Article 12 – Tag-Based Access Control (TBAC) & Attribute-Based Access Control (ABAC)

1. Introduction to Dynamic Metadata Governance

As enterprise cloud footprints grow to encompass thousands of compute VMs, storage buckets, and subnets across dozens of compartments, managing static compartment-based IAM policies becomes an operational bottleneck.

Oracle Cloud Infrastructure (OCI) solves this by supporting Tag-Based Access Control (TBAC) and Attribute-Based Access Control (ABAC).

Using TBAC, access permissions are evaluated dynamically based on Defined Tag metadata attached to resources. When a developer launches a new VM and tags it Environment = Dev, IAM policies automatically grant appropriate development teams access to that VM instantly, without modifying any policy documents.

2. Defined Tags vs. Freeform Tags

OCI supports two distinct types of resource tagging:

  1. Freeform Tags: Simple key-value string pairs (e.g., Owner = Alex). Freeform tags have no administrative schema, no pre-defined value lists, and CANNOT be evaluated in IAM policy conditions.
  2. Defined Tags: Schema-governed tags contained within a controlled Tag Namespace. Defined tags support restricted value lists, default tag rules, tag tracking, and can be evaluated natively in IAM policy where clauses.

[!IMPORTANT]
Policy Evaluation Requires Defined Tags
IAM policy conditions (target.resource.tag.<Namespace>.<Key>) evaluate Defined Tags ONLY. Freeform tags are ignored by the OCI Policy Engine.

3. Tag-Based Policy Syntax

To write a Tag-Based Access Control policy, reference the Defined Tag Namespace and Key in the where clause:

Allow group Dev-Engineers to manage instance-family in compartment Engineering where target.resource.tag.Operations.Environment = 'Dev'
Breakdown:
  • Operations: The Tag Namespace.
  • Environment: The Tag Key.
  • 'Dev': The target Tag Value.
4. OCI Web Console (GUI) Step-by-Step Walkthrough

Creating Tag Namespaces, Defined Tags, and Tag-Based Policies is managed directly in the OCI Web Console GUI.

Step 1: Creating a Tag Namespace and Tag Key
  1. Log in to the Oracle Cloud Console (https://cloud.oracle.com).
  2. Open Navigation Menu (≡) ➔ Governance & Administration ➔ Tag Namespaces.
  3. Select Root Tenancy (or target compartment).
  4. Click Create Tag Namespace.
  5. Namespace Name: Operations
  6. Description: Operational governance tags.
  7. Click Create Tag Namespace.
  8. Click the newly created Operations namespace from the table list.
  9. Click Create Tag Key Definition.
  10. Tag Key: Environment
  11. Description: Lifecycle environment classification.
  12. Values: Select Static List ➔ Add values: Dev, Stage, Prod.
  13. Click Create Tag Key Definition.
Step 2: Creating a Tag-Based Policy
  1. Open Identity & Security ➔ Policies.
  2. Select target compartment (e.g., Engineering).
  3. Click Create Policy.
  4. Name the policy: TBAC-Dev-Instance-Policy.
  5. Toggle to manual editor and enter:
    text
    Allow group Dev-Engineers to manage instance-family in compartment Engineering where target.resource.tag.Operations.Environment = 'Dev'
  6. Click Create.

Developers in Dev-Engineers can now manage any compute VM inside Engineering tagged Operations.Environment = Dev, while remaining blocked from VMs tagged Operations.Environment = Prod.

5. Common Architectural Misconceptions & Pitfalls
Misconception 1: “Freeform Tags Can Be Referenced in IAM Policies”
  • Reality: Attempting to reference a Freeform tag in a policy where clause will result in policy syntax rejection or silent evaluation failure. Always use Defined Tags inside a Tag Namespace for security governance.
Misconception 2: “Tag Namespaces and Keys Are Case-Insensitive”
  • Reality: Tag Namespaces and Key names are strictly case-sensitive in policy conditions. target.resource.tag.operations.environment will NOT match a resource tagged Operations.Environment.
6. OCI Defined Tags vs. Google Cloud (GCP) Tags & Labels

For cloud architects familiar with Google Cloud, the following table compares metadata tagging:

Metadata FeatureGoogle Cloud (GCP)Oracle Cloud Infrastructure (OCI)Key Technical Difference
Ungoverned Key-ValuesGCP Labels (used for filtering/billing)Freeform Tags (used for basic grouping, not security)Both provide lightweight ungoverned key-value strings.
Governed MetadataGCP Resource Manager Tags (Resource Namespaces)Defined Tags (Tag Namespaces)Both enforce schema control and value lists via central namespaces.
IAM Policy EvaluationGCP IAM Conditions referencing resource.matchTag()OCI Policies evaluating target.resource.tag.<Namespace>.<Key>OCI natively embeds Defined Tag Namespace paths directly into IAM policy syntax.