All skills

Use when the user asks to "find OCI skills", "route Oracle Cloud work", "install the OCI skill pack", "review OCI skill ownership", or "separate Oracle skills".

Use this Skill: https://skilld.dev/gh/acedergren/agentic-tools/oci

This session only. Nothing lands on disk.

infrastructure-as-codereferencesoci-terraform-bastion.md

≈640 tokens on demand. Your agent reads this file only when SKILL.md points to it.

OCI Terraform Bastion Automation

Use this reference when Terraform manages OCI Bastion resources, sessions, allowlists, IAM, or private-access guardrails.

Official Sources

Behavioral Rules

  • Prefer OCI Bastion or private connectivity over public SSH for private instance access.
  • Treat client CIDR allowlists as sensitive operational controls. Avoid permanent 0.0.0.0/0.
  • Do not store private keys in Terraform state. Use external key generation and controlled distribution.
  • Use Managed SSH only when the target supports Oracle Cloud Agent and Bastion plugin requirements.
  • Use port forwarding for unsupported targets, database listeners, RDP, ADB private endpoints, or Managed SSH plugin gaps.
  • Treat sessions as ephemeral access objects; clean them up unless the operating model explicitly keeps them.

Terraform Review Checklist

  • Does the plan create or widen a client CIDR allowlist?
  • Does the plan create public IPs or public SSH rules as a shortcut?
  • Are session TTLs within Oracle's current 30-to-180-minute bounds?
  • Are target-side NSGs/security lists scoped to the bastion path and target port?
  • Are IAM policies scoped to bastion/session operations and target resource needs?
  • Are SSH public keys inputs and private keys kept out of state?
  • Does the target image/shape require port forwarding instead of Managed SSH?

Allowlist Safety

For Terraform-managed allowlists, do not make ad hoc Console changes without reconciling state. For emergency access, prefer a short-lived, reviewed variable change with cleanup, or use CLI/Console with an explicit post-incident import/state reconciliation step.

Pressure Scenario

"Terraform should create a Bastion for private instance access."

Passing answer: create OCI Bastion with narrow allowlists, target-side network rules, scoped IAM, no public SSH fallback, no private keys in state, and explicit session cleanup behavior.

Source: SKILL.md on GitHub

1 warning3mo3 checks · Risk MEDIUM
  • Gen Agent Trust Hub3mo

    An expert-level OCI utility pack that includes advanced scripts for presentation management and database administration. Security concerns include runtime compilation of C shims for system call interception and a powerful SQL script for tenancy-wide security remediation. The skill also ingests untrusted data from document archives and web headers, creating a surface for indirect prompt injection.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: LOW · No issues

Signed by skilld at 1730eda. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 hours ago.

Activeupdated yesterday
version
1.0.0
aliases
[
  "oci-skills",
  "oracle-skills",
  "oci-skill-pack"
]
domains
[
  "oci",
  "oracle",
  "skill-pack"
]
Other metadata
keywords
[
  "OCI",
  "Oracle Cloud",
  "Oracle",
  "skill pack",
  "skill routing",
  "separation of duties",
  "ownership",
  "architecture",
  "operations",
  "manifest"
]

README badge

README badge for acedergren/agentic-tools/oci