Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
62 changes: 36 additions & 26 deletions oci/SKILL.md
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
---
name: oci
description: Oracle Cloud Infrastructure guidance for designing, operating, and troubleshooting OCI services, including OCI Kubernetes Engine (OKE), OCI Internet of Things Platform, OCI Functions deployment and troubleshooting, and Enterprise AI workflows for OCI Generative AI models, Responses API agents, RAG, cost estimation, governance, private endpoints, hosted agentic applications, and Oracle platform integrations. Use when the user asks about OKE cluster design, Terraform or Resource Manager planning, OKE incident troubleshooting, Generic VNIC Attachment, Multus, pod networking, node pools, add-ons, ingress, load balancers, OCIR image pulls, Workload Identity, Kubernetes workloads on OCI, OCI IoT domains or digital twins, device publish flows, OCI Functions setup, deployment, invocation, or troubleshooting, OCI Generative AI, Enterprise AI Models, Enterprise AI Agents, governed GenAI applications, agentic workflows, RAG on Oracle Cloud, or OCI Generative AI pricing.
description: Oracle Cloud Infrastructure guidance for designing, operating, and troubleshooting OCI services, including OCI Kubernetes Engine (OKE), OCI Internet of Things Platform, OCI Functions deployment and troubleshooting, OCI IAM Terraform configuration, and Enterprise AI workflows for OCI Generative AI models, Responses API agents, RAG, cost estimation, governance, private endpoints, hosted agentic applications, and Oracle platform integrations. Use when the user asks about OKE cluster design, Terraform or Resource Manager planning, OCI compartment hierarchy, classic IAM groups or group membership assignment, dynamic groups, IAM policies, OCI Identity Domains resources, OKE incident troubleshooting, Generic VNIC Attachment, Multus, pod networking, node pools, add-ons, ingress, load balancers, OCIR image pulls, Workload Identity, Kubernetes workloads on OCI, OCI IoT domains or digital twins, device publish flows, OCI Functions setup, deployment, invocation, or troubleshooting, OCI Generative AI, Enterprise AI Models, Enterprise AI Agents, governed GenAI applications, agentic workflows, RAG on Oracle Cloud, or OCI Generative AI pricing.
---

# Oracle Cloud Infrastructure Skills

Use this domain for practical Oracle Cloud Infrastructure guidance. Current content covers OCI Kubernetes Engine (OKE): cluster design, operational troubleshooting, Generic VNIC Attachment (GVA), and Multus multi-interface pod validation. It covers OCI Internet of Things Platform resource discovery, digital twin lifecycle workflows, device publish flows, and optional MCP-assisted operation. It covers OCI Functions local deployment and diagnosis-first troubleshooting. It also covers Enterprise AI because that work is built around OCI Generative AI, OCI networking, IAM, cost estimation, hosted applications, and OCI platform integrations.
Use this domain for practical Oracle Cloud Infrastructure guidance. Current content covers OCI Kubernetes Engine (OKE): cluster design, operational troubleshooting, Generic VNIC Attachment (GVA), and Multus multi-interface pod validation. It covers OCI Internet of Things Platform resource discovery, digital twin lifecycle workflows, device publish flows, and optional MCP-assisted operation. It covers OCI Functions local deployment and diagnosis-first troubleshooting. It includes a constrained Terraform Configuration generator for OCI IAM compartments, groups, dynamic groups, policies, and Identity Domains resources. It also covers Enterprise AI because that work is built around OCI Generative AI, OCI networking, IAM, cost estimation, hosted applications, and OCI platform integrations.

## How to Use This Domain

Expand Down Expand Up @@ -46,6 +46,11 @@ oci/
│ ├── scripts/
│ ├── templates/
│ └── tests/
├── oci-landing-zone-terraform-module/
│ └── terraform-oci-modules-iam-skill/
│ ├── SKILL.md
│ ├── agents/
│ └── references/
└── oke/
├── cluster-design.md
├── troubleshooting.md
Expand All @@ -61,19 +66,20 @@ oci/

## Category Routing

| Topic | Start With |
|-------|------------|
| Design or scaffold an OKE cluster, Terraform stack, or OCI Resource Manager stack | Start with `oci/oke/cluster-design.md`, then load `oci/oke/skills/oke-cluster-generator/SKILL.md` |
| Troubleshoot OKE workloads, pods, services, DNS, add-ons, ingress, load balancers, image pulls, storage, Workload Identity, or cluster access | Start with `oci/oke/troubleshooting.md`, then load `oci/oke/skills/oke-troubleshooter/SKILL.md` |
| Configure OKE managed node pools with Generic VNIC Attachment secondary VNIC profiles and Application Resources | Start with `oci/oke/gva-node-pools.md`, then load `oci/oke/skills/oke-gva-deployer/SKILL.md` |
| Deploy or validate Multus NetworkAttachmentDefinitions and multi-interface pods on OKE | Start with `oci/oke/multus-multihome.md`, then load `oci/oke/skills/oke-multihome-deployer/SKILL.md` |
| Deploy an OCI Function from a local macOS or Linux workstation | `oci/functions/oci-functions-deploy/SKILL.md` |
| Troubleshoot OCI Functions setup, deployment, invocation, or observability | `oci/functions/oci-functions-troubleshoot/SKILL.md` |
| Topic | Start With |
|------------------------------------------------------------------------------------------------------------------------------------------------|------------|
| Design or scaffold an OKE cluster, Terraform stack, or OCI Resource Manager stack | Start with `oci/oke/cluster-design.md`, then load `oci/oke/skills/oke-cluster-generator/SKILL.md` |
| Troubleshoot OKE workloads, pods, services, DNS, add-ons, ingress, load balancers, image pulls, storage, Workload Identity, or cluster access | Start with `oci/oke/troubleshooting.md`, then load `oci/oke/skills/oke-troubleshooter/SKILL.md` |
| Configure OKE managed node pools with Generic VNIC Attachment secondary VNIC profiles and Application Resources | Start with `oci/oke/gva-node-pools.md`, then load `oci/oke/skills/oke-gva-deployer/SKILL.md` |
| Deploy or validate Multus NetworkAttachmentDefinitions and multi-interface pods on OKE | Start with `oci/oke/multus-multihome.md`, then load `oci/oke/skills/oke-multihome-deployer/SKILL.md` |
| Deploy an OCI Function from a local macOS or Linux workstation | `oci/functions/oci-functions-deploy/SKILL.md` |
| Troubleshoot OCI Functions setup, deployment, invocation, or observability | `oci/functions/oci-functions-troubleshoot/SKILL.md` |
| Generate or update Terraform Configuration for OCI IAM compartments, groups, dynamic groups, policies, or Identity Domains | `oci/oci-landing-zone-terraform-module/terraform-oci-modules-iam-skill/SKILL.md` |
| OCI IoT domains, domain groups, digital twin models, adapters, instances, relationships, raw commands, Data API access, or HTTPS publish flows | `oci/iot-platform/SKILL.md` |
| OCI Generative AI models, custom/imported models, endpoints, or private endpoints | `oci/enterprise-ai/SKILL.md` |
| OCI Responses API agents, tools, memory, File Search, Code Interpreter, MCP, or SQL Search | `oci/enterprise-ai/SKILL.md` |
| OCI Generative AI and OCI Generative AI Agents cost estimation | `oci/enterprise-ai/cost/cost-estimation.md` |
| OCI Enterprise AI governance, IAM, API keys, OAuth, guardrails, or ZPR | `oci/enterprise-ai/governance/private-endpoints-and-governance.md` |
| OCI Generative AI models, custom/imported models, endpoints, or private endpoints | `oci/enterprise-ai/SKILL.md` |
| OCI Responses API agents, tools, memory, File Search, Code Interpreter, MCP, or SQL Search | `oci/enterprise-ai/SKILL.md` |
| OCI Generative AI and OCI Generative AI Agents cost estimation | `oci/enterprise-ai/cost/cost-estimation.md` |
| OCI Enterprise AI governance, IAM, API keys, OAuth, guardrails, or ZPR | `oci/enterprise-ai/governance/private-endpoints-and-governance.md` |

## Key Starting Points

Expand All @@ -85,6 +91,7 @@ oci/
- `oci/functions/oci-functions-troubleshoot/SKILL.md`
- `oci/functions/oci-functions-deploy/references/oci-functions-quickstart.md`
- `oci/functions/oci-functions-troubleshoot/references/error-patterns.md`
- `oci/oci-landing-zone-terraform-module/terraform-oci-modules-iam-skill/SKILL.md`
- `oci/iot-platform/SKILL.md`
- `oci/iot-platform/references/cli-workflows.md`
- `oci/iot-platform/references/mcp-optional-use.md`
Expand All @@ -106,23 +113,25 @@ The OKE operational skills include deterministic helper tools under `oci/oke/scr

## Common Multi-Step Flows

| Task | Recommended Sequence |
|------|----------------------|
| Plan a production OKE cluster | `oke/cluster-design.md` |
| Diagnose an OKE service with no load balancer IP | `oke/troubleshooting.md` |
| Task | Recommended Sequence |
|------------------------------------------------------------------|----------------------|
| Plan a production OKE cluster | `oke/cluster-design.md` |
| Diagnose an OKE service with no load balancer IP | `oke/troubleshooting.md` |
| Build a node pool with workload-specific secondary VNIC profiles | `oke/gva-node-pools.md` -> `oke/multus-multihome.md` if pods need multiple interfaces |
| Validate Multus pod networking on GVA-enabled nodes | `oke/multus-multihome.md` -> `oke/troubleshooting.md` if symptoms remain |
| Investigate OKE workload access to OCI APIs | `oke/troubleshooting.md` |
| Deploy a local function | `functions/oci-functions-deploy/SKILL.md` -> preflight -> Fn context validation -> OCIR auth check -> app selection -> scaffold -> deploy |
| Troubleshoot a failed function deploy | `functions/oci-functions-troubleshoot/SKILL.md` -> `functions/oci-functions-troubleshoot/references/error-patterns.md` -> `functions/oci-functions-troubleshoot/references/deploy.md` |
| Troubleshoot function invocation failures | `functions/oci-functions-troubleshoot/SKILL.md` -> `functions/oci-functions-troubleshoot/references/invoke.md` -> logs, traces, metrics, and limits |
| Explore or update OCI IoT digital twin resources | `iot-platform/SKILL.md` -> `iot-platform/references/cli-workflows.md` -> `iot-platform/references/resilience-guidance.md` |
| Publish test telemetry to an OCI IoT twin | `iot-platform/SKILL.md` -> `iot-platform/references/cli-workflows.md` -> `iot-platform/templates/publish-curl.template.sh` |
| Build a governed enterprise assistant | `enterprise-ai/SKILL.md` -> `enterprise-ai/agent-workflows/agent-tools.md` -> `enterprise-ai/data/rag-and-search.md` -> `enterprise-ai/governance/private-endpoints-and-governance.md` |
| Validate Multus pod networking on GVA-enabled nodes | `oke/multus-multihome.md` -> `oke/troubleshooting.md` if symptoms remain |
| Investigate OKE workload access to OCI APIs | `oke/troubleshooting.md` |
| Deploy a local function | `functions/oci-functions-deploy/SKILL.md` -> preflight -> Fn context validation -> OCIR auth check -> app selection -> scaffold -> deploy |
| Troubleshoot a failed function deploy | `functions/oci-functions-troubleshoot/SKILL.md` -> `functions/oci-functions-troubleshoot/references/error-patterns.md` -> `functions/oci-functions-troubleshoot/references/deploy.md` |
| Troubleshoot function invocation failures | `functions/oci-functions-troubleshoot/SKILL.md` -> `functions/oci-functions-troubleshoot/references/invoke.md` -> logs, traces, metrics, and limits |
| Generate OCI IAM Terraform Configuration | `oci-landing-zone-terraform-module/terraform-oci-modules-iam-skill/SKILL.md` -> determine supported module -> collect and validate inputs -> generate `main.tf`, `variables.tf`, and `terraform.tfvars` without running Terraform |
| Explore or update OCI IoT digital twin resources | `iot-platform/SKILL.md` -> `iot-platform/references/cli-workflows.md` -> `iot-platform/references/resilience-guidance.md` |
| Publish test telemetry to an OCI IoT twin | `iot-platform/SKILL.md` -> `iot-platform/references/cli-workflows.md` -> `iot-platform/templates/publish-curl.template.sh` |
| Build a governed enterprise assistant | `enterprise-ai/SKILL.md` -> `enterprise-ai/agent-workflows/agent-tools.md` -> `enterprise-ai/data/rag-and-search.md` -> `enterprise-ai/governance/private-endpoints-and-governance.md` |

## Scope Boundaries

- Keep OCI service, networking, IAM, agent hosting, and cost-estimation guidance in this domain.
- Route OCI IAM Terraform configuration to `oci/oci-landing-zone-terraform-module/terraform-oci-modules-iam-skill/`; it supports only the upstream compartments, groups, dynamic groups, policies, and Identity Domains modules, and does not create standalone classic users or memberships.
- Route OCI IoT domain, digital twin, adapter, device publish, raw command, and Data API workflows to `oci/iot-platform/`.
- Route Oracle Database-owned implementation details to `db/features/`.
- Route APEX artifact generation to `apex/apexlang/`.
Expand All @@ -134,6 +143,7 @@ The OKE operational skills include deterministic helper tools under `oci/oke/scr
- https://docs.oracle.com/en-us/iaas/Content/ContEng/Tasks/contengAttaching_Multiple_VNICs.htm
- https://docs.oracle.com/en-us/iaas/Content/ContEng/Tasks/contenggrantingworkloadaccesstoresources.htm
- https://github.com/oracle-terraform-modules/terraform-oci-oke
- https://github.com/oci-landing-zones/terraform-oci-modules-iam
- https://docs.oracle.com/en-us/iaas/Content/internet-of-things/home.htm
- https://github.com/oracle-samples/oci-iot-samples
- https://docs.oracle.com/en-us/iaas/Content/generative-ai/overview.htm
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,94 @@
Build OCI IAM Terraform Skill
===============================

This skill safely generates or updates Terraform root configuration for OCI IAM
by using only the supported modules from:
https://github.com/oci-landing-zones/terraform-oci-modules-iam

It supports compartment hierarchies, classic IAM groups (including assigning
existing users), dynamic groups, IAM policies, and Identity Domains resources.
It does not create classic IAM users, manage standalone memberships, or manage
Cloud Guard security zones/recipes. For unsupported requests, it reports that
the Terraform module is not supported instead of inventing an alternative.

How this skill works
---------------------

1. Inspects the target Terraform project before making changes.
2. Checks module-support.md to confirm the requested capability has an upstream
submodule.
3. Collects required inputs from the matching input-collection.md section.
4. Ask whether the user wants documented optional parameters, then validate the
completed inputs with validation.md.
5. Uses terraform-sources.md and main-tf-map.md to generate the smallest safe
configuration change.
6. This skill not run or install Terraform. It Hands off terraform init, validate, plan,
and apply for the user to run; Terraform 1.3.0 or later is required and the
plan must be reviewed before applying.


How to use
----------

Unzip this folder and put the /references and SKILL.md in a folder named `build-oci-iam-main-tf`

Load this skill into an agent whenever the use case is to create or update OCI IAM
Terraform using the `oci-landing-zones/terraform-oci-modules-iam` repository.
Typical requests include compartments, IAM groups, dynamic groups, IAM policies,
and Identity Domains resources.

After loading, the agent reads `SKILL.md` first and follows its reference-routing
workflow: confirm support, collect inputs, ask about optional parameters,
validate the values, then generate the smallest safe Terraform change. The agent
must not run or install Terraform, and it must hand off `terraform init`,
`terraform validate`, `terraform plan`, and `terraform apply` for the user to
run. Terraform 1.3.0 or later is required, and the user must review the plan
before applying it.

The skill is additive by default. It preserves existing project layout and does
not modify Terraform state. Updates, moves, removals, recovery, and deletion
requests require the extra lifecycle checks in lifecycle-safety.md.


Reference files
---------------

module-support.md
The upstream support allowlist: exact module directories for compartments,
groups, dynamic-groups, policies, and identity-domains. It also identifies
unsupported capabilities and provides the required rejection wording.

input-collection.md
Module-specific input checklist and structural checks. Its sections cover
compartments, groups, dynamic groups, policies, and Identity Domains. It
distinguishes required data from optional parameters, handles secrets safely,
and requires an optional-input question before validation.

terraform-sources.md
The canonical Git module source format, approved module paths, version-pin
guidance, and integration rules for existing repositories or a new minimal
Terraform workspace.

validation.md
The validation contract: tenancy OCID checks through the OCI MCP interface,
lifecycle state requirements, compartment hierarchy checks, and safe behavior
when validation is missing or fails.

main-tf-map.md
Rules for mapping validated data into main.tf, variables.tf, and
terraform.tfvars. It explains when to extend an existing module versus add a
supported module block, while preserving repository conventions.

lifecycle-safety.md
Additional guardrails for updates, moves, recovery, remove-from-configuration,
and deletes. It covers state ownership, dependencies, compartment deletion
staging, and the required user-facing plan review warning.

Quick reference flow
--------------------

request -> module-support.md -> relevant input-collection.md section +
terraform-sources.md -> validation.md -> main-tf-map.md -> generate safely

For lifecycle changes, read lifecycle-safety.md before collecting inputs and
apply the state checks in validation.md before proposing a configuration change.
Loading