first commit
This commit is contained in:
34
README.md
Normal file
34
README.md
Normal file
@@ -0,0 +1,34 @@
|
||||
# PDB Self-Service Portal
|
||||
|
||||
MVP portal for approval-based PDB provisioning on OCI Exadata Database Service on Exascale Infrastructure.
|
||||
|
||||
## Workflow
|
||||
|
||||
1. A developer submits a PDB name, requested `DATA` tablespace size, and initial PDB administrator password.
|
||||
2. The portal encrypts the password before persisting the request and records it as `PENDING`.
|
||||
3. An administrator approves the request.
|
||||
4. The backend invokes OCI `CreatePluggableDatabase` for the configured CDB.
|
||||
5. Once OCI reports the PDB as `AVAILABLE`, the backend connects through JDBC and creates `DATA` at the approved initial size.
|
||||
|
||||
The application never uses SQL*Plus. It uses the OCI Java SDK for PDB provisioning and Oracle JDBC only for the post-provisioning DDL that the OCI PDB API does not expose.
|
||||
|
||||
## Required production configuration
|
||||
|
||||
Set these as deployment secrets, not in source control:
|
||||
|
||||
- `PDB_PORTAL_CDB_OCID`: the Container Database OCID (the `ocid1.database...` value).
|
||||
- `PDB_PORTAL_CDB_ADMIN_PASSWORD`: supplied at runtime by OCI Vault or the deployment secret manager.
|
||||
- `PDB_PORTAL_ENCRYPTION_KEY`: a Base64-encoded 256-bit AES key used to protect the submitted PDB password while approval is pending.
|
||||
- `PDB_PORTAL_JDBC_URL_TEMPLATE`: e.g. `jdbc:oracle:thin:@//scan-host:1521/{pdbName}`.
|
||||
|
||||
When deployed on OCI, grant a dynamic group containing the application runtime permission to manage PDBs in the target compartment. The backend uses a Resource Principal; a personal OCI API key must only be used for local development, never embedded in the portal.
|
||||
|
||||
## Run locally
|
||||
|
||||
Install JDK 21 and Maven, then set the variables above (a non-production local key is acceptable only for development):
|
||||
|
||||
```powershell
|
||||
mvn spring-boot:run
|
||||
```
|
||||
|
||||
Development users are configured in `application.yml`; replace Basic authentication with the company OIDC provider before production.
|
||||
Reference in New Issue
Block a user