About This Architecture
OCI zero-trust architecture for Exadata and ExaCC enforces identity-first security across perimeter, distribution, and access layers with DDoS protection, WAF, and edge firewalls. Traffic flows from external users through CDN and API Gateway into a segmented VCN (10.10.0.0/16) with app and data subnets protected by network security groups, internal firewalls, and micro-segmentation. Identity governance via IAM Identity Domain, Active Directory/MFA, and OCI Vault ensures least-privilege access to Exadata Cloud@Customer and Autonomous Database with encryption in transit and at rest. Comprehensive observability through OCI Logging, Log Analytics, Cloud Guard threat intelligence, and vulnerability scanning enables continuous compliance monitoring and incident response. Fork this diagram on Diagrams.so to customize compartment policies, routing rules, and security zone configurations for your OCI region and workload requirements.