- Support
- Integrations
- Cloud Guard
Cloud Guard
Oracle Cloud integration · 20 node(s).
00Overview
Keep watch over your Oracle Cloud tenancy's security posture straight from a flow — list and triage the problems Cloud Guard raises, mark them open, resolved or dismissed, and pull the full detail of any single finding. Manage the building blocks behind that monitoring too: create and organise detector recipes, targets and managed lists, and move detector recipes between compartments. Automate routine security housekeeping so findings are enriched, escalated or cleared without anyone opening the Console.
Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.
01Connecting Cloud Guard
- Open the node's Authentication dropdown and choose how it signs in: Connect Oracle Cloud (recommended) uses a managed connection you set up once, while API signing key (advanced) lets you supply raw signing-key credentials by hand.
- For Connect Oracle Cloud, open your Flomation Environment → Connections, add an Oracle Cloud connection, and follow the wizard to authorise Flomation against your tenancy — you supply your Tenancy OCID and home Region as part of that setup.
- Once the connection tests green, return to the node, leave Authentication on Connect Oracle Cloud, and pick your connection in the Oracle Cloud connection field.
- To use API signing key (advanced) instead, in the OCI Console open your Profile menu → My profile → API keys, choose Add API key, and either generate a new key pair or upload your own public key — the Console then shows a configuration preview containing your Tenancy OCID, User OCID, Region and Key Fingerprint.
- Copy those four values into the node's matching fields, then store the private key (the full PEM) as a Flomation environment secret (e.g.
cloudguard_secret) and select it in the node's Private Key (PEM) field — add a Private Key Passphrase secret too if your key is encrypted. - Finally, set the Compartment OCID on each node to the compartment whose security posture you want to work with; you can find it in the OCI Console under Identity & Security → Compartments.
| Field | Type | Details | |
|---|---|---|---|
| Authentication | string | Connect Oracle Cloud, API signing key (advanced) | |
| Oracle Cloud connection | credential | Pick a connected Oracle Cloud account | |
| Region | string | e.g. uk-london-1 | |
| Private Key (PEM) | secret | The API signing private key — full PEM, incl. BEGIN/END lines | |
| Private Key Passphrase | secret | Only if the key is encrypted (optional) | |
| Tenancy OCID | string | ocid1.tenancy.oc1..aaaa… | |
| User OCID | string | ocid1.user.oc1..aaaa… | |
| Key Fingerprint | string | aa:bb:cc:… fingerprint of the uploaded API key |
Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.
02Detector
OCI Cloud Guard: Change Detector Recipe Compartment
oracle/cloudguard/detector_recipe_change_compartment · Action
Move a Cloud Guard detector recipe into a different compartment — the recipe keeps its OCID, only its compartment placement changes.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Detector Recipe OCID | string | Required | ocid1.cloudguarddetectorrecipe.oc1..aaaa… (the recipe to move) |
| Destination Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (where to move the recipe) |
Returns: tool_result, id, destination_compartment_id, success, error
OCI Cloud Guard: Create Detector Recipe
oracle/cloudguard/detector_recipe_create · Action
Create a detector recipe by cloning an Oracle-managed source recipe into a compartment, ready for its rules to be tuned.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Display Name | string | Required | A name for the new detector recipe |
| Source Detector Recipe OCID | string | Required | The Oracle-managed detector recipe to clone |
| Description | string | Optional |
Returns: tool_result, recipe, id, lifecycle_state, success, error
OCI Cloud Guard: Delete Detector Recipe
oracle/cloudguard/detector_recipe_delete · Action
Delete a Cloud Guard detector recipe by its OCID.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Detector Recipe OCID | string | Required | ocid1.cloudguarddetectorrecipe.oc1..aaaa… of the recipe to delete |
Returns: tool_result, id, success, error
OCI Cloud Guard: Get Detector Recipe
oracle/cloudguard/detector_recipe_get · Action
Fetch a single Cloud Guard detector recipe by its OCID — its owner, detector, source recipe and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Detector Recipe OCID | string | Required | ocid1.securitydetectorrecipe.oc1..aaaa… |
Returns: tool_result, recipe, id, lifecycle_state, success, error
OCI Cloud Guard: List Detector Recipes
oracle/cloudguard/detector_recipe_list · Action
List the Cloud Guard detector recipes in a compartment. Optionally filter by exact display name or lifecycle state, and cap the per-page size. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Display Name Filter | string | Only recipes with this exact name (optional) | |
| Lifecycle State | string | Defaults to ACTIVE when unset — choices: Creating, Updating, Active, Inactive, Deleting, Deleted, Failed | |
| Page Size | string | Max items per page (optional) |
Returns: tool_result, recipes, count, truncated, success, error
OCI Cloud Guard: Update Detector Recipe
oracle/cloudguard/detector_recipe_update · Action
Partially update a Cloud Guard detector recipe — change only the display name or description you supply; blank fields are left unchanged and the recipe's detector rules are preserved.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Detector Recipe OCID | string | Required | ocid1.cloudguarddetectorrecipe.oc1..aaaa… — the recipe to update |
| Display Name | string | New name (leave blank to keep unchanged) | |
| Description | string | New description (leave blank to keep unchanged) |
Returns: tool_result, recipe, id, success, error
03Managed
OCI Cloud Guard: Create Managed List
oracle/cloudguard/managed_list_create · Action
Create a Cloud Guard managed list — a named, typed collection of values (CIDR blocks, user/group OCIDs, IP addresses, …) that detector and responder rules reference to parameterise what they match on.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… — where the managed list is created |
| Display Name | string | Required | A name for the managed list |
| List Type | string | Required | The kind of value stored in the list — choices: CIDR Block, Users, Groups, IPv4 Address, IPv6 Address, Resource OCID, Region, Country, State, City, Tags, Generic, Fusion Apps Role, Fusion Apps Permission, Namespace Selector, Pod Resource Selector |
| List Items (CSV) | text | Comma-separated values, e.g. 10.0.0.0/24, 192.168.0.0/16 (optional) | |
| Description | string | Optional |
Returns: tool_result, managed_list, id, lifecycle_state, success, error
OCI Cloud Guard: Delete Managed List
oracle/cloudguard/managed_list_delete · Action
Delete a Cloud Guard managed list by its OCID — it is removed from any rules that referenced it.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Managed List OCID | string | Required | ocid1.cloudguardmanagedlist.oc1..aaaa… of the list to delete |
Returns: tool_result, id, success, error
OCI Cloud Guard: Get Managed List
oracle/cloudguard/managed_list_get · Action
Fetch a single Cloud Guard managed list by its OCID — its type, feed provider, item count and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Managed List OCID | string | Required | ocid1.cloudguardmanagedlist.oc1..aaaa… |
Returns: tool_result, managed_list, id, lifecycle_state, success, error
OCI Cloud Guard: List Managed Lists
oracle/cloudguard/managed_list_list · Action
List the Cloud Guard managed lists in a compartment. Optionally filter by exact display name, list type or lifecycle state. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Display Name Filter | string | Only managed lists with this exact name (optional) | |
| List Type | string | Filter by the kind of managed list (optional) — choices: CIDR Block, Users, Groups, IPv4 Address, IPv6 Address, Resource OCID, Region, Country, State, City, Tags, Generic, Fusion Apps Role, Fusion Apps Permission, Namespace Selector, Pod Resource Selector | |
| Lifecycle State | string | Defaults to ACTIVE when unset — choices: Creating, Updating, Active, Inactive, Deleting, Deleted, Failed | |
| Page Size | string | Max items per page (optional) |
Returns: tool_result, managed_lists, count, truncated, success, error
04Problem
OCI Cloud Guard: Get Problem
oracle/cloudguard/problem_get · Action
Fetch a single Cloud Guard problem by its OCID — its risk level, affected resource, detector rule and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Problem OCID | string | Required | ocid1.cloudguardproblem.oc1..aaaa… |
Returns: tool_result, problem, id, lifecycle_state, success, error
OCI Cloud Guard: List Problems
oracle/cloudguard/problem_list · Action
List the security problems Cloud Guard has surfaced in a compartment, optionally filtered by lifecycle detail, lifecycle state, or risk level. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Lifecycle Detail | string | Defaults to OPEN when unset — choices: Open, Resolved, Dismissed, Deleted | |
| Lifecycle State | string | Defaults to ACTIVE when unset — choices: Active, Inactive | |
| Risk Level | string | Only problems at this risk level (optional) — choices: Critical, High, Medium, Low, Minor | |
| Page Size | string | Items per page (optional) |
Returns: tool_result, problems, count, truncated, success, error
OCI Cloud Guard: Update Problem Status
oracle/cloudguard/problem_update_status · Action
Change a Cloud Guard problem's workflow status — mark it OPEN, RESOLVED or DISMISSED.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Problem OCID | string | Required | ocid1.cloudguardproblem.oc1..aaaa… — the problem to update |
| Status | string | Required | The new workflow status — choices: Open, Resolved, Dismissed |
| Comment | text | Optional note recorded with the status change |
Returns: tool_result, problem, id, success, error
05Responder
OCI Cloud Guard: List Responder Recipes
oracle/cloudguard/responder_recipe_list · Action
List the Cloud Guard responder recipes in a compartment. Optionally filter by exact display name or lifecycle state, and cap the per-page size. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Display Name Filter | string | Only recipes with this exact name (optional) | |
| Lifecycle State | string | Defaults to ACTIVE when unset — choices: Creating, Updating, Active, Inactive, Deleting, Deleted, Failed | |
| Page Size | string | Max items per page (optional) |
Returns: tool_result, responder_recipes, count, truncated, success, error
06Target
OCI Cloud Guard: Change Target Compartment
oracle/cloudguard/target_change_compartment · Action
Attempt to move a Cloud Guard target to another compartment — reports that OCI provides no such operation for targets.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Target OCID | string | Required | ocid1.cloudguardtarget.oc1..aaaa… (the target to move) |
| Destination Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (where you want the target) |
Returns: tool_result, success, error
OCI Cloud Guard: Create Target
oracle/cloudguard/target_create · Action
Create a Cloud Guard target — the compartment (or ERP/HCM Cloud instance) whose resources Cloud Guard monitors against its detector and responder recipes.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… — where the target is created |
| Display Name | string | Required | A name for the target |
| Target Resource Type | string | Required | The kind of resource the target monitors — choices: Compartment, ERP Cloud, HCM Cloud |
| Target Resource OCID | string | Required | OCID of the compartment / ERP / HCM instance to monitor |
| Description | string | Optional | |
| Freeform Tags (JSON) | string | {"env":"prod"} (optional) |
Returns: tool_result, target, id, lifecycle_state, success, error
OCI Cloud Guard: Delete Target
oracle/cloudguard/target_delete · Action
Delete a Cloud Guard target by its OCID — it stops applying its detector and responder recipes to the compartment.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Target OCID | string | Required | ocid1.cloudguardtarget.oc1..aaaa… of the target to delete |
Returns: tool_result, id, success, error
OCI Cloud Guard: Get Target
oracle/cloudguard/target_get · Action
Fetch a single Cloud Guard target by its OCID — its monitored resource, recipes and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Target OCID | string | Required | ocid1.cloudguardtarget.oc1..aaaa… |
Returns: tool_result, target, id, lifecycle_state, success, error
OCI Cloud Guard: List Targets
oracle/cloudguard/target_list · Action
List the Cloud Guard targets in a compartment. Optionally filter by exact display name or lifecycle state. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Display Name Filter | string | Only targets with this exact name (optional) | |
| Lifecycle State | string | Defaults to ACTIVE when unset — choices: Creating, Updating, Active, Inactive, Deleting, Deleted, Failed | |
| Page Size | string | Max items per page (optional) |
Returns: tool_result, targets, count, truncated, success, error
OCI Cloud Guard: Update Target
oracle/cloudguard/target_update · Action
Partially update a Cloud Guard target — change only the display name you supply; a blank field is left unchanged and the target's existing detector and responder recipes are preserved.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Target OCID | string | Required | ocid1.cloudguardtarget.oc1..aaaa… — the target to update |
| Display Name | string | New name (leave blank to keep unchanged) |
Returns: tool_result, target, id, success, error
07Notes & Limitations
Behaviours and constraints worth knowing before you build with these nodes.
- Cloud Guard consolidates every problem in your tenancy's single reporting region, so set the node's Region to that reporting region — querying any other region returns no findings even when problems exist.
- Cloud Guard targets cannot be moved between compartments — the attempt returns an explanation instead of moving anything, so to relocate a target, recreate it in the destination compartment with the same target resource and recipes and then delete the original.
- Updating a detector recipe changes only the display name and description you provide, and updating a target changes only its display name; blank fields are left as they were, and the detector and responder rules already configured are preserved untouched.
- List actions page through results automatically but stop at a safety cap of 25 pages, so in large compartments narrow the results with the display-name or lifecycle-state filters rather than expecting a single call to return everything.