Cloud Operations for Oracle Cloud Machine ORACLE WHITE PAPER MARCH 2017

Similar documents
Veritas NetBackup and Oracle Cloud Infrastructure Object Storage ORACLE HOW TO GUIDE FEBRUARY 2018

Creating Custom Project Administrator Role to Review Project Performance and Analyze KPI Categories

Oracle CIoud Infrastructure Load Balancing Connectivity with Ravello O R A C L E W H I T E P A P E R M A R C H

Tutorial on How to Publish an OCI Image Listing

Achieving High Availability with Oracle Cloud Infrastructure Ravello Service O R A C L E W H I T E P A P E R J U N E

Generate Invoice and Revenue for Labor Transactions Based on Rates Defined for Project and Task

JD Edwards EnterpriseOne Licensing

Leverage the Oracle Data Integration Platform Inside Azure and Amazon Cloud

April Understanding Federated Single Sign-On (SSO) Process

Deploy VPN IPSec Tunnels on Oracle Cloud Infrastructure. White Paper September 2017 Version 1.0

Oracle Secure Backup. Getting Started. with Cloud Storage Devices O R A C L E W H I T E P A P E R F E B R U A R Y

Migration Best Practices for Oracle Access Manager 10gR3 deployments O R A C L E W H I T E P A P E R M A R C H 2015

An Oracle White Paper November Primavera Unifier Integration Overview: A Web Services Integration Approach

Protecting Your Investment in Java SE

MySQL CLOUD SERVICE. Propel Innovation and Time-to-Market

August 6, Oracle APEX Statement of Direction

ORACLE SERVICES FOR APPLICATION MIGRATIONS TO ORACLE HARDWARE INFRASTRUCTURES

Correction Documents for Poland

Oracle Cloud Infrastructure Virtual Cloud Network Overview and Deployment Guide ORACLE WHITEPAPER JANUARY 2018 VERSION 1.0

Bastion Hosts. Protected Access for Virtual Cloud Networks O R A C L E W H I T E P A P E R F E B R U A R Y

Oracle Data Provider for.net Microsoft.NET Core and Entity Framework Core O R A C L E S T A T E M E N T O F D I R E C T I O N F E B R U A R Y

Establishing secure connectivity between Oracle Ravello and Oracle Cloud Infrastructure Database Cloud ORACLE WHITE PAPER DECEMBER 2017

Migrating VMs from VMware vsphere to Oracle Private Cloud Appliance O R A C L E W H I T E P A P E R O C T O B E R

Oracle Cloud Applications. Oracle Transactional Business Intelligence BI Catalog Folder Management. Release 11+

Oracle WebLogic Server Multitenant:

Load Project Organizations Using HCM Data Loader O R A C L E P P M C L O U D S E R V I C E S S O L U T I O N O V E R V I E W A U G U S T 2018

Repairing the Broken State of Data Protection

Automatic Receipts Reversal Processing

Oracle WebLogic Portal O R A C L E S T A T EM EN T O F D I R E C T IO N F E B R U A R Y 2016

An Oracle White Paper June Enterprise Database Cloud Deployment with Oracle SuperCluster T5-8

October Oracle Application Express Statement of Direction

Oracle Fusion Configurator

Establishing secure connections between Oracle Ravello and Oracle Database Cloud O R A C L E W H I T E P A P E R N O V E M E B E R

Oracle Communications Interactive Session Recorder and Broadsoft Broadworks Interoperability Testing. Technical Application Note

Application Container Cloud

Oracle Java SE Advanced for ISVs

RAC Database on Oracle Ravello Cloud Service O R A C L E W H I T E P A P E R A U G U S T 2017

ORACLE DATABASE LIFECYCLE MANAGEMENT PACK

Oracle Clusterware 18c Technical Overview O R A C L E W H I T E P A P E R F E B R U A R Y

Oracle DIVArchive Storage Plan Manager

Benefits of an Exclusive Multimaster Deployment of Oracle Directory Server Enterprise Edition

Corente Cloud Services Exchange

CONTAINER CLOUD SERVICE. Managing Containers Easily on Oracle Public Cloud

DATA INTEGRATION PLATFORM CLOUD. Experience Powerful Data Integration in the Cloud

Deploying Custom Operating System Images on Oracle Cloud Infrastructure O R A C L E W H I T E P A P E R M A Y

VISUAL APPLICATION CREATION AND PUBLISHING FOR ANYONE

Oracle JD Edwards EnterpriseOne Object Usage Tracking Performance Characterization Using JD Edwards EnterpriseOne Object Usage Tracking

StorageTek ACSLS Manager Software Overview and Frequently Asked Questions

COMPUTE CLOUD SERVICE. Moving to SPARC in the Oracle Cloud

Frequently Asked Questions Oracle Content Management Integration. An Oracle White Paper June 2007

An Oracle White Paper December, 3 rd Oracle Metadata Management v New Features Overview

Oracle Exadata Statement of Direction NOVEMBER 2017

An Oracle White Paper September Security and the Oracle Database Cloud Service

NOSQL DATABASE CLOUD SERVICE. Flexible Data Models. Zero Administration. Automatic Scaling.

Oracle VM 3: IMPLEMENTING ORACLE VM DR USING SITE GUARD O R A C L E W H I T E P A P E R S E P T E M B E R S N

Siebel CRM Applications on Oracle Ravello Cloud Service ORACLE WHITE PAPER AUGUST 2017

An Oracle White Paper October The New Oracle Enterprise Manager Database Control 11g Release 2 Now Managing Oracle Clusterware

Oracle Grid Infrastructure 12c Release 2 Cluster Domains O R A C L E W H I T E P A P E R N O V E M B E R

TABLE OF CONTENTS DOCUMENT HISTORY 3

Oracle Data Masking and Subsetting

Oracle Enterprise Performance Reporting Cloud. What s New in September 2016 Release (16.09)

Configuring Oracle Business Intelligence Enterprise Edition to Support Teradata Database Query Banding

Integrating Oracle SuperCluster Engineered Systems with a Data Center s 1 GbE and 10 GbE Networks Using Oracle Switch ES1-24

Oracle Privileged Account Manager

Loading User Update Requests Using HCM Data Loader

WebCenter Portal Task Flow Customization in 12c O R A C L E W H I T E P A P E R J U N E

Extreme Performance Platform for Real-Time Streaming Analytics

An Oracle White Paper October Release Notes - V Oracle Utilities Application Framework

Subledger Accounting Reporting Journals Reports

Overview. Implementing Fibre Channel SAN Boot with the Oracle ZFS Storage Appliance. January 2014 By Tom Hanvey; update by Peter Brouwer Version: 2.

Oracle Grid Infrastructure Cluster Domains O R A C L E W H I T E P A P E R F E B R U A R Y

Oracle Database Appliance X6-2S / X6-2M ORACLE ENGINEERED SYSTEMS NOW WITHIN REACH FOR EVERY ORGANIZATION

Increasing Network Agility through Intelligent Orchestration

An Oracle White Paper October Minimizing Planned Downtime of SAP Systems with the Virtualization Technologies in Oracle Solaris 10

Differentiate Your Business with Oracle PartnerNetwork. Specialized. Recognized by Oracle. Preferred by Customers.

INTEGRATION CLOUD SERVICE. Accelerate Your Application Integration Across the Cloud and On Premises

How to Monitor Oracle Private Cloud Appliance with Oracle Enterprise Manager 13c O R A C L E W H I T E P A P E R J U L Y

Oracle Service Registry - Oracle Enterprise Gateway Integration Guide

Transitioning from Oracle Directory Server Enterprise Edition to Oracle Unified Directory

Installation Instructions: Oracle XML DB XFILES Demonstration. An Oracle White Paper: November 2011

SOA Cloud Service Automatic Service Migration

August Oracle - GoldenGate Statement of Direction

Oracle JD Edwards EnterpriseOne Object Usage Tracking Performance Characterization Using JD Edwards EnterpriseOne Object Usage Tracking

Oracle NoSQL Database For Time Series Data O R A C L E W H I T E P A P E R D E C E M B E R

TABLE OF CONTENTS DOCUMENT HISTORY 3

Handling Memory Ordering in Multithreaded Applications with Oracle Solaris Studio 12 Update 2: Part 2, Memory Barriers and Memory Fences

Working with Time Zones in Oracle Business Intelligence Publisher ORACLE WHITE PAPER JULY 2014

Oracle Best Practices for Managing Fusion Application: Discovery of Fusion Instance in Enterprise Manager Cloud Control 12c

Oracle Database Security Assessment Tool

Technical Upgrade Guidance SEA->SIA migration

Pricing Cloud: Upgrading to R13 - Manual Price Adjustments from the R11/R12 Price Override Solution O R A C L E W H I T E P A P E R A P R I L

See What's Coming in Oracle CPQ Cloud

Oracle Mobile Application Framework

Oracle Developer Studio 12.6

An Oracle White Paper July Methods for Downgrading from Oracle Database 11g Release 2

Oracle Database Vault

Using the Oracle Business Intelligence Publisher Memory Guard Features. August 2013

Oracle Database Vault

Deploying the Zero Data Loss Recovery Appliance in a Data Guard Configuration ORACLE WHITE PAPER MARCH 2018

Oracle Linux Management with Oracle Enterprise Manager 13c O R A C L E W H I T E P A P E R J U L Y

Transcription:

Cloud Operations for Oracle Cloud Machine ORACLE WHITE PAPER MARCH 2017

Disclaimer The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. The development, release, and timing of any features or functionality described for Oracle s products remains at the sole discretion of Oracle. CLOUD OPERATIONS FOR ORACLE PUBLIC CLOUD MACHINE

Table of Contents Disclaimer 1 Table of Contents 1 Introduction 2 Oracle Cloud Operations Service Overview 2 Oracle Cloud Operations Benefits 2 Services Scope Summary 2 Installation and Configuration Services 3 Cloud Operations and Support Services 4 Cloud Administration as Provided in Oracle Public Cloud 5 Customer Responsibilities 5 Services Delivery 6 Advanced Support 6 Remote Service Delivery 6 Remote Delivery Architecture 6 Security Considerations 8 Conclusion 8 We took a piece of the cloud, out of our cloud, lifted it up, and put it in your data center. LARRY ELLISON EXECUTIVE CHAIRMAN AND CTO ORACLE CORPORATION

Introduction Oracle Public Cloud Machine, also known as Oracle Cloud Machine, delivers Oracle Public Cloud to your data center. Rather than procuring hardware, installing software, and managing the system, you can easily consume cloud services on your premises on a subscription basis, just like you do with the Oracle Public Cloud. Oracle provides the hardware, installs the Oracle Cloud software, and manages the day-to-day operation of the Oracle Cloud Machine infrastructure and Oracle Cloud. It includes a wide range of Oracle Cloud services, from Oracle Compute Cloud to Database Cloud Service, Java Cloud Service and Integration Cloud Service. You can use these cloud services as building blocks to accelerate the development of your innovative applications. This whitepaper outlines the comprehensive cloud management and operation support included in the Oracle Cloud Operations Service as part of your subscription to Oracle Cloud Machine. The "Overview of Oracle Public Cloud Machine Whitepaper" provides additional information about Oracle Cloud Machine and the PaaS cloud services available for on-premises. Oracle Cloud Operations Service Overview Oracle Cloud Operations enables you to accelerate time to deployment, manage the patching and maintenance schedule, minimize upgrade costs with systematic and proactive change management, and keep full control over data and applications that are critical to business, on your own premises. Oracle Cloud Operations is personalized and proactive mission-critical support for organizations seeking to maximize the availability, performance, and value of their Oracle solutions. Oracle Cloud Operations Benefits» Run the same technology as the Oracle Cloud in your datacenter» Operated in your data center for your convenience by Oracle» Turn-key experience that allows you to focus on innovative tasks that add business value» Reduce risk with Oracle Cloud Operations providing best-in-class service levels Services Scope Summary For an easy transition to cloud, Oracle Cloud Operations expertise is delivered in your datacenter -- ranging from system installation, cloud administration, life cycle management, and overall day-to-day operations of the Oracle Cloud Machine infrastructure and Oracle Cloud. You subscribe to the infrastructure and platform services that you need. The service hides all the low-level complexities and provides you with the provisioning of tenant, network, compute, storage, and other fundamental infrastructure resources at the IaaS layer as well as the deployment of application platform using automated self-service provisioning facility at the PaaS layer -- just like Oracle Public Cloud. Oracle Cloud Operations provides you with the capabilities to manage your own tenant domain while putting your focus on core business needs. Figure 1 depicts the delineation of the roles and responsibilities between Oracle Cloud Operations and the customer.

Figure 1: Cloud Operations Roles and Responsibilities The following services are included with Cloud Operations to supply, operate and maintain the Oracle Cloud Machine in your datacenter. Installation and Configuration System installation Oracle Cloud Machine configuration Support and Cloud Operations Upgrade and patching Monitoring Incident management and resolution Oracle Cloud Support Change management Cloud Administration as provided in Oracle Public Cloud Tenant Administration Tenant Administrator Access management Installation and Configuration Services Oracle provides both hardware installation and software configuration, led by an Oracle Technical Account Manager as your single point of contact throughout the duration of the Oracle Cloud Machine subscription period. The hardware installation is performed on-site to prepare and configure the Oracle Cloud Machine at your data center for remote management, monitoring and support. TABLE 1: INSTALLATION AND CONFIGURATION SERVICES FOR ORACLE CLOUD MACHINE Service System Installation Service Summary Comprehensive, standard system hardware installation including site audit, installation and configuration planning documentation, and hardware, network, and operating system functionality validation and testing. The following installations are provided: Oracle Cloud Machine

Oracle Advanced Support Gateway Oracle Cloud Machine Configuration Oracle engineers cover all aspects of the required OS and application networking components configuration. Oracle Cloud Machine configuration Oracle Advanced Support Platform configuration Cloud Operations and Support Services TABLE 2: CLOUD OPERATIONS AND SUPPORT FOR ORACLE CLOUD MACHINE Service Patching Service Summary Oracle Cloud Machine must be updated on a quarterly basis to stay compatible with Oracle Public Cloud. Oracle Cloud Operations will may also need to apply patches out of cycle to correct or prevent critical issues. Patching is performed on the following Oracle Cloud Machine components: Hardware: compute nodes, storage nodes, switches IaaS control plane PaaS engine Each Patch that will impact the availability of the tenants will be coordinated with the primary customer contact. Where possible, Oracle Cloud Operations will provide the customer with as much lead time as possible. When possible, Oracle Cloud Operations will apply patches node by node. PaaS Engine Upgrade Each upgrade includes the on-boarding of additional PaaS Cloud Services and features. The upgrade process does not normally require an interruption to end users, but in the event a downtime of some components is necessary, Oracle Cloud Operations will be coordinated with the primary customer contact to minimize business impact. Monitoring Incident Management and Resolution Backup and Restoration Oracle Cloud Support Change Management Predictive monitoring provides 24x7 proactive system monitoring. These services leverage proprietary Oracle technologies and provide coverage for Oracle Cloud Machine from the network layer to the Cloud Service Infrastructure layer. Monitoring services help ensure uptime and deliver increased service levels via early detection of potential issues. Monitoring of the Oracle Cloud Machine includes System performance System availability Fault monitoring Capacity monitoring Resolution services include proactive monitoring and provide the ITIL-based processes and technological expertise for system administration and incident resolution. A dedicated team of technical experts delivers proactive and preventive maintenance. Incident tickets are used to track and assign priority and severity of all incidents. Key areas covered: Incident management Incident remediation Daily backups of the Oracle Cloud Machine infrastructure will be performed. Oracle Cloud Support covers hardware and software components of the Oracle Cloud Machine. Management of product support Service Requests (SR) includes: Response and resolution of SRs Replacement parts Field dispatch Change management maintains the integrity of the Oracle Cloud Machine environment in a proactive manner by governing the introduction of change. Change management SRs are used to create and maintain an on-going record of all changes. Key areas covered: System capacity

System performance System administration Cloud Administration as Provided in Oracle Public Cloud TABLE 3: CLOUD ADMINISTRATION SERVICES FOR ORACLE CLOUD MACHINE Service Service Summary Tenant Administration Oracle Cloud Operations will create the Tenant based on the template submitted in the change request SR. The Tenant will be built with a single Tenant Administrator identified in the template. Tenant Change Request performed by Oracle Cloud Operations include: Manage quota Manage vnet access Manage service networks Access Management Tenant Administrator User Administration Customer Responsibilities A key part of the successful operation of the Oracle Cloud Machine is the clear understanding and planning of customer responsibilities and requirements, complementing Oracle Cloud Operations. The following is a summary of these customer responsibilities: TABLE 4: CUSTOMER RESPONSIBILITIES FOR ORACLE CLOUD MACHINE Service Pre-Installation Installation and Configuration Support and Cloud Operations Cloud Administration Tenant Administration Service Summary Assign a primary customer contact that will be the single point of contact for Oracle and will help coordinate customer resources, activities, and decisions for a smooth implementation and integration with customer processes and operations. The primary customer contact should have a sufficient leadership position within the customer to be able to provide Oracle singular direction in all matters of implementing and operating the Oracle Cloud Machine. Provide space for the Oracle Cloud Machine and Oracle Advanced Support Platform server Provide and setup network connectivity for the Advanced Support Platform Provide access to a cloud services database on a separate compute environment for use with Integration Cloud Service Identify maintenance windows Provide network access and validation to enable monitoring of the Oracle Cloud Machine Approve routine patching work schedules Configure, monitor, operate, patch, backup, and secure customer's own IaaS VMs and all programs and data running within the IaaS VMs Configure, monitor, operate, patch, backup, and secure customer's own PaaS instances and data Creation of change requests Create and manage tenant users, private networks, IaaS instances, and PaaS instances Monitor customer's own VMs Backup and restore all guest VM environments

Services Delivery Advanced Support Oracle Cloud Machine Cloud Operation Services are delivered remotely using a combination of Advanced Support infrastructure and expertise, using a Remote Delivery Architecture detailed below.» Oracle Advanced Support Cloud Our Global Centers of Excellence leverage codified best practices and automation to provide a wide range of support services via the cloud.» Oracle Advanced Support Platform This software toolset is installed in your environment to enable a secure connection to the cloud and advanced support delivery. Remote Service Delivery Oracle Cloud Operations is enabled through the Oracle Advanced Support Platform (Figure 2), comprised of the Oracle Advanced Support Gateway, the Oracle Advanced Support Portal, and internal components for analysis, reporting, configuration management, and change management. The Oracle Advanced Support Gateway is an essential part of the Oracle delivery architecture for Oracle Cloud Operations. The gateway provides the ability to deliver remote fault monitoring, remote response and restoration, and patch deployment services, as detailed in Figure 3 under 'Remote Delivery Architecture'. Figure 2. Delivery of Oracle Cloud Operations via Advanced Support Platform Cloud operations requests, such as Change Management and Incident Management, are made by submitting Service Request via My Oracle Support (MOS). Remote Delivery Architecture Oracle Advanced Support Platform is based on the IT Infrastructure Library (ITIL) framework. These standards are designed to ensure confidentiality, integrity, and availability of customer data. A strong policy and process framework defines the service delivery with multiple layers of encryption, authorization, access control, and data protection. Procedures are approved and controlled by a high-level Oracle security committee.

Figure 3 and Table 5 provide an overview of the delivery architecture using a secure network connection and protocols. Additional details are provided under Security Considerations. Figure 3. Delivery architecture using a secure network connection TABLE 5: MAIN COMPONENTS OF ORACLE REMOTE DELIVERY Name Function Security Features Oracle Cloud Machine Oracle Cloud Machine and services monitored or analyzed Access via Oracle Advanced Support Platform (Gateway) using secure protocols. Data access limited to telemetry that is essential for service delivery. Firewall Secures data flow between Oracle Advanced Support Platform (Gateway) and Oracle Cloud Machine Oracle Advanced Support Gateway and Oracle Advanced Support Platform Detailed firewall rules and templates are provided to the customer during the implementation process. Oracle Advanced Support Gateway Software appliance for provisioning and delivery of remote Oracle services and tools. Located within the customer s data center on a general-purpose server. Authentication and encryption. Recommended to be placed into a demilitarized zone (DMZ). Oracle Continuous Connection Network Secure connectivity between Oracle and customers. Dedicated private network and separate from Oracle s internal network. Access only by authorized Oracle personnel with two-factor authentication. VPN tunnel / HTTPS Software VPN client within Oracle Advanced Support Gateway to secure and encrypt inbound connections from Oracle to Oracle Advanced Support Gateway. HTTPS for all outbound connections from Oracle Advanced Support Gateway to Oracle. SSL-based VPN client. Encryption. Failover, backup, and disaster recovery functions. Alternatively, IPSecbased connection can be established. HTTPS with 128-bit SSL transport encryption. Oracle Advanced Support Platform Remote service delivery system by Oracle, based on the ITIL framework. Extensive physical and virtual security measures. Multiple layers of encryption, role-based authentication, authorization, and data security. AES- 256 encrypted audit log records are retained for 90 days. Analysis, reporting Monitoring, analysis, and report generation based on defined thresholds and recommended practices. Only authenticated Oracle personnel have system access to deliver the contracted services. Oracle Advanced Support Portal API-based web portal for configuring the database, managing monitoring events, handling changes, and documenting customer requests. Accessible internally by Oracle engineers. All sessions are encrypted. Configuration Management Database (CMDB) Database within Oracle Advanced Support Platform to store customer data required to deliver the services. No direct, outside data access. Data is segregated at a customer level through a multi-tenancy security model. Multiple layers of API-based access and authorization controls.

Security Considerations Security is of the utmost importance when Oracle Cloud Operations accesses the Oracle Advanced Support Gateway for management, monitoring, and patching. Oracle Cloud Operations access can be summarized with two network traffic types (Figure 3): External network traffic originating from Oracle Advanced Support Gateway to Oracle support» Outbound: Remote monitoring (telemetry, configuration, diagnostics) via HTTPS» Inbound: Remote management via SSL VPN requiring two-factor authentication NOTE: ORACLE DOES NOT REQUIRE CUSTOMERS TO OPEN UP ADDITIONAL INBOUND FIREWALL PORTS Internal network traffic between Oracle Advanced Support Gateway and Oracle Cloud Machine» SSL connection between the gateway and the agent hosted within Oracle Cloud Machine» SSH connection from the gateway to Oracle Cloud Machine» SNMP traffic from Oracle Cloud Machine to the gateway for hardware monitoring Oracle follows strict security principles in its approach to keeping IT environments and information secure. More details on security aspects of Oracle Advanced Support Platform are discussed in the Oracle Advanced Support Gateway Security Guide. Conclusion Oracle Cloud Machine solves the challenges of cloud adoption by bringing the benefits of cloud to your organization, to the physical location you specify. and addresses the challenges of cloud adoption. The entire offer, including the hardware, software, and services, is available as a subscription service, like Oracle Public Cloud but on your own premises. The subscription includes hardware, software, and service. Oracle Cloud Operations delivers PaaS and IaaS services at your datacenter in a comprehensive, secure and cost effective manner. This service enables your IT staff to focus on adding value to your core business activities and competitive edge as you will be able to dictate rate of consumption and related cloud services based on your needs and objectives. Additionally, Oracle will ensure that your Oracle Cloud Machine is fully up to date and compatible with Oracle Public Cloud providing choice, agility, application compatibility, and flexibility for your business.

Oracle Corporation, World Headquarters Worldwide Inquiries 500 Oracle Parkway Phone: +1.650.506.7000 Redwood Shores, CA 94065, USA Fax: +1.650.506.7200 CONNECT WITH US blogs.oracle.com/oracle facebook.com/oracle twitter.com/oracle oracle.com Copyright 2017, Oracle and/or its affiliates. All rights reserved. This document is provided for information purposes only, and the contents hereof are subject to change without notice. This document is not warranted to be error-free, nor subject to any other warranties or conditions, whether expressed orally or implied in law, including implied warranties and conditions of merchantability or fitness for a particular purpose. We specifically disclaim any liability with respect to this document, and no contractual obligations are formed either directly or indirectly by this document. This document may not be reproduced or transmitted in any form or by any means, electronic or mechanical, for any purpose, without our prior written permission. Oracle and Java are registered trademarks of Oracle and/or its affiliates. Other names may be trademarks of their respective owners. Intel and Intel Xeon are trademarks or registered trademarks of Intel Corporation. All SPARC trademarks are used under license and are trademarks or registered trademarks of SPARC International, Inc. AMD, Opteron, the AMD logo, and the AMD Opteron logo are trademarks or registered trademarks of Advanced Micro Devices. UNIX is a registered trademark of The Open Group. 0116 ORACLE CLOUD MACHINE CLOUD OPERATION SERVICE March 2017 Author: Brian Couling