# CMDB-360 OCI Satellite — Frequently Asked Questions
# General
What is the CMDB-360 OCI Satellite?
The CMDB-360 OCI Satellite is a software component that provides visibility into cloud resources provisioned within an Oracle Cloud Infrastructure (OCI) tenancy or designated compartments. It regularly discovers and sends resource rosters to the CMDB-360 Base Station to aid in managing customer cloud assets.
Is any sensitive or proprietary asset data stored on the CMDB-360 Base Station?
No. Only simple, non-sensitive rosters of discovered cloud resources are recorded on the Base Station. Detailed asset information is streamed on-demand from the OCI Satellite to the Base Station and is never stored there permanently.
What are the core functions of the OCI Satellite?
The OCI Satellite performs three primary functions:
- Asset Discovery — Regularly discovers cloud resources within an OCI tenancy or compartment and sends non-sensitive resource details to the CMDB-360 Base Station.
- Metrics Collection — Collects and stores OCI resource metrics locally for up to one year, which can be displayed as charts and graphs in the CMDB-360 portal on demand.
- On-Demand Access — Provides the Base Station with on-demand access to detailed asset information without storing sensitive data outside the OCI tenancy.
What OCI resource types does the Satellite discover and manage?
The OCI Satellite manages the following resource types:
- Compute — Bare metal and virtual machines
- Databases — Oracle Database Service (DBaaS), Autonomous Database, and MySQL Service
- Networking — Virtual Cloud Networks (VCN) and Load Balancers
- Vulnerability Scanning Service
- Announcements
- Metrics
- Cost & Usage
Note
Discovery and access for any of these resource types can be disabled from the Satellite scheduler.
# Security & Permissions
What level of OCI permissions does the Satellite require?
The OCI Satellite only requires read-only permissions to gather all required CMDB details within a tenancy. You can grant full tenancy read-only access or customize policies to limit access to specific compartments and resource types.
Can I restrict the Satellite to only certain compartments?
Yes. You can fine-tune the OCI policies used by the Satellite to limit access to specific compartments and/or specific resource types. This applies whether you are using Instance Principals or a named user for authentication.
What are the firewall requirements for the OCI Satellite?
The Satellite only requires outbound HTTPS connectivity — no inbound ports need to be opened. Specifically:
- Inbound: None required. CMDB-360 and other systems never connect to the OCI Satellite.
- Outbound: HTTPS via TCP port 443 (may vary based on your Base Station configuration) to two destinations:
- The update/control server (typically
control.cmdb360.com:443) - Your CMDB-360 Base Station (typically
yourcompany.cmdb360.com:443)
- The update/control server (typically
# Deployment & Installation
What are the available deployment methods?
There are three ways to deploy the OCI Satellite:
-
OCI Marketplace (Recommended) — Deploy a pre-configured Oracle Linux 8.6+ ARM virtual machine directly from the OCI Marketplace. This is the simplest method and has been validated by Oracle Cloud.
-
Docker Image — Pull and run the public Docker image on any compute instance with Docker installed. See the Docker installation docs for details.
-
Manual Installer — Install on any Linux compute instance (Oracle Linux 8+/9 or Ubuntu 20.04/22.04, ARM or x86_64) using the graphical Installer or the AutoInstaller utility. Minimum requirements are 1 CPU, 4 GB RAM, and 20 GB disk.
Where should the OCI Satellite be deployed?
CMDB-360 recommends deploying the OCI Satellite within the target customer’s OCI tenancy to keep all sensitive data inside the tenancy boundary. However, it can be deployed in any OCI tenancy or other location (such as an on-premises datacenter), though some limitations may apply. See the deployment options documentation for details.
How are updates delivered to the OCI Satellite?
Updates are delivered through the internal Satellite update mechanism, regardless of the original deployment method. You may also redeploy from the OCI Marketplace or pull the latest Docker image to update, though re-configuration will be required in those cases.
# Configuration
What is involved in configuring the OCI Satellite?
Configuration is a two-step process:
-
Base Station Connection — Configure the Satellite to communicate with your CMDB-360 Base Station using the URL and Token values in the encrypted
config.ymlfile, managed by the AdminTool utility. See setup documentation. -
OCI REST API Access — Grant the Satellite credentials to query the OCI REST API, either via Instance Principals or a Named User. See the Configure OCI Access documentation.
Note: If you use the Installer or AutoInstaller utility, both configuration steps are completed automatically during installation.
What is the difference between Instance Principals and a Named User for OCI access?
-
Instance Principals (Preferred) — Uses OCI’s IAM feature to authorize the Satellite compute instance itself to call OCI APIs. Certificates are automatically created, assigned, and rotated — no credential distribution or manual rotation required.
-
Named User — A dedicated OCI user account is created and assigned to a group with the required read-only policies. This method is typically used when the Satellite is deployed outside of the customer’s OCI tenancy or when Instance Principals is not available.
Terraform templates are provided for configuring either method.
# Metrics & Monitoring
What compute metrics does the Satellite collect?
The OCI Satellite collects the following compute metrics from the OCI Metrics Service, stored locally for up to one year:
- CPU/Load: CPU Utilization %, Load Average
- Memory: Memory Utilization %, Memory Allocation Stalls
- Disk: Disk I/O Read/Write, Disk Bytes Read/Written
- Network: Network Bytes In/Out
Metrics can also be retrieved on-demand for any period up to the past 90 days.
How frequently does the Satellite perform asset discovery?
By default, the Satellite performs asset discovery hourly. This interval is configurable.
For additional documentation and support, visit www.cmdb360.com/docs.