Article 04 – Resource Types and Resource Families: Precision Access Control

1. Introduction to OCI Resource Target Scoping

In Oracle Cloud Infrastructure (OCI) policy statements, the target of an action is defined by a Resource Type or a Resource Family.

Rather than requiring administrators to reference individual API permission strings for every cloud service, OCI groups related resources into logical hierarchies. This design allows you to grant broad administrative rights across an entire infrastructure component using a single Resource Family, or enforce strict least-privilege security using Individual Resource Types.

Understanding how resource families expand into individual resource types is essential for constructing clean, auditable IAM policies.

2. Resource Families vs. Individual Resource Types
What is a Resource Family?

A Resource Family is a top-level abstraction that encompasses multiple related individual resource types. When you specify a resource family in a policy statement, OCI automatically applies the specified verb to all individual resources contained within that family.

For example, referencing instance-family covers compute instances, console connections, volume attachments, instance images, and custom boot volumes under a single policy statement.

What is an Individual Resource Type?

An Individual Resource Type targets a specific, singular OCI resource component. Use individual resource types when enforcing least-privilege access rules where users need access to one specific component without gaining access to surrounding service features.

For example, specifying instances targets compute VMs, but excludes management of custom machine images or console connections.

3. Core OCI Resource Families Breakdown

Below is the mapping of major OCI Resource Families and their constituent Individual Resource Types:

Resource FamilyIncluded Individual Resource TypesPrimary Target Components Covered
all-resourcesEvery existing and future resource type across all OCI servicesComplete tenancy or compartment administration
instance-familyinstances, instance-images, console-histories, volume-attachmentsCompute VMs, custom images, serial consoles, and disk attachments
virtual-network-familyvcns, subnets, route-tables, security-lists, dhcp-options, drgs, internet-gateways, nat-gateways, service-gateways, vnicsComplete core networking, subnets, routing, and gateway infrastructure
volume-familyvolumes, volume-backups, boot-volumes, volume-groupsElastic Block Storage volumes, boot disks, and backup snapshots
object-familybuckets, objectsOCI Object Storage containers and stored files
database-familyautonomous-databases, db-systems, db-nodes, db-homes, backupsOracle Autonomous Databases, Bare Metal/VM DB Systems, and Exadata

[!IMPORTANT]
The all-resources Universal Family
Granting manage all-resources in compartment Production provides full administrative control over every OCI service operating in that compartment—including services deployed by Oracle in the future. This family should be reserved strictly for top-level Security Administrators and Tenant Root Admins.

4. Resource Family Expansion Example

To understand how policy statements evaluate under the hood, compare these two policy formulations:

Option A: Using a Resource Family (Broad Scoping)
Allow group Dev-Network-Admins to manage virtual-network-family in compartment Dev-Compartment
  • Effect: Grants permission to create, modify, and delete VCNs, Subnets, Route Tables, Security Lists, DRGs, Internet Gateways, and NAT Gateways inside Dev-Compartment.
Option B: Using Individual Resource Types (Least-Privilege Scoping)
Allow group Dev-Operators to use subnets in compartment Dev-Compartment
Allow group Dev-Operators to use vnics in compartment Dev-Compartment
  • Effect: Grants developers permission to attach compute VMs to existing subnets and VNICs, but prevents them from deleting VCNs, modifying route tables, or altering security list rules.
5. OCI Web Console (GUI) Step-by-Step Walkthrough

Selecting and configuring resource types in policy statements is managed directly in the OCI Web Console GUI.

Step 1: Navigating to Policies
  1. Log in to the Oracle Cloud Console (https://cloud.oracle.com).
  2. Open the Navigation Menu (≡) ➔ Identity & Security ➔ Policies.
  3. Select the target compartment (e.g., Engineering-Compartment).
Step 2: Selecting Resource Scopes in the Policy Builder
  1. Click Create Policy.
  2. Name the policy: StorageAdminPolicy.
  3. Under Policy Builder:
  4. Switch off the manual editor to use the GUI Builder Dropdowns.
  5. Verb: Select manage.
  6. Target Resource: Choose Resource Family or Individual Resource:
    • Selecting volume-family grants access to all block volumes, boot disks, and backups.
    • Selecting individual buckets restricts access specifically to Object Storage containers.
  7. Complete the statement and click Create.
6. Common Architectural Misconceptions & Pitfalls
Misconception 1: “Specifying instance-family Automatically Grants Permission to Create Subnets”
  • Reality: Provisioning a compute VM requires attaching it to a Virtual Network Interface Card (VNIC) on a subnet. If a user has manage instance-family but lacks use subnets or use vnics in virtual-network-family, VM creation will fail during network attachment.
Misconception 2: “Individual Resource Types Can Be Combined in a Single Statement Array”
  • Reality: An OCI policy statement accepts either one specific resource family, one individual resource type, or a comma-separated list of individual types belonging to the same service. Mixing incompatible resource families in a single statement syntax is invalid.
7. OCI Resource Types vs. Google Cloud (GCP) Resource Scoping

For cloud architects familiar with Google Cloud, the following table compares resource targeting models:

Scoping MetricGoogle Cloud (GCP)Oracle Cloud Infrastructure (OCI)Key Technical Difference
Permission GranularityIndividual API permission strings (e.g., compute.instances.create)Resource Families or Individual Resource Types combined with progressive verbsOCI groups related API methods under unified resource abstractions (instance-family) rather than managing granular string arrays.
Broad ScopingPrimitive Roles (Owner, Editor, Viewer)Universal Family all-resources combined with verbs (inspect, read, use, manage)OCI allows broad administrative control without granting destructive ownership permissions tenancy-wide.
Service CoverageManaged via individual GCP service API enablementAutomatically covers current and future OCI services inside the targeted resource familyOCI policy resource families expand automatically when new features are added to a service family.