OCI VCN - Core-Distribution-Access Architecture

OCINetworkadvanced
OCI VCN - Core-Distribution-Access Architecture — OCI network diagram

About This Architecture

OCI VCN with core-distribution-access three-layer architecture spans DMZ, app, SFTP, data, integration, and observability subnets across 10.0.0.0/16 in us-ashburn-1 region. Internet traffic flows through Internet Gateway, WAF/DDoS protection, and OCI Public Load Balancer to Ubuntu app servers running Docker, React, and Spring Boot, which connect to PostgreSQL DB, Redis cache, and OCI API Gateway for external integrations. Bastion Service provides secure admin access; SFTP instances handle Oracle HCM data transfers; PostgreSQL, Object Storage, and File Storage comprise the data tier with encryption via Vault and monitoring via Data Safe. OCI Monitoring, Logging, Log Analytics, APM, and Flow Logs provide full observability across all tiers and NSGs. Fork this diagram on Diagrams.so to customize subnets, add additional regions, or adapt security policies for your production workload. This architecture demonstrates OCI best practices for defense-in-depth, least-privilege access, and comprehensive audit trails.

People also ask

How do I design a secure, multi-tier OCI VCN architecture with proper network segmentation and observability?

This diagram shows a production OCI VCN using core-distribution-access layering: the core tier includes PostgreSQL, Redis, and storage; the distribution tier routes traffic via API Gateway and Integration Service; the access tier provides Internet Gateway, WAF/DDoS, load balancer, and Bastion Service for secure admin access. All tiers are monitored via OCI Monitoring, Logging, and APM.

OCIVCNnetwork-architecturesecuritymulti-tierobservability
Domain:
Cloud Aws
Audience:
OCI cloud architects designing secure, multi-tier production networks

Generated by Diagrams.so — AI architecture diagram generator with native Draw.io output. Fork this diagram, remix it, or download as .drawio, PNG, or SVG.

Generate your own network diagram →

About This Architecture

OCI VCN with core-distribution-access three-layer architecture spans DMZ, app, SFTP, data, integration, and observability subnets across 10.0.0.0/16 in us-ashburn-1 region. Internet traffic flows through Internet Gateway, WAF/DDoS protection, and OCI Public Load Balancer to Ubuntu app servers running Docker, React, and Spring Boot, which connect to PostgreSQL DB, Redis cache, and OCI API Gateway for external integrations. Bastion Service provides secure admin access; SFTP instances handle Oracle HCM data transfers; PostgreSQL, Object Storage, and File Storage comprise the data tier with encryption via Vault and monitoring via Data Safe. OCI Monitoring, Logging, Log Analytics, APM, and Flow Logs provide full observability across all tiers and NSGs. Fork this diagram on Diagrams.so to customize subnets, add additional regions, or adapt security policies for your production workload. This architecture demonstrates OCI best practices for defense-in-depth, least-privilege access, and comprehensive audit trails.

People also ask

How do I design a secure, multi-tier OCI VCN architecture with proper network segmentation and observability?

This diagram shows a production OCI VCN using core-distribution-access layering: the core tier includes PostgreSQL, Redis, and storage; the distribution tier routes traffic via API Gateway and Integration Service; the access tier provides Internet Gateway, WAF/DDoS, load balancer, and Bastion Service for secure admin access. All tiers are monitored via OCI Monitoring, Logging, and APM.

OCI VCN - Core-Distribution-Access Architecture

OCIadvancedVCNnetwork-architecturesecuritymulti-tierobservability
Domain: Cloud AwsAudience: OCI cloud architects designing secure, multi-tier production networks
0 views0 favoritesPublic

Created by

May 20, 2026

Updated

May 20, 2026 at 7:51 AM

Type

network

Need a custom architecture diagram?

Describe your architecture in plain English and get a production-ready Draw.io diagram in seconds. Works for AWS, Azure, GCP, Kubernetes, and more.

Generate with AI