Ensure that resource locking is enabled for production or mission critical Oracle Cloud Infrastructure (OCI) File Storage systems so that non-admin users are not able to delete or modify your file systems in order to help prevent accidental and malicious changes or resource deletion.
In Oracle Cloud Infrastructure (OCI), resource locking enables you to restrict operations on production file systems where modifying or deleting a resource would have a significant negative impact on the entire ecosystem. As an OCI account administrator, it may be necessary to lock an important cloud resource in order to prevent other users within your organization from mistakenly deleting or modifying the resource. A resource lock can have one of the following types:
- "Delete": prevents deletion of the locked resource.
- "Full": prevents update, move, and deletion of the locked resource.
Audit
To determine if your production OCI File Storage systems have resource locking configured, perform the following operations:
Remediation / Resolution
Locks help protect resources against tampering and accidental deletion. To enable resource locking for your production or mission critical Oracle Cloud Infrastructure (OCI) File Storage systems, perform the following operations:
References
- Oracle Cloud Infrastructure Documentation
- Overview of File Storage
- Managing File Systems
- Updating a File System
- Oracle Cloud Infrastructure CLI Documentation
- compartment list
- file-system list
- file-system get
- file-system add