See below for the requirements to use BYOK with OCI.
User requirements
The user you use to connect to CSP Vault can be new or existing.
User Group requirements
The user group used for BYOK management users can be new or existing.
You must add the selected user to this group.
Compartment requirements
If you plan to use compartments, you must create the appropriate compartments before you connect to the CSP Vault. Create vaults and keys in this compartment or subcompartment.
Access permissions for compartments are controlled at the user group level.
If you are not using compartments, please ensure that your vault, keys, user group, and users are all in the root tenancy.
Policy requirements
The policy grants the user group the appropriate permissions to manage keys and vaults.
- Set the Policy use cases drop-down under Policy Builder to 'Key and Secret Management'.
- The 'Let security admins manage vaults, keys and secrets' policy must be selected.
- Under Identity Domain, select the user group you created for Groups, and the compartment you created for Location.
Vault requirements
The OCI keys reside inside vaults. Create the vault you want to use inside your compartment. The user group that you selected must have permissions to manage this vault.
You can choose to use a virtual private vault. If you do, you must have a storage bucket configured and accessible in the same compartment as the vault.
OCI endpoint access requirements
If your organization restricts outbound access to the public internet, the following endpoints must be whitelisted for OCI BYOK to function correctly:
https://cloud.oracle.comWhitelist the following endpoint individually for each region you want to use.
https://kms.<region>.oraclecloud.comhttps://identity.region>.oci.oraclecloud.comYou must whitelist this endpoint individually for each vault you want to use. You can find the URL on the vault information tile in the OCI console.
https://<vaultid>-management.kms.us-phoenix-1.oraclecloud.comIf a proxy is in use in the network, you can test these endpoints in the Vault application on the Settings > Proxy Settings Vault page.