An OCI landing zone for Oracle SaaS extensions
The minimum OCI structure we put around Fusion: compartments, network, identity, vault and observability, all in Terraform.
By AMTEX Consulting · Editorial
Extensions around Fusion accumulate: an ATP for staging, a few Functions, an API Gateway for the mobile app, buckets for files. Without structure they end up in the root compartment with policies that allow everything. This is the landing zone we start from.
Compartments
- shared: network, vault, logging
- integration-<env>: OIC, agents, staging ATP
- apps-<env>: API Gateway, Functions, application databases
- security: Cloud Guard targets, audit
Network
One VCN per environment with private subnets for databases and Functions, a public subnet only where API Gateway needs it, service gateway for OCI services and a NAT gateway for egress. OIC reaches on-prem through the connectivity agent in a private subnet.
Identity and secrets
Groups per role, policies per compartment, dynamic groups for Functions and instances. Every credential OIC uses lives in Vault and is referenced, never pasted.
Observability
Logging for every service, a Monitoring dashboard per environment, alarms for OIC errors, Function failures and database CPU, all routed through Notifications to the right team.
- oci
- terraform
- landing-zone