
ADS
In tenancy
Allow creation of backups from volumes
Admit group CortexOutpostGroup of tenancy CortexOutpost to use key-delegate in tenancy
ADS
In tenancy
Re-encrypt backups during copy/restore operations
Admit group CortexOutpostGroup of tenancy CortexOutpost to associate keys in tenancy with volumes in tenancy CortexOutpost
ADS
Volumes in tenancy
Associate encryption keys with volumes during backup/restore
Admit group CortexOutpostGroup of tenancy CortexOutpost to use tag-namespaces in tenancy
ADS
In tenancy
Enable tagging for permission scoping, resource tracking, and cost visibility
Admit group CortexOutpostGroup of tenancy CortexOutpost to manage boot-volume-backups in tenancy where request.operation != 'DeleteBootVolumeBackup'
ADS
Excludes delete
Allow full management of boot volume backups except deletion
Admit group CortexOutpostGroup of tenancy CortexOutpost to manage boot-volume-backups in tenancy where target.resource.tag.cortex_m-o-lcaas_id.panw_capability = 'cortex-scan-platform'
ADS
Only boot-volume-backups tagged with panw_capability = cortex-scan-platform
Restrict deletion to Cortex scan-related resources only
Admit group CortexOutpostGroup of tenancy CortexOutpost to read all-resources in tenancy
ADS
In tenancy
Read-only access to all resources
Registry Scan
Dynamic group permissions
Allow dynamic-group registry-scan to manage buckets in tenancy
Tag-scoped (project_id)
Manage Object Storage buckets for scan artifacts/results
Allow dynamic-group registry-scan to manage objects in tenancy
Tag-scoped (project_id)
Upload/download image layers, manifests, and reports
Allow dynamic-group registry-scan to read secret-bundles in tenancy
Tag-scoped (project_id)
Retrieve registry credentials from OCI Vault
Endorse dynamic-group registry-scan to read repos in any-tenancy
Cross-tenancy
Allow cross-tenancy image pulls for scans
Inherited base permissions for registry scanning
Allow any-user to manage buckets in tenancy
Tag-scoped (project_id)
Create/manage buckets for scan data
Allow any-user to manage objects in tenancy
Tag-scoped (project_id)
Read/write objects (artifacts, logs, results)
Allow any-user to use keys in tenancy
Tag-scoped (project_id)
Decrypt secrets for registry access
Allow any-user to manage secret-versions in tenancy
Tag-scoped (project_id)
Rotate credentials and manage secret versions
Allow any-user to manage secrets in tenancy
Tag-scoped (project_id)
Create/update secrets for scanners
Allow any-user to manage secret-family in tenancy
Tag-scoped (project_id)
Broader secret-management rights
Allow any-user to manage vaults in tenancy
Tag-scoped (project_id)
Create/administer Vaults for key and secret storage
Allow any-user to inspect tag-family in tenancy
Global
Discover tag namespaces/definitions
Allow any-user to use tag-family (namespace=cortex_cloud, managed_by=PANW)
Restricted
Restrict tag usage to Palo Alto-managed groups
Endorse any-group to use tag-namespaces in any-tenancy
Cross-tenancy
Allow tag namespace usage across tenancies
Last updated
Was this helpful?
