Policies for Block Volume Service

Shows how to allow Disaster Recovery (DR) to manage block storage volumes and volume groups that are part of the application stack.

Policies to configure using resource principal


Allow dynamic-group <Dynamic_group_Name> to manage volume-family in compartment <compartment_name>
Allow dynamic-group <Dynamic_group_Name> read vaults in compartment <compartment_name>
Allow dynamic-group <Dynamic_group_Name> read secret-family in compartment <compartment_name>

Policies to configure using user authentication

Allow group group_name to manage volume-family in compartment compartment_name
Allow group group_name read vaults in compartment <compartment_name>
Allow group group_name read secret-family in compartment <compartment_name>

For more details on Identity and Access Management (IAM) policies for block volume storage, refer Details for the Core Services.