- Support
- Integrations
- Bastion
Bastion
Oracle Cloud integration · 10 node(s).
00Overview
Create and manage Oracle Cloud bastions and open managed SSH sessions straight from a flow — stand up a bastion against a private subnet, tighten its client-IP allow-list and session limits, then broker time-limited SSH access to hosts that have no public endpoint. List, fetch, update and move bastions between compartments, and open, list, fetch and tear down sessions as your automation needs them. Because every create, update and delete is asynchronous, a flow can start the work and poll each resource until it is ready.
Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.
01Connecting Bastion
- The node's Authentication dropdown offers two methods. Connect Oracle Cloud (recommended) uses a managed connection, so no private signing key ever lives in your flow; API signing key (advanced) lets you paste an existing OCI signing key by hand.
- For Connect Oracle Cloud, open your Flomation environment's connections, add an Oracle Cloud connection and give it a name, then follow the guided setup to connect Flomation to your tenancy — once it is connected, pick it in the node's Oracle Cloud connection field.
- For API signing key (advanced) instead, open your user's profile in the OCI Console and choose API Keys → Add API Key, then fill the node's Tenancy OCID, User OCID, Region (e.g.
uk-london-1) and Key Fingerprint from the key you added. - Provide the Compartment OCID that holds (or will hold) your bastion, copied from the OCI Console under Compartments — every bastion and session action needs it in its Compartment OCID field.
- On the advanced path, store the signing key's PEM as a Flomation environment secret (e.g.
bastion_secret) and select it in the node's Private Key (PEM) field; add a Private Key Passphrase secret only if the key is encrypted.
| Field | Type | Details | |
|---|---|---|---|
| Authentication | string | Connect Oracle Cloud, API signing key (advanced) | |
| Oracle Cloud connection | credential | Pick a connected Oracle Cloud account | |
| Region | string | e.g. uk-london-1 | |
| Private Key (PEM) | secret | The API signing private key — full PEM, incl. BEGIN/END lines | |
| Private Key Passphrase | secret | Only if the key is encrypted (optional) | |
| Tenancy OCID | string | ocid1.tenancy.oc1..aaaa… | |
| User OCID | string | ocid1.user.oc1..aaaa… | |
| Key Fingerprint | string | aa:bb:cc:… fingerprint of the uploaded API key |
Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.
02Bastion
OCI Bastion: Change Bastion Compartment
oracle/bastion/bastion_change_compartment · Action
Move a bastion into a different compartment — the bastion keeps its OCID, only its compartment placement changes.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Bastion OCID | string | Required | ocid1.bastion.oc1..aaaa… (the bastion to move) |
| Destination Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (where to move the bastion) |
Returns: tool_result, id, destination_compartment_id, opc_request_id, success, error
OCI Bastion: Create Bastion
oracle/bastion/bastion_create · Action
Create a standard bastion in a target subnet. Optionally set a name, a client CIDR allow-list and a maximum session TTL. Returns a work-request id — poll Get Bastion until ACTIVE.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Target Subnet OCID | string | Required | ocid1.subnet.oc1..aaaa… (private subnet the bastion connects to) |
| Name | string | A name for the bastion, fixed after creation (optional) | |
| Max Session TTL (seconds) | string | Longest a session may stay active, e.g. 10800 (optional) | |
| Client CIDR Allow-list | string | Comma-separated CIDRs allowed to connect, e.g. 10.0.0.0/24,203.0.113.5/32 (optional) |
Returns: tool_result, bastion, id, lifecycle_state, work_request_id, success, error
OCI Bastion: Delete Bastion
oracle/bastion/bastion_delete · Action
Delete an OCI Bastion by its OCID — returns a work-request OCID to poll for completion.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Bastion OCID | string | Required | ocid1.bastion.oc1..aaaa… of the bastion to delete |
Returns: tool_result, id, work_request_id, success, error
OCI Bastion: Get Bastion
oracle/bastion/bastion_get · Action
Fetch a single OCI Bastion by its OCID — its type, target network, session limits and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Bastion OCID | string | Required | ocid1.bastion.oc1..aaaa… |
Returns: tool_result, bastion, id, lifecycle_state, success, error
OCI Bastion: List Bastions
oracle/bastion/bastion_list · Action
List the bastions in a compartment. Optionally filter by lifecycle state, exact name, or a specific bastion OCID. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Lifecycle State | string | Only bastions in this state (optional) — choices: Creating, Updating, Active, Deleting, Deleted, Failed | |
| Name Filter | string | Only the bastion whose name matches this exactly (optional) | |
| Bastion OCID Filter | string | Restrict to a specific bastion OCID (optional) |
Returns: tool_result, bastions, count, truncated, success, error
OCI Bastion: Update Bastion
oracle/bastion/bastion_update · Action
Partially update a bastion — change only the maximum session time-to-live or the client CIDR allow-list you supply; blank fields are left unchanged. Returns a work-request id to poll.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Bastion OCID | string | Required | ocid1.bastion.oc1..aaaa… — the bastion to update |
| Max Session TTL (seconds) | string | New maximum session lifetime, e.g. 10800 (leave blank to keep unchanged) | |
| Client CIDR Allow-list | text | Comma- or newline-separated CIDR ranges, e.g. 10.0.0.0/16 (leave blank to keep unchanged) |
Returns: tool_result, id, work_request_id, success, error
03Session
OCI Bastion: Create Session
oracle/bastion/session_create · Action
Open a managed SSH bastion session to a target host on a private subnet. Returns the session in a CREATING state plus a work-request id — poll Get Session until ACTIVE, then connect with the matching private key.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Bastion OCID | string | Required | ocid1.bastion.oc1..aaaa… the bastion to create the session on |
| Target Resource OCID | string | Required | ocid1.instance.oc1..aaaa… the host to connect to |
| Target OS Username | string | Required | e.g. opc — the OS user the session logs in as |
| SSH Public Key | text | Required | The OpenSSH public key (ssh-rsa AAAA…) whose private key you will connect with |
| Target Resource Port | string | Port to connect to on the target (optional, default 22) | |
| Display Name | string | A name for the session (optional) | |
| Session TTL (seconds) | string | How long the session stays active (optional) |
Returns: tool_result, session, id, lifecycle_state, work_request_id, success, error
OCI Bastion: Delete Session
oracle/bastion/session_delete · Action
Delete a Bastion session by its OCID — it tears down the brokered SSH access.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Session OCID | string | Required | ocid1.bastionsession.oc1..aaaa… of the session to delete |
Returns: tool_result, id, work_request_id, success, error
OCI Bastion: Get Session
oracle/bastion/session_get · Action
Fetch a single Bastion session by its OCID — its target-resource details, TTL, key type and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Session OCID | string | Required | ocid1.bastionsession.oc1..aaaa… |
Returns: tool_result, session, id, lifecycle_state, success, error
OCI Bastion: List Sessions
oracle/bastion/session_list · Action
List the sessions on a bastion. Optionally filter by lifecycle state or exact display name and cap the page size. Walks pagination up to a safe limit.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Bastion OCID | string | Required | ocid1.bastion.oc1..aaaa… — the bastion whose sessions to list |
| Display Name Filter | string | Only sessions with this exact name (optional) | |
| Lifecycle State | string | Filter by session state (optional) — choices: Creating, Active, Deleting, Deleted, Failed | |
| Page Size | string | Max sessions per page (optional) |
Returns: tool_result, sessions, count, truncated, success, error
04Notes & Limitations
Behaviours and constraints worth knowing before you build with these nodes.
- Creating, updating and deleting bastions and sessions all run asynchronously: the action returns straight away with a work-request id, and creates come back in a transitional
CREATINGstate, so poll the matching Get action until the resource isACTIVE(or gone) before a later step relies on it. - A managed SSH session only succeeds when the target host runs an OpenSSH server and the Oracle Cloud Agent, and it logs in as the OS user named in
Target OS Username(for exampleopc). - The session action brokers the access but does not open the shell itself — once the session is
ACTIVE, you connect to the host from outside the flow using the private key that matches theSSH Public Keyyou supplied. - Every bastion and session action requires a
Compartment OCID, including fetches and deletes that already identify the resource by its own OCID. - Create Bastion always provisions a standard bastion and its name is fixed at creation; Update Bastion changes only the maximum session TTL and the client CIDR allow-list, leaving any field you leave blank untouched.