All skills

Use when the user asks to "find OCI skills", "route Oracle Cloud work", "install the OCI skill pack", "review OCI skill ownership", or "separate Oracle skills".

Use this Skill: https://skilld.dev/gh/acedergren/agentic-tools/oci

This session only. Nothing lands on disk.

landing-zonesreferencessecurity-zone-automation.md

≈774 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Security Zone Automation Runbook

Use this playbook when rolling out Security Zones, recipes, and monitoring at scale across compartments/environments. All commands assume OCI CLI.

1. Define Security Policies (Recipe)

RECIPE_NAME="CIS-Prod-Recipe"
OCI_REGION="us-ashburn-1"

oci cloud-guard security-policy-collection list-security-policies --all \
  --query 'data[].{"name":"display-name","id":"id"}' --output table

# capture policy OCIDs you want to enforce
# Example filters for specific display names
POLICY_IDS_JSON=$(oci cloud-guard security-policy-collection list-security-policies --all \
  --query 'data[?"display-name"==`deny-public-ip` || "display-name"==`deny-public-bucket` || "display-name"==`require-encryption`].id')

oci cloud-guard security-recipe create \
  --compartment-id "$TENANCY_OCID" \
  --display-name "$RECIPE_NAME" \
  --security-policies "$POLICY_IDS_JSON"

RECIPE_ID=$(oci cloud-guard security-recipe-collection list-security-recipes --compartment-id "$TENANCY_OCID" \
  --display-name "$RECIPE_NAME" --query 'data[0].id' --raw-output)

2. Apply Recipe to Compartments

for COMPARTMENT in $(jq -r '.compartments[].id' compartments.json); do
  oci cloud-guard security-zone create \
    --compartment-id "$COMPARTMENT" \
    --display-name "$(oci iam compartment get --compartment-id "$COMPARTMENT" --query 'data."name"' --raw-output)-SZ" \
    --security-zone-recipe-id "$RECIPE_ID" \
    --wait-for-state ACTIVE
done

Tip: Generate compartments.json via oci iam compartment list --all --compartment-id $TENANCY_OCID and filter by tag (e.g., Environment=Prod).

3. Automate with Terraform

resource "oci_cloud_guard_security_zone" "prod" {
  compartment_id         = oci_identity_compartment.prod.id
  display_name           = "${var.compartment_name}-security-zone"
  security_zone_recipe_id = oci_cloud_guard_security_zone_recipe.prod.id
}

data "oci_cloud_guard_security_policies" "all" {
  compartment_id = var.tenancy_ocid
}

locals {
  required_policy_names = ["deny-public-ip", "deny-public-bucket", "require-cmk-encryption"]
}

resource "oci_cloud_guard_security_zone_recipe" "prod" {
  compartment_id   = var.tenancy_ocid
  display_name     = "CIS-Prod"
  security_policies = [
    for policy in data.oci_cloud_guard_security_policies.all.security_policies : policy.id
    if contains(local.required_policy_names, policy.display_name)
  ]
}

Apply after any manual change so state remains accurate.

4. Verification Commands

oci cloud-guard security-zone get --security-zone-id $ZONE_ID --query 'data."lifecycle-state"'
oci cloud-guard security-zone-collection list-security-zones --compartment-id $TENANCY_OCID --all --output table
oci cloud-guard problem list --compartment-id $TENANCY_OCID --problem-category SECURITY_ZONE \
  --compartment-id-in-subtree true --access-level ACCESSIBLE --all --output table

Alert SRE if any compartment shows new SECURITY_ZONE problems after remediation.

5. Rollback / Removal

oci cloud-guard security-zone delete --security-zone-id $ZONE_ID --force
oci cloud-guard security-recipe delete --security-recipe-id $RECIPE_ID --force

Only remove zones with compliance approval. Document reason in incident ticket.

Source: SKILL.md on GitHub

1 warning3mo3 checks · Risk MEDIUM
  • Gen Agent Trust Hub3mo

    An expert-level OCI utility pack that includes advanced scripts for presentation management and database administration. Security concerns include runtime compilation of C shims for system call interception and a powerful SQL script for tenancy-wide security remediation. The skill also ingests untrusted data from document archives and web headers, creating a surface for indirect prompt injection.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: LOW · No issues

Signed by skilld at d0e87b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 4 months ago
version
1.0.0
aliases
[
  "oci-skills",
  "oracle-skills",
  "oci-skill-pack"
]
domains
[
  "oci",
  "oracle",
  "skill-pack"
]
Other metadata
keywords
[
  "OCI",
  "Oracle Cloud",
  "Oracle",
  "skill pack",
  "skill routing",
  "separation of duties",
  "ownership",
  "architecture",
  "operations",
  "manifest"
]

README badge

README badge for acedergren/agentic-tools/oci