policies
Creates, updates, deletes, gets or lists a policies resource.
Overview​
| Name | policies |
| Type | Resource |
| Id | oci.identity.policies |
Fields​
The following fields are returned by SELECT queries:
- get
- list
The policy was retrieved.
| Name | Datatype | Description |
|---|---|---|
id | string | The OCID of the policy. |
name | string | The name you assign to the policy during creation. The name must be unique across all policies in the tenancy and cannot be changed. |
compartmentId | string | The OCID of the compartment containing the policy (either the tenancy or another compartment). |
definedTags | object | Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}} |
description | string | The description you assign to the policy. Does not have to be unique, and it's changeable. |
freeformTags | object | Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"} |
inactiveStatus | integer (int64) | The detailed status of INACTIVE lifecycleState. |
lifecycleState | string | The policy's current state. After creating a policy, make sure its lifecycleState changes from CREATING to ACTIVE before using it. (CREATING, ACTIVE, INACTIVE, DELETING, DELETED) |
locks | array | Locks associated with this resource. |
statements | array | An array of one or more policy statements written in the policy language. |
timeCreated | string (date-time) | Date and time the policy was created, in the format defined by RFC3339. Example: 2016-08-25T21:10:29.600Z |
versionDate | string (date-time) | The version of the policy. If null or set to an empty string, when a request comes in for authorization, the policy will be evaluated according to the current behavior of the services at that moment. If set to a particular date (YYYY-MM-DD), the policy will be evaluated according to the behavior of the services on that date. |
A document that specifies the type of access a group has to the resources in a compartment. For information about<br />policies and other IAM Service components, see<br />[Overview of IAM](/Content/Identity/getstarted/identity-domains.htm). If you're new to policies, see<br />[Get Started with Policies](/Content/Identity/policiesgs/get-started-with-policies.htm).<br /><br />The word "policy" is used by people in different ways:<br /><br /> * An individual statement written in the policy language<br /> * A collection of statements in a single, named "policy" document (which has an Oracle Cloud ID (OCID) assigned to it)<br /> * The overall body of policies your organization uses to control access to resources<br /><br />To use any of the API operations, you must be authorized in an IAM policy. If you're not authorized,<br />talk to an administrator.<br /><br />Warning: Oracle recommends that you avoid using any confidential information when you supply string values<br />using the API.<br />
| Name | Datatype | Description |
|---|---|---|
id | string | The OCID of the policy. |
name | string | The name you assign to the policy during creation. The name must be unique across all policies in the tenancy and cannot be changed. |
compartmentId | string | The OCID of the compartment containing the policy (either the tenancy or another compartment). |
definedTags | object | Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}} |
description | string | The description you assign to the policy. Does not have to be unique, and it's changeable. |
freeformTags | object | Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"} |
inactiveStatus | integer (int64) | The detailed status of INACTIVE lifecycleState. |
lifecycleState | string | The policy's current state. After creating a policy, make sure its lifecycleState changes from CREATING to ACTIVE before using it. (CREATING, ACTIVE, INACTIVE, DELETING, DELETED) |
locks | array | Locks associated with this resource. |
statements | array | An array of one or more policy statements written in the policy language. |
timeCreated | string (date-time) | Date and time the policy was created, in the format defined by RFC3339. Example: 2016-08-25T21:10:29.600Z |
versionDate | string (date-time) | The version of the policy. If null or set to an empty string, when a request comes in for authorization, the policy will be evaluated according to the current behavior of the services at that moment. If set to a particular date (YYYY-MM-DD), the policy will be evaluated according to the behavior of the services on that date. |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | policyId, region | Gets the specified policy's information. | |
list | select | compartmentId, region | page, limit, name, sortBy, sortOrder, lifecycleState | Lists the policies in the specified compartment (either the tenancy or another of your compartments).<br />See [Where to Get the Tenancy's OCID and User's OCID](/Content/API/Concepts/apisigningkey.htm#five).<br /><br />To determine which policies apply to a particular group or compartment, you must view the individual<br />statements inside all your policies. There isn't a way to automatically obtain that information via the API.<br /> |
create | insert | region, name, compartmentId, statements, description | opc-retry-token | Creates a new policy in the specified compartment (either the tenancy or another of your compartments).<br />If you're new to policies, see [Get Started with Policies](/Content/Identity/policiesgs/get-started-with-policies.htm).<br /><br />You must specify a name for the policy, which must be unique across all policies in your tenancy<br />and cannot be changed.<br /><br />You must also specify a description for the policy (although it can be an empty string). It does not<br />have to be unique, and you can change it anytime with [UpdatePolicy](#/en/identity/20160918/Policy/UpdatePolicy).<br /><br />You must specify one or more policy statements in the statements array. For information about writing<br />policies, see [How Policies Work](/Content/Identity/policieshow/how-policies-work.htm) and<br />[Common Policies](/Content/Identity/policiescommon/commonpolicies.htm).<br /><br />After you send your request, the new object's lifecycleState will temporarily be CREATING. Before using the<br />object, first make sure its lifecycleState has changed to ACTIVE.<br /><br />New policies take effect typically within 10 seconds.<br /> |
update | update | policyId, region | if-match, isLockOverride | Updates the specified policy. You can update the description or the policy statements themselves.<br /><br />Policy changes take effect typically within 10 seconds.<br /> |
delete | delete | policyId, region | if-match, isLockOverride | Deletes the specified policy. The deletion takes effect typically within 10 seconds. |
add_policy_lock | exec | policyId, region, type | if-match, opc-request-id, opc-retry-token | Add a resource lock to a tag namespace.<br /> |
remove_policy_lock | exec | policyId, region, type | if-match, opc-request-id, opc-retry-token | Remove a resource lock to a policy<br /> |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
compartmentId | string | The OCID of the compartment (remember that the tenancy is simply the root compartment). |
policyId | string | The OCID of the policy. |
region | string | OCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION) |
if-match | string | For optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value. |
isLockOverride | boolean | Whether to override locks (if any exist). |
lifecycleState | string | A filter to only return resources that match the given lifecycle state. The state value is case-insensitive. |
limit | integer | The maximum number of items to return in a paginated "List" call. |
name | string | A filter to only return resources that match the given name exactly. |
opc-request-id | string | Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. |
opc-retry-token | string | A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected). |
page | string | The value of the opc-next-page response header from the previous "List" call. |
sortBy | string | The field to sort by. You can provide one sort order (sortOrder). Default order for TIMECREATED is descending. Default order for NAME is ascending. The NAME sort order is case sensitive. Note: In general, some "List" operations (for example, ListInstances) let you optionally filter by Availability Domain if the scope of the resource type is within a single Availability Domain. If you call one of these "List" operations without specifying an Availability Domain, the resources are grouped by Availability Domain, then sorted. |
sortOrder | string | The sort order to use, either ascending (ASC) or descending (DESC). The NAME sort order is case sensitive. |
SELECT examples​
- get
- list
Gets the specified policy's information.
SELECT
id,
name,
compartmentId,
definedTags,
description,
freeformTags,
inactiveStatus,
lifecycleState,
locks,
statements,
timeCreated,
versionDate
FROM oci.identity.policies
WHERE policyId = '{{ policyId }}' -- required
AND region = '{{ region }}' -- required
;
Lists the policies in the specified compartment (either the tenancy or another of your compartments).<br />See [Where to Get the Tenancy's OCID and User's OCID](/Content/API/Concepts/apisigningkey.htm#five).<br /><br />To determine which policies apply to a particular group or compartment, you must view the individual<br />statements inside all your policies. There isn't a way to automatically obtain that information via the API.<br />
SELECT
id,
name,
compartmentId,
definedTags,
description,
freeformTags,
inactiveStatus,
lifecycleState,
locks,
statements,
timeCreated,
versionDate
FROM oci.identity.policies
WHERE compartmentId = '{{ compartmentId }}' -- required
AND region = '{{ region }}' -- required
AND page = '{{ page }}'
AND limit = '{{ limit }}'
AND name = '{{ name }}'
AND sortBy = '{{ sortBy }}'
AND sortOrder = '{{ sortOrder }}'
AND lifecycleState = '{{ lifecycleState }}'
;
INSERT examples​
- create
- Manifest
Creates a new policy in the specified compartment (either the tenancy or another of your compartments).<br />If you're new to policies, see [Get Started with Policies](/Content/Identity/policiesgs/get-started-with-policies.htm).<br /><br />You must specify a name for the policy, which must be unique across all policies in your tenancy<br />and cannot be changed.<br /><br />You must also specify a description for the policy (although it can be an empty string). It does not<br />have to be unique, and you can change it anytime with [UpdatePolicy](#/en/identity/20160918/Policy/UpdatePolicy).<br /><br />You must specify one or more policy statements in the statements array. For information about writing<br />policies, see [How Policies Work](/Content/Identity/policieshow/how-policies-work.htm) and<br />[Common Policies](/Content/Identity/policiescommon/commonpolicies.htm).<br /><br />After you send your request, the new object's lifecycleState will temporarily be CREATING. Before using the<br />object, first make sure its lifecycleState has changed to ACTIVE.<br /><br />New policies take effect typically within 10 seconds.<br />
INSERT INTO oci.identity.policies (
compartmentId,
definedTags,
description,
freeformTags,
locks,
name,
statements,
versionDate,
region,
opc-retry-token
)
SELECT
'{{ compartmentId }}' /* required */,
'{{ definedTags }}',
'{{ description }}' /* required */,
'{{ freeformTags }}',
'{{ locks }}',
'{{ name }}' /* required */,
'{{ statements }}' /* required */,
'{{ versionDate }}',
'{{ region }}',
'{{ opc-retry-token }}'
RETURNING
id,
name,
compartmentId,
definedTags,
description,
freeformTags,
inactiveStatus,
lifecycleState,
locks,
statements,
timeCreated,
versionDate
;
# Description fields are for documentation purposes
- name: policies
props:
- name: region
value: "{{ region }}"
description: Required parameter for the policies resource.
- name: compartmentId
value: "{{ compartmentId }}"
description: |
The OCID of the compartment containing the policy (either the tenancy or another compartment).
- name: definedTags
value: "{{ definedTags }}"
description: |
Defined tags for this resource. Each key is predefined and scoped to a namespace.
For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm).
Example: `{"Operations": {"CostCenter": "42"}}`
- name: description
value: "{{ description }}"
description: |
The description you assign to the policy during creation. Does not have to be unique, and it's changeable.
- name: freeformTags
value: "{{ freeformTags }}"
description: |
Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace.
For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm).
Example: `{"Department": "Finance"}`
- name: locks
description: |
Locks associated with this resource.
value:
- message: "{{ message }}"
relatedResourceId: "{{ relatedResourceId }}"
type: "{{ type }}"
- name: name
value: "{{ name }}"
description: |
The name you assign to the policy during creation. The name must be unique across all policies
in the tenancy and cannot be changed.
- name: statements
value:
- "{{ statements }}"
description: |
An array of policy statements written in the policy language. See
[How Policies Work](/Content/Identity/policieshow/how-policies-work.htm) and
[Common Policies](/Content/Identity/policiescommon/commonpolicies.htm).
- name: versionDate
value: "{{ versionDate }}"
description: |
The version of the policy. If null or set to an empty string, when a request comes in for authorization, the
policy will be evaluated according to the current behavior of the services at that moment. If set to a particular
date (YYYY-MM-DD), the policy will be evaluated according to the behavior of the services on that date.
- name: opc-retry-token
value: "{{ opc-retry-token }}"
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
UPDATE examples​
- update
Updates the specified policy. You can update the description or the policy statements themselves.<br /><br />Policy changes take effect typically within 10 seconds.<br />
UPDATE oci.identity.policies
SET
definedTags = '{{ definedTags }}',
description = '{{ description }}',
freeformTags = '{{ freeformTags }}',
statements = '{{ statements }}',
versionDate = '{{ versionDate }}'
WHERE
policyId = '{{ policyId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match}}'
AND isLockOverride = {{ isLockOverride}}
RETURNING
id,
name,
compartmentId,
definedTags,
description,
freeformTags,
inactiveStatus,
lifecycleState,
locks,
statements,
timeCreated,
versionDate;
DELETE examples​
- delete
Deletes the specified policy. The deletion takes effect typically within 10 seconds.
DELETE FROM oci.identity.policies
WHERE policyId = '{{ policyId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match }}'
AND isLockOverride = '{{ isLockOverride }}'
;
Lifecycle Methods​
- add_policy_lock
- remove_policy_lock
Add a resource lock to a tag namespace.<br />
EXEC oci.identity.policies.add_policy_lock
@policyId='{{ policyId }}' --required,
@region='{{ region }}' --required,
@if-match='{{ if-match }}',
@opc-request-id='{{ opc-request-id }}',
@opc-retry-token='{{ opc-retry-token }}'
@@json=
'{
"message": "{{ message }}",
"relatedResourceId": "{{ relatedResourceId }}",
"type": "{{ type }}"
}'
;
Remove a resource lock to a policy<br />
EXEC oci.identity.policies.remove_policy_lock
@policyId='{{ policyId }}' --required,
@region='{{ region }}' --required,
@if-match='{{ if-match }}',
@opc-request-id='{{ opc-request-id }}',
@opc-retry-token='{{ opc-retry-token }}'
@@json=
'{
"type": "{{ type }}"
}'
;