first commit
This commit is contained in:
34
README.md
Normal file
34
README.md
Normal file
@@ -0,0 +1,34 @@
|
|||||||
|
# PDB Self-Service Portal
|
||||||
|
|
||||||
|
MVP portal for approval-based PDB provisioning on OCI Exadata Database Service on Exascale Infrastructure.
|
||||||
|
|
||||||
|
## Workflow
|
||||||
|
|
||||||
|
1. A developer submits a PDB name, requested `DATA` tablespace size, and initial PDB administrator password.
|
||||||
|
2. The portal encrypts the password before persisting the request and records it as `PENDING`.
|
||||||
|
3. An administrator approves the request.
|
||||||
|
4. The backend invokes OCI `CreatePluggableDatabase` for the configured CDB.
|
||||||
|
5. Once OCI reports the PDB as `AVAILABLE`, the backend connects through JDBC and creates `DATA` at the approved initial size.
|
||||||
|
|
||||||
|
The application never uses SQL*Plus. It uses the OCI Java SDK for PDB provisioning and Oracle JDBC only for the post-provisioning DDL that the OCI PDB API does not expose.
|
||||||
|
|
||||||
|
## Required production configuration
|
||||||
|
|
||||||
|
Set these as deployment secrets, not in source control:
|
||||||
|
|
||||||
|
- `PDB_PORTAL_CDB_OCID`: the Container Database OCID (the `ocid1.database...` value).
|
||||||
|
- `PDB_PORTAL_CDB_ADMIN_PASSWORD`: supplied at runtime by OCI Vault or the deployment secret manager.
|
||||||
|
- `PDB_PORTAL_ENCRYPTION_KEY`: a Base64-encoded 256-bit AES key used to protect the submitted PDB password while approval is pending.
|
||||||
|
- `PDB_PORTAL_JDBC_URL_TEMPLATE`: e.g. `jdbc:oracle:thin:@//scan-host:1521/{pdbName}`.
|
||||||
|
|
||||||
|
When deployed on OCI, grant a dynamic group containing the application runtime permission to manage PDBs in the target compartment. The backend uses a Resource Principal; a personal OCI API key must only be used for local development, never embedded in the portal.
|
||||||
|
|
||||||
|
## Run locally
|
||||||
|
|
||||||
|
Install JDK 21 and Maven, then set the variables above (a non-production local key is acceptable only for development):
|
||||||
|
|
||||||
|
```powershell
|
||||||
|
mvn spring-boot:run
|
||||||
|
```
|
||||||
|
|
||||||
|
Development users are configured in `application.yml`; replace Basic authentication with the company OIDC provider before production.
|
||||||
Reference in New Issue
Block a user