Removing a Subcompartment from a Security Zone

When you remove a subcompartment from a security zone, Oracle Cloud Infrastructure no longer enforces security zone policies on the resources in the subcompartment.

Note

You can't remove the parent compartment that was used to create the security zone. You must delete the security zone.

When you remove a subcompartment from a zone, Cloud Guard creates a standard target for the subcompartment. The new target has the same detector recipes as the security zone target for the parent compartment, but it doesn't detect security zone policy violations. No changes are made to any of the existing Cloud Guard targets and detector recipes.

The following diagram illustrates the Cloud Guard configuration for a subcompartment that's removed from a security zone:


The parent compartment is in a security zone and one of the child compartments is not in a security zone. The parent compartment is associated with a security zone target in Cloud Guard, and the child compartment is associated with a standard target. The security zone target and the standard target are associated with the same detector recipes.

View full-size image.