All skills

Use when the user asks to "find OCI skills", "route Oracle Cloud work", "install the OCI skill pack", "review OCI skill ownership", or "separate Oracle skills".

Use this Skill: https://skilld.dev/gh/acedergren/agentic-tools/oci

This session only. Nothing lands on disk.

infrastructure-as-codereferencesoci-terraform-auth-matrix.md

≈944 tokens on demand. Your agent reads this file only when SKILL.md points to it.

OCI Terraform Auth Matrix

Use this reference when Terraform auth is the real problem, especially for 401, 403, NotAuthorizedOrNotFound, or environment-specific failures.

Official Sources

Context Matrix

Execution context Prefer Avoid
Local laptop API key config profile for durable work; SecurityToken profile for short interactive work Committing private keys, OCIDs, or credentials in provider blocks
Cloud Shell Use current Oracle Cloud Shell/provider guidance and short-lived profile behavior Assuming a laptop ~/.oci/config exists unchanged
GitHub Actions or external CI Organization-approved OIDC/federation if configured; otherwise scoped API key secret Long-lived administrator API keys or unscoped tenancy policies
OCI DevOps build pipeline Resource principal/dynamic group policies for the pipeline resource User credentials copied into build specs
OCI Compute instance auth = "InstancePrincipal" plus dynamic group and IAM policy API key files on the instance
OCI Functions or supported service auth = "ResourcePrincipal" plus required resource principal env and policies Instance principal syntax
OKE workload auth = "OKEWorkloadIdentity" when the provider/resource supports it Node instance principal for app workload identity
OCI Resource Manager Provider block normally needs only region; Resource Manager supplies execution context Local API key provider blocks inside Resource Manager configs

Provider Auth Methods

OCI Terraform provider auth methods to check in current docs:

  • APIKey
  • InstancePrincipal
  • ResourcePrincipal
  • SecurityToken
  • OKEWorkloadIdentity

When parameters are set in multiple supported provider locations, Oracle documents precedence among environment variables, non-default OCI config profiles, and the DEFAULT profile. Also inspect explicit provider arguments in HCL because they can lock a configuration to the wrong user, tenancy, region, or auth method.

403 Triage

  1. Identify the caller: user, group, identity-domain group, dynamic group, CI principal, Resource Manager user/job, instance principal, resource principal, or OKE workload identity.
  2. Identify target resource family and compartment.
  3. Check policy location is at or above the target resource compartment.
  4. Check verb is high enough: inspect < read < use < manage.
  5. Check resource family is correct: virtual-network-family, instance-family, volume-family, object-family, orm-family, etc.
  6. Check condition clauses and dynamic-group matching rules.
  7. Allow for IAM propagation lag before rerunning.

Pressure Scenarios

  • "Terraform apply gets 403 creating a VCN": verify caller and manage virtual-network-family scope before changing HCL.
  • "Compute instance Terraform cannot list buckets": use instance principal dynamic-group membership and object-family policy.
  • "Resource Manager cannot create a stack from Git": check orm-config-source-providers, orm-stacks, and source provider permissions.
  • "IDCS group can log in but Terraform fails": map identity-domain/IDCS group membership to the OCI IAM policy subject and compartment scope.

Source: SKILL.md on GitHub

1 warning3mo3 checks · Risk MEDIUM
  • Gen Agent Trust Hub3mo

    An expert-level OCI utility pack that includes advanced scripts for presentation management and database administration. Security concerns include runtime compilation of C shims for system call interception and a powerful SQL script for tenancy-wide security remediation. The skill also ingests untrusted data from document archives and web headers, creating a surface for indirect prompt injection.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: LOW · No issues

Signed by skilld at 1730eda. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 34 minutes ago.

Activeupdated yesterday
version
1.0.0
aliases
[
  "oci-skills",
  "oracle-skills",
  "oci-skill-pack"
]
domains
[
  "oci",
  "oracle",
  "skill-pack"
]
Other metadata
keywords
[
  "OCI",
  "Oracle Cloud",
  "Oracle",
  "skill pack",
  "skill routing",
  "separation of duties",
  "ownership",
  "architecture",
  "operations",
  "manifest"
]

README badge

README badge for acedergren/agentic-tools/oci