All skills

Use when the user asks to "find OCI skills", "route Oracle Cloud work", "install the OCI skill pack", "review OCI skill ownership", or "separate Oracle skills".

Use this Skill: https://skilld.dev/gh/acedergren/agentic-tools/oci

This session only. Nothing lands on disk.

networking-managementreferencesoci-networking-reference.md

≈796 tokens on demand. Your agent reads this file only when SKILL.md points to it.

OCI Networking Reference

Last verified: 2026-09-30 against docs.oracle.com and OCI CLI 3.94.1. Limits and prices change; re-check the linked pages before quoting.

Verified facts

Topic Fact
Subnet reserved IPs 3 per subnet: the first two and the last address of the CIDR
VCN CIDR size /16 to /30 per CIDR block; CIDRs can be added or modified later with restrictions
Security lists Max 5 per subnet; rules are stateful by default, stateless is opt-in per rule
NSGs A VNIC can belong to at most 5 NSGs; NSG rules can reference another NSG as source/destination
Load balancer IPs Public LB uses 2 private IPs; private LB uses 3 (primary, standby, floating). One regional subnet is recommended
Service Gateway Targets the "All <region> Services in Oracle Services Network" or "OCI <region> Object Storage" CIDR label; reaches Oracle public endpoints without an internet gateway
Peering LPG/RPC peering is not transitive; transit routing uses DRG route tables and import distributions
Pricing (price list, 2026-09-30) No charge SKUs exist for NAT gateway, DRG, or Site-to-Site VPN; FastConnect billed per port-hour (1 Gbps $0.2125, SKU B88325) with no data charges on private virtual circuits; first 10 TB/month outbound data free in most regions

Connectivity debug checklist

A packet must be allowed by every layer. Check in this order and record which layer fails:

  1. Route table of the source subnet has a rule for the destination (IGW, NAT, SGW, DRG, LPG, private IP).
  2. Security lists on both subnets (ingress on the destination, egress on the source; stateless rules need both directions).
  3. NSGs on both VNICs.
  4. ZPR policy, if the resource has security attributes (see ../zpr-security).
  5. OS firewall on the instance (firewalld/iptables on Oracle Linux images is on by default).
  6. DNS: VCN resolver, private views, and on-prem forwarding rules.

Useful commands:

oci network route-table get --rt-id "$RT_ID"
oci network security-list get --security-list-id "$SL_ID"
oci network nsg rules list --nsg-id "$NSG_ID" --all
oci network service list --all          # Service Gateway CIDR labels
oci network drg-route-table list --drg-id "$DRG_ID" --all

Network Path Analyzer (console: Networking > Network Command Center) can evaluate a path end to end.

Official Oracle Sources

Source: SKILL.md on GitHub

1 warning3mo3 checks · Risk MEDIUM
  • Gen Agent Trust Hub3mo

    An expert-level OCI utility pack that includes advanced scripts for presentation management and database administration. Security concerns include runtime compilation of C shims for system call interception and a powerful SQL script for tenancy-wide security remediation. The skill also ingests untrusted data from document archives and web headers, creating a surface for indirect prompt injection.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: LOW · No issues

Signed by skilld at 1730eda. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 33 minutes ago.

Activeupdated yesterday
version
1.0.0
aliases
[
  "oci-skills",
  "oracle-skills",
  "oci-skill-pack"
]
domains
[
  "oci",
  "oracle",
  "skill-pack"
]
Other metadata
keywords
[
  "OCI",
  "Oracle Cloud",
  "Oracle",
  "skill pack",
  "skill routing",
  "separation of duties",
  "ownership",
  "architecture",
  "operations",
  "manifest"
]

README badge

README badge for acedergren/agentic-tools/oci