Connect to an Oracle Cloud Infrastructure NetApp Storage Service storage system with a link
To perform advanced storage management operations, set up a connection between your NetApp Workload Factory account and an Oracle Cloud Infrastructure NetApp Storage Service (OCI NSS) system. This process involves creating and associating a link with your storage system. Link association lets you monitor and manage certain features directly from the OCI NSS system that are unavailable through OCI APIs.
About this task
A link in Workload Factory is an OCI Functions application in your tenancy. Workload Factory uses it to talk to the ONTAP system on an OCI NSS storage pool (HTTPS 443 and SSH 22).
Links use OCI Functions to execute code in response to events and automatically manage the computing resources required by that code. The links that you create are part of your NetApp account and they are associated with an Oracle Cloud Infrastructure account.
You deploy the link, or function, with Terraform, then register the function OCID in Workload Factory.
This stack runs in your tenancy with your OCI user. It is not the cross-tenancy credentials policy. That policy belongs at the tenancy root when you add credentials; you do not create it again to create a link.
What Terraform creates
| Resource | Example name |
|---|---|
Functions application |
|
Function |
|
Log group + Functions invoke log |
|
Dynamic group + vault-read policy |
Only if you enable Local OCI Vault Authentication ( |
Create a new link
You can create a link in your account when defining an OCI NSS system. You use the link for that storage system, and you can use it for other OCI NSS systems. You can also associate a link for a storage system later.
Links require authentication. You can authenticate links using credentials stored in the Workload Factory credentials service or with your credentials stored in OCI Vault. Only one authentication method is supported per link. For example, if you select link authentication with OCI Vault, you can't change the authentication method later.
|
|
OCI Vault isn't supported when using a Console agent. |
-
You added Workload Factory credentials for the tenancy.
-
You can sign in to the OCI Console for the tenancy and region where the storage pool lives.
-
Networking:
-
A private subnet in the VCN that can reach the ONTAP management LIF
-
A service gateway with a route to All \<Region\> Services in Oracle Services Network (needed to pull the function image)
-
-
Create an IAM policy for the group that will deploy the stack. Learn more about OCI NSS permissions.
Grant the group permission to create the stack and function. Replace
<deploy-group>and<compartment-name>with your values. Use a named group, notany-user.Allow group <deploy-group> to manage orm-stacks in compartment <compartment-name> Allow group <deploy-group> to manage orm-jobs in compartment <compartment-name> Allow group <deploy-group> to manage functions-family in compartment <compartment-name> Allow group <deploy-group> to manage log-groups in compartment <compartment-name> Allow group <deploy-group> to use virtual-network-family in compartment <compartment-name>
If you enable Local OCI Vault Authentication, add:
Allow group <deploy-group> to manage dynamic-groups in tenancy Allow group <deploy-group> to manage policies in compartment <compartment-name>
The stack then creates (or reuses) dynamic group
netapp-functions-dgso the function can read the Vault secret. Matching rule:ALL {resource.type = 'fnfunc', resource.compartment.id = '<compartment-ocid>'}Vault policy in the compartment where the function and secret live:
Allow dynamic-group netapp-functions-dg to read secret-bundles in compartment <compartment-name> Allow dynamic-group netapp-functions-dg to use keys in compartment <compartment-name>
Use the OCI CLI or OCI Terraform to create and register the link within Workload Factory.
-
Select the menu
, Administration > Links. -
On the Links page, select Create and associate link > OCI NetApp Storage Service.
-
In the Add Link dialog under Details, provide the following:
-
Link name: Enter the name that you want to use for this link. The name must be unique within your account.
-
OCI Vault: Optional. Allows Workload Factory to fetch ONTAP access credentials securely from your OCI Vault.
The link deployment stack adds the following default OCI Vault secret OCID regex to the OCI Functions permission policy:
ocid1.vaultsecret.oc1.iad.<unique_id>.ONTAPSecret*.You can either create secrets in alignment with the default regex or update the regex in the Terraform configuration file to match your secret OCID.
-
Tags: Optionally, add up to 50 tags to associate with this link so you can more easily categorize your resources. For example, you could add a tag that identifies this link as being used by OCI NSS storage systems.
-
Link registration: Follow the instructions in the Workload Factory console to register the link. Link registration happens from your OCI Terraform environment. Select OCI Terraform from the Codebox for the instructions.
-
Link association: Select the OCI NSS storage system to associate with this link, and enter the user name and password.
-
Link permissions: Specify the required permissions for the user group to create the link.
Required permissions for the linkAllow group to manage orm-stacks in compartment id Allow group to manage orm-jobs in compartment id Allow group to manage dynamic-groups in tenancy Allow group to manage policies in compartment id Allow group to manage functions-family in compartment id Allow group to manage log-groups in compartment id Allow group to use virtual-network-family in compartment id
-
-
In the Add Link dialog under Location, provide the following:
-
OCI tenancy: Enter the OCI tenancy.
-
Compartment: Enter the compartment.
-
Region: Select the region.
-
Subnet: Select the subnet.
-
Network security group: Enter the security group.
Workload Factory automatically retrieves the OCI account, location, and security group based on the selected OCI NSS system.
-
-
Select Add.
You can monitor the link creation status on the Events page. This should take no more than five minutes.
-
Return to the Workload Factory interface and you'll see that the link is associated with the OCI NSS storage system.
Deploy the Terraform stack in OCI Resource Manager
-
In the Codebox, select OCI Terraform.
-
Select Redirect to OCI Resource Manager.
-
In the dialog, select Continue.
-
Sign in to the OCI tenancy that contains the storage pool.
-
Review compartment, region, and variables (pre-filled from Workload Factory).
-
Select Create. Wait until the apply job succeeds.
-
Open Job Output and copy
function_ocid.
Register the function in Workload Factory
-
Return to the Add link page.
-
Under Link registration, paste the function OCID (
ocid1.fnfunc.oc1…). -
Select Add.
Other ways to apply the same template
Use these only if you are not using Resource Manager from the Codebox.
Terraform CLI
-
Create a folder.
-
Copy or download OCI Terraform from the Codebox (
main.tf) into that folder. -
From the folder:
terraform init terraform plan terraform apply
-
Copy
function_ocidfrom the apply output and continue with [Register the function](#3-register-the-function-in-workload-factory).
OCI CLI
Use the OCI CLI tab in the Codebox to download the zip file, create the Resource Manager stack, then run plan, and apply jobs.
The link appears in your Links list.
To remove the function, delete the link in Workload Factory, then destroy the Resource Manager stack (or run terraform destroy).
The link appears in your Links list.
To remove the function, delete the link in Workload Factory, then destroy the Resource Manager stack (or run terraform destroy).
Associate an existing link with an OCI NetApp Storage Service system
After you create a link, associate it with one or more OCI NetApp Storage Service systems.
-
Select the menu
, Workloads > Storage. -
Select OCI NetApp Storage Service > Inventory.
-
Select the actions menu of the storage pool to associate a link with, and then select Associate link.
-
Verify the network identifier (subnet name or OCID and CIDR).
-
Select Associate an existing link.
-
Select the link name.
-
Choose the authentication method:
-
Workload Factory: enter the ONTAP admin user name and password.
-
OCI secret management - OCI Vault Key: use when the link function was deployed with Vault support. Enter the vault secret OCID.
-
-
Select Apply.
Workload Factory associates the link with the OCI NSS system. You can perform advanced ONTAP operations.