openapi: 3.2.0 info: description:
Oracle Cloud My Services API is an Internet facing service that allows customers to access the Oracle Cloud
title: Oracle Cloud My Services SE Exadata Security Groups Resource API version: v1 x-provenance: method: harvested first_party: true publisher: Oracle source: https://docs.oracle.com/en-us/iaas/api/specs/2fd4343e03912de02e1b6e82eb9fed428530a4191aff1e43fb986fb90c429748.json harvested: '2026-08-04' note: Published by Oracle as the contract for the Oracle Cloud My Services API OCI service and stored verbatim; API Evangelist added only this provenance block. x-evidence: - url: https://docs.oracle.com/en-us/iaas/api/specs/index.json what: Oracle's own index of every OCI service specification - url: https://docs.oracle.com/en-us/iaas/api/specs/2fd4343e03912de02e1b6e82eb9fed428530a4191aff1e43fb986fb90c429748.json what: the harvested document for Oracle Cloud My Services API servers: - url: https://itra.oraclecloud.com/itas tags: - description: Represents a Service Entitlement Service Configuration Exadata SecurityGroups Resource. name: SEExadataSecurityGroupsResource paths: ? /{domain}/myservices/api/v1/serviceEntitlements/{serviceEntitlementId}/serviceConfigurations/{serviceConfigurationId}/securityGroups : get: description: Returns SEExadataSecurityGroup resource collection operationId: resource_MSSEExadataSecurityGroupsResource_get_GET parameters: - description: The identity domain name or the IDCS GUID of the resource in: path name: domain required: true schema: type: string - description: ServiceEntitlementId unique identifier in: path name: serviceEntitlementId required: true schema: type: string - description: ServiceConfigurationId unique identifier in: path name: serviceConfigurationId required: true schema: type: string responses: '200': description: Success headers: {} content: application/json: schema: $ref: '#/components/schemas/json_MSSEExadataSecurityGroups' description: '' default: description: Unexpected error. summary: Returns SEExadataSecurityGroup resource collection. tags: - SEExadataSecurityGroupsResource post: description: "Create a new Security Group
\n\n\n POST /{domain}/myservices/api/{versionId}/serviceEntitlements/{serviceEntitlementId}/serviceConfigurations/{serviceConfigurationId}/securityGroups HTTP/1.1\n\n {\n \"customerId\": \"504078663\",\n \"name\": \"TestGroup2\",\n \"description\": \"HR's first group\",\n \"version\": 1,\n \"rules\": [\n {\n \"direction\": \"ingress\",\n \"proto\": \"tcp\",\n \"startPort\": 30,\n \"endPort\": 31,\n \"ipSubnet\": \"100.100.100.255\",\n \"ruleInterface\": \"admin\"\n },\n {\n \"direction\": \"egress\",\n \"proto\": \"tcp\",\n \"startPort\": 32,\n \"endPort\": 33,\n \"ipSubnet\": \"100.100.255.255\",\n \"ruleInterface\": \"admin\"\n }\n ]\n }\n \n "
operationId: resource_MSSEExadataSecurityGroupsResource_post_POST
parameters:
- description: The identity domain name or the IDCS GUID of the resource
in: path
name: domain
required: true
schema:
type: string
- description: ServiceEntitlementId unique identifier
in: path
name: serviceEntitlementId
required: true
schema:
type: string
- description: ServiceConfigurationId unique identifier
in: path
name: serviceConfigurationId
required: true
schema:
type: string
responses:
'201':
description: Success
headers: {}
content:
application/json:
schema:
description: ''
type: string
format: binary
default:
description: Unexpected error.
summary: .
tags:
- SEExadataSecurityGroupsResource
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/json_MSSEExadataSecurityGroup'
description: ''
components:
schemas:
json_MSSEExadataSecurityGroup:
description: 'MyServices Exadata Security Group. Exadata Cloud Service Self-Service Firewall provides a system of rules and groups. By default, the firewall denies network access to the Exadata Cloud Service instance.
Security groups contains security rules. The security rules effectively define a white-list of allowed network access points.'
properties:
canonicalLink:
description: Canonical Link
type: string
customerId:
description: Customer Id. This must be the same as the {serviceEntitlementId}
type: string
description:
description: Group Description
type: string
id:
description: MSSEExadataSecurityGroup unique identifier
type: string
name:
description: Group Name. A group name.
type: string
rules:
description: Rules defining the white-list of allowed network access points
items:
$ref: '#/components/schemas/json_MSSEExadataSecurityRule'
type: array
version:
description: Version
type: number
title: SEExadataSecurityGroup
type: object
json_MSSEExadataSecurityGroups:
description: MyServices Exadata Security Groups object
properties:
canonicalLink:
description: link to access this SEExadataSecurityGroup list
type: string
hasMore:
description: Set to true if subsequent GETs need to be done to list all SEExadataSecurityGroups
type: boolean
items:
description: List of SEExadataSecurityGroups.
items:
$ref: '#/components/schemas/json_MSSEExadataSecurityGroup'
type: array
limit:
description: Maximum number of SEExadataSecurityGroup returned
type: number
nextLink:
description: Link to next SEExadataSecurityGroup page
type: string
offset:
description: Starting offset of SEExadataSecurityGroups returned
type: number
previousLink:
description: Link to previous SEExadataSecurityGroup page
type: string
title: SEExadataSecurityGroups
type: object
json_MSSEExadataSecurityRule:
description: MyServices Exadata Security Rule. Each rule defines an element in the white-list of allowed network access points
properties:
direction:
description: 'Direction of the network communications that are subject to this rule. Allowed values: [ingress | egress] for inbound (configures the rule to allow network communications to be received from the location specified in the rule) or outbound (configures the rule to allow network communications to be sent to the location specified in the rule).'
type: string
endPort:
description: See startPort.
type: number
ipSubnet:
description: Specifies the IP addresses that are subject to this rule. Specify a single IP address, or specify a range of IP addresses using Classless Inter-Domain Routing (CIDR) notation.
type: string
proto:
description: 'Network Protocol. Allowed values: [tcp | udp].'
type: string
ruleInterface:
description: 'Network interface that is subject to this rule. Allowed values: [admin | client | backup]. admin: The rule applies to network communications over the administration network interface. The administration network is typically used to support administration tasks by using terminal sessions, monitoring agents, and so on. client: The rule applies to network communications over the client access network interface, which is typically used by Oracle Net (database) connections. backup: The rule applies to network communications over the backup network interface, which is typically used to transport backup information to and from network-based storage that is separate from Exadata Cloud Service.'
type: string
startPort:
description: startPort and endPort define the range of ports to open/white-list [0 - 65535]. startPort <= endPort and startPort == endPort to open only 1 port.
type: number
title: SEExadataSecurityRule
type: object