Zero Trust Packet Routing IAM Policies

Use the Oracle Cloud Infrastructure Identity and Access Management (IAM) service to create policies to control access to the Zero Trust Packet Routing (ZPR) service.

See Details for the Core Services for information on IAM policies for Networking and Compute.

Individual Resource Types

zpr-policy

zpr-security-attribute

Supported Variables

Zero Trust Packet Routing supports all the general variables, plus the ones listed here. For more information about general variables supported by Oracle Cloud Infrastructure services, see Details for Verbs + Resource-Type Combinations.

Variable Variable Type Comments
target.security-attribute-namespace.name String Use this variable to control whether to allow operations against a specific security attribute namespace in response to a request to read, update, delete, or move a security attribute namespace, or to view information related to work requests for a security attribute namespace.
target.security-attribute-namespace.id Entity This variable is supported only in statements granting permissions for the security-attribute-namespaces resource-type.

Details for Verbs + Resource-Type Combinations

The level of access is cumulative as you go from inspect to read to use to manage.

A plus sign (+) in a table cell indicates incremental access when compared to the preceding cell, whereas no extra indicates no incremental access.

For example, the read verb for the zpr-policy resource-type includes the same permissions and API operations as the inspect verb, but also adds the GetZprPolicy API operation. Likewise, the manage verb for the zpr-policy resource-type allows even more permissions when compared to the use permission. For the zpr-policy resource-type, the manage verb includes the same permissions and API operations as the use verb, plus the ZPR_POLICY_CREATE and the ZPR_POLICY_DELETE permissions, and the applicable API operations (CreateZprPolicy and DeleteZprPolicy).

Permissions Required for Each API Operation

The following sections list the Zero Trust Packet Routing API and Security Attribute API operations.

Policy Examples

Use the following examples to learn about Zero Trust Packet Routing IAM policies.

To use the Zero Trust Packet Routing (ZPR) service, users require the following permissions for other Oracle Cloud Infrastructure resources:

  • Read compute instances
  • Read database resources
  • Inspect work requests

To learn more, see Details for the Core Services, including Networking and Compute.