1. Support
  2. Integrations
  3. Cloud Guard
Oracle Cloud 20 nodes

Cloud Guard

Oracle Cloud integration · 20 node(s).

00Overview

Keep watch over your Oracle Cloud tenancy's security posture straight from a flow — list and triage the problems Cloud Guard raises, mark them open, resolved or dismissed, and pull the full detail of any single finding. Manage the building blocks behind that monitoring too: create and organise detector recipes, targets and managed lists, and move detector recipes between compartments. Automate routine security housekeeping so findings are enriched, escalated or cleared without anyone opening the Console.

Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.

01Connecting Cloud Guard

  1. Open the node's Authentication dropdown and choose how it signs in: Connect Oracle Cloud (recommended) uses a managed connection you set up once, while API signing key (advanced) lets you supply raw signing-key credentials by hand.
  2. For Connect Oracle Cloud, open your Flomation Environment → Connections, add an Oracle Cloud connection, and follow the wizard to authorise Flomation against your tenancy — you supply your Tenancy OCID and home Region as part of that setup.
  3. Once the connection tests green, return to the node, leave Authentication on Connect Oracle Cloud, and pick your connection in the Oracle Cloud connection field.
  4. To use API signing key (advanced) instead, in the OCI Console open your Profile menu → My profile → API keys, choose Add API key, and either generate a new key pair or upload your own public key — the Console then shows a configuration preview containing your Tenancy OCID, User OCID, Region and Key Fingerprint.
  5. Copy those four values into the node's matching fields, then store the private key (the full PEM) as a Flomation environment secret (e.g. cloudguard_secret) and select it in the node's Private Key (PEM) field — add a Private Key Passphrase secret too if your key is encrypted.
  6. Finally, set the Compartment OCID on each node to the compartment whose security posture you want to work with; you can find it in the OCI Console under Identity & Security → Compartments.
FieldTypeDetails
AuthenticationstringConnect Oracle Cloud, API signing key (advanced)
Oracle Cloud connectioncredentialPick a connected Oracle Cloud account
Regionstringe.g. uk-london-1
Private Key (PEM)secretThe API signing private key — full PEM, incl. BEGIN/END lines
Private Key PassphrasesecretOnly if the key is encrypted (optional)
Tenancy OCIDstringocid1.tenancy.oc1..aaaa…
User OCIDstringocid1.user.oc1..aaaa…
Key Fingerprintstringaa:bb:cc:… fingerprint of the uploaded API key
Good to know

Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.

02Detector

OCI Cloud Guard: Change Detector Recipe Compartment

oracle/cloudguard/detector_recipe_change_compartment · Action

Move a Cloud Guard detector recipe into a different compartment — the recipe keeps its OCID, only its compartment placement changes.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa…
Detector Recipe OCIDstringRequiredocid1.cloudguarddetectorrecipe.oc1..aaaa… (the recipe to move)
Destination Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (where to move the recipe)

Returns: tool_result, id, destination_compartment_id, success, error

OCI Cloud Guard: Create Detector Recipe

oracle/cloudguard/detector_recipe_create · Action

Create a detector recipe by cloning an Oracle-managed source recipe into a compartment, ready for its rules to be tuned.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa…
Display NamestringRequiredA name for the new detector recipe
Source Detector Recipe OCIDstringRequiredThe Oracle-managed detector recipe to clone
DescriptionstringOptional

Returns: tool_result, recipe, id, lifecycle_state, success, error

OCI Cloud Guard: Delete Detector Recipe

oracle/cloudguard/detector_recipe_delete · Action

Delete a Cloud Guard detector recipe by its OCID.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa…
Detector Recipe OCIDstringRequiredocid1.cloudguarddetectorrecipe.oc1..aaaa… of the recipe to delete

Returns: tool_result, id, success, error

OCI Cloud Guard: Get Detector Recipe

oracle/cloudguard/detector_recipe_get · Action

Fetch a single Cloud Guard detector recipe by its OCID — its owner, detector, source recipe and lifecycle state.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa…
Detector Recipe OCIDstringRequiredocid1.securitydetectorrecipe.oc1..aaaa…

Returns: tool_result, recipe, id, lifecycle_state, success, error

OCI Cloud Guard: List Detector Recipes

oracle/cloudguard/detector_recipe_list · Action

List the Cloud Guard detector recipes in a compartment. Optionally filter by exact display name or lifecycle state, and cap the per-page size. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Display Name FilterstringOnly recipes with this exact name (optional)
Lifecycle StatestringDefaults to ACTIVE when unset — choices: Creating, Updating, Active, Inactive, Deleting, Deleted, Failed
Page SizestringMax items per page (optional)

Returns: tool_result, recipes, count, truncated, success, error

OCI Cloud Guard: Update Detector Recipe

oracle/cloudguard/detector_recipe_update · Action

Partially update a Cloud Guard detector recipe — change only the display name or description you supply; blank fields are left unchanged and the recipe's detector rules are preserved.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa…
Detector Recipe OCIDstringRequiredocid1.cloudguarddetectorrecipe.oc1..aaaa… — the recipe to update
Display NamestringNew name (leave blank to keep unchanged)
DescriptionstringNew description (leave blank to keep unchanged)

Returns: tool_result, recipe, id, success, error

03Managed

OCI Cloud Guard: Create Managed List

oracle/cloudguard/managed_list_create · Action

Create a Cloud Guard managed list — a named, typed collection of values (CIDR blocks, user/group OCIDs, IP addresses, …) that detector and responder rules reference to parameterise what they match on.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… — where the managed list is created
Display NamestringRequiredA name for the managed list
List TypestringRequiredThe kind of value stored in the list — choices: CIDR Block, Users, Groups, IPv4 Address, IPv6 Address, Resource OCID, Region, Country, State, City, Tags, Generic, Fusion Apps Role, Fusion Apps Permission, Namespace Selector, Pod Resource Selector
List Items (CSV)textComma-separated values, e.g. 10.0.0.0/24, 192.168.0.0/16 (optional)
DescriptionstringOptional

Returns: tool_result, managed_list, id, lifecycle_state, success, error

OCI Cloud Guard: Delete Managed List

oracle/cloudguard/managed_list_delete · Action

Delete a Cloud Guard managed list by its OCID — it is removed from any rules that referenced it.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa…
Managed List OCIDstringRequiredocid1.cloudguardmanagedlist.oc1..aaaa… of the list to delete

Returns: tool_result, id, success, error

OCI Cloud Guard: Get Managed List

oracle/cloudguard/managed_list_get · Action

Fetch a single Cloud Guard managed list by its OCID — its type, feed provider, item count and lifecycle state.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa…
Managed List OCIDstringRequiredocid1.cloudguardmanagedlist.oc1..aaaa…

Returns: tool_result, managed_list, id, lifecycle_state, success, error

OCI Cloud Guard: List Managed Lists

oracle/cloudguard/managed_list_list · Action

List the Cloud Guard managed lists in a compartment. Optionally filter by exact display name, list type or lifecycle state. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Display Name FilterstringOnly managed lists with this exact name (optional)
List TypestringFilter by the kind of managed list (optional) — choices: CIDR Block, Users, Groups, IPv4 Address, IPv6 Address, Resource OCID, Region, Country, State, City, Tags, Generic, Fusion Apps Role, Fusion Apps Permission, Namespace Selector, Pod Resource Selector
Lifecycle StatestringDefaults to ACTIVE when unset — choices: Creating, Updating, Active, Inactive, Deleting, Deleted, Failed
Page SizestringMax items per page (optional)

Returns: tool_result, managed_lists, count, truncated, success, error

04Problem

OCI Cloud Guard: Get Problem

oracle/cloudguard/problem_get · Action

Fetch a single Cloud Guard problem by its OCID — its risk level, affected resource, detector rule and lifecycle state.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa…
Problem OCIDstringRequiredocid1.cloudguardproblem.oc1..aaaa…

Returns: tool_result, problem, id, lifecycle_state, success, error

OCI Cloud Guard: List Problems

oracle/cloudguard/problem_list · Action

List the security problems Cloud Guard has surfaced in a compartment, optionally filtered by lifecycle detail, lifecycle state, or risk level. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Lifecycle DetailstringDefaults to OPEN when unset — choices: Open, Resolved, Dismissed, Deleted
Lifecycle StatestringDefaults to ACTIVE when unset — choices: Active, Inactive
Risk LevelstringOnly problems at this risk level (optional) — choices: Critical, High, Medium, Low, Minor
Page SizestringItems per page (optional)

Returns: tool_result, problems, count, truncated, success, error

OCI Cloud Guard: Update Problem Status

oracle/cloudguard/problem_update_status · Action

Change a Cloud Guard problem's workflow status — mark it OPEN, RESOLVED or DISMISSED.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa…
Problem OCIDstringRequiredocid1.cloudguardproblem.oc1..aaaa… — the problem to update
StatusstringRequiredThe new workflow status — choices: Open, Resolved, Dismissed
CommenttextOptional note recorded with the status change

Returns: tool_result, problem, id, success, error

05Responder

OCI Cloud Guard: List Responder Recipes

oracle/cloudguard/responder_recipe_list · Action

List the Cloud Guard responder recipes in a compartment. Optionally filter by exact display name or lifecycle state, and cap the per-page size. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Display Name FilterstringOnly recipes with this exact name (optional)
Lifecycle StatestringDefaults to ACTIVE when unset — choices: Creating, Updating, Active, Inactive, Deleting, Deleted, Failed
Page SizestringMax items per page (optional)

Returns: tool_result, responder_recipes, count, truncated, success, error

06Target

OCI Cloud Guard: Change Target Compartment

oracle/cloudguard/target_change_compartment · Action

Attempt to move a Cloud Guard target to another compartment — reports that OCI provides no such operation for targets.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa…
Target OCIDstringRequiredocid1.cloudguardtarget.oc1..aaaa… (the target to move)
Destination Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (where you want the target)

Returns: tool_result, success, error

OCI Cloud Guard: Create Target

oracle/cloudguard/target_create · Action

Create a Cloud Guard target — the compartment (or ERP/HCM Cloud instance) whose resources Cloud Guard monitors against its detector and responder recipes.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… — where the target is created
Display NamestringRequiredA name for the target
Target Resource TypestringRequiredThe kind of resource the target monitors — choices: Compartment, ERP Cloud, HCM Cloud
Target Resource OCIDstringRequiredOCID of the compartment / ERP / HCM instance to monitor
DescriptionstringOptional
Freeform Tags (JSON)string{"env":"prod"} (optional)

Returns: tool_result, target, id, lifecycle_state, success, error

OCI Cloud Guard: Delete Target

oracle/cloudguard/target_delete · Action

Delete a Cloud Guard target by its OCID — it stops applying its detector and responder recipes to the compartment.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa…
Target OCIDstringRequiredocid1.cloudguardtarget.oc1..aaaa… of the target to delete

Returns: tool_result, id, success, error

OCI Cloud Guard: Get Target

oracle/cloudguard/target_get · Action

Fetch a single Cloud Guard target by its OCID — its monitored resource, recipes and lifecycle state.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa…
Target OCIDstringRequiredocid1.cloudguardtarget.oc1..aaaa…

Returns: tool_result, target, id, lifecycle_state, success, error

OCI Cloud Guard: List Targets

oracle/cloudguard/target_list · Action

List the Cloud Guard targets in a compartment. Optionally filter by exact display name or lifecycle state. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Display Name FilterstringOnly targets with this exact name (optional)
Lifecycle StatestringDefaults to ACTIVE when unset — choices: Creating, Updating, Active, Inactive, Deleting, Deleted, Failed
Page SizestringMax items per page (optional)

Returns: tool_result, targets, count, truncated, success, error

OCI Cloud Guard: Update Target

oracle/cloudguard/target_update · Action

Partially update a Cloud Guard target — change only the display name you supply; a blank field is left unchanged and the target's existing detector and responder recipes are preserved.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa…
Target OCIDstringRequiredocid1.cloudguardtarget.oc1..aaaa… — the target to update
Display NamestringNew name (leave blank to keep unchanged)

Returns: tool_result, target, id, success, error

07Notes & Limitations

Behaviours and constraints worth knowing before you build with these nodes.

  • Cloud Guard consolidates every problem in your tenancy's single reporting region, so set the node's Region to that reporting region — querying any other region returns no findings even when problems exist.
  • Cloud Guard targets cannot be moved between compartments — the attempt returns an explanation instead of moving anything, so to relocate a target, recreate it in the destination compartment with the same target resource and recipes and then delete the original.
  • Updating a detector recipe changes only the display name and description you provide, and updating a target changes only its display name; blank fields are left as they were, and the detector and responder rules already configured are preserved untouched.
  • List actions page through results automatically but stop at a safety cap of 25 pages, so in large compartments narrow the results with the display-name or lifecycle-state filters rather than expecting a single call to return everything.