ServiceNow Discovery • Oracle Cloud Infrastructure: OCI Discovery setup readiness, validation, API testing, and troubleshootingSummary<!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } :root { color-scheme:light; --ink:#18212f; --muted:#596579; --line:#dbe4f0; --page:#f3f6fb; --indigo:#312e81; --blue:#2563eb; --cyan:#0891b2; --green:#059669; --amber:#d97706; --red:#dc2626; } * { box-sizing:border-box; } html { scroll-behavior:smooth; } body { margin:0; padding:24px; background:radial-gradient(circle at top right,#e0f2fe 0,transparent 28%),var(--page); color:var(--ink); font-family:Inter,-apple-system,BlinkMacSystemFont,"Segoe UI",Arial,sans-serif; line-height:1.58; } a { color:#1d4ed8; text-underline-offset:2px; } .portal-tools { position:sticky; top:10px; z-index:20; max-width:1180px; margin:0 auto 14px; display:flex; gap:10px; align-items:center; padding:10px; border:1px solid rgba(203,213,225,.92); border-radius:14px; background:rgba(255,255,255,.92); box-shadow:0 8px 26px rgba(15,23,42,.10); backdrop-filter:blur(10px); } .portal-tools label { font-size:12px; font-weight:800; color:#475569; white-space:nowrap; } .portal-tools input { width:100%; padding:9px 12px; border:1px solid #cbd5e1; border-radius:9px; font:inherit; } .portal-tools button { padding:9px 12px; border:0; border-radius:9px; background:#312e81; color:#fff; cursor:pointer; } .kb-page { max-width:1180px; margin:0 auto; } .kb-hero { position:relative; overflow:hidden; } .kb-hero:after { content:""; position:absolute; right:-80px; bottom:-110px; width:280px; height:280px; border:38px solid rgba(255,255,255,.11); border-radius:50%; } .kb-badges { position:relative; z-index:1; } .kb-toc { box-shadow:0 10px 30px rgba(15,23,42,.05); } .kb-toc li { break-inside:avoid; margin:4px 0; } .kb-section { transition:opacity .2s ease,transform .2s ease; } .kb-section.hidden { display:none; } .kb-section-title { box-shadow:0 6px 20px rgba(49,46,129,.16); } .kb-panel { box-shadow:0 10px 28px rgba(15,23,42,.045); } .kb-panel h3 { margin:20px 0 8px; color:#1e3a8a; font-size:17px; } .kb-panel h3:first-child { margin-top:0; } .kb-panel h4 { margin:18px 0 8px; color:#334155; } .kb-panel p:first-child { margin-top:0; } .kb-panel p:last-child { margin-bottom:0; } .kb-card { padding:16px; border:1px solid var(--line); border-radius:10px; background:#fff; } .kb-card h3 { margin-top:0; } .kb-card ul { margin-bottom:0; padding-left:20px; } .kb-table-wrap { overflow-x:auto; margin:14px 0; border:1px solid #dbe4f0; border-radius:10px; } table { width:100%; border-collapse:collapse; font-size:13px; } th { padding:10px 12px; background:#334155; color:#fff; text-align:left; vertical-align:top; } td { padding:10px 12px; border-bottom:1px solid #e5e7eb; vertical-align:top; } tr:last-child td { border-bottom:0; } tr:nth-child(even) td { background:#f8fafc; } code { padding:1px 4px; border-radius:4px; background:#eef2f7; color:#0f3b62; font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace; font-size:.92em; overflow-wrap:anywhere; } pre { overflow:auto; padding:15px; border-radius:9px; background:#101827; color:#f8fafc; box-shadow:inset 0 0 0 1px #263244; } pre code { padding:0; background:transparent; color:inherit; white-space:pre; } details { margin:0 0 11px; border:1px solid #bfdbfe; border-radius:9px; overflow:hidden; background:#fff; } summary { cursor:pointer; padding:12px 15px; background:linear-gradient(90deg,#eff6ff,#f8fafc); color:#1e3a5f; font-weight:750; } details > div { padding:16px; border-top:1px solid #dbeafe; } .flow-node { min-width:135px; flex:1; display:flex; flex-direction:column; justify-content:center; gap:3px; padding:13px; border:1px solid #c7d2fe; border-radius:10px; background:linear-gradient(180deg,#eef2ff,#fff); text-align:center; } .flow-node span { font-size:11px; color:#64748b; } .flow-arrow { display:flex; align-items:center; color:#2563eb; font-size:24px; } .check { display:flex; align-items:flex-start; gap:9px; padding:12px; border:1px solid #dbe4f0; border-radius:9px; background:#fbfdff; } .check input { margin-top:5px; accent-color:#059669; } .steps li { margin:0 0 10px; padding-left:5px; } .trigger-map p { margin:7px 0; } .ladder-step { display:flex; flex-direction:column; align-items:center; gap:4px; padding:13px; border:1px solid #a5f3fc; border-radius:10px; background:linear-gradient(180deg,#ecfeff,#fff); text-align:center; } .ladder-step b { display:grid; place-items:center; width:28px; height:28px; border-radius:50%; background:#0891b2; color:#fff; } .decision-node { display:flex; flex-direction:column; gap:5px; padding:14px; border-top:4px solid #6366f1; border-radius:8px; background:#f8fafc; box-shadow:0 2px 10px rgba(15,23,42,.07); } .decision-node span { color:#64748b; font-size:12px; } .small { color:#64748b; font-size:12px; } .sources li { margin-bottom:6px; } .search-status { min-width:90px; color:#64748b; font-size:12px; text-align:right; } @media (max-width:760px) { body { padding:10px; } .kb-hero { padding:23px 19px !important; border-radius:13px !important; } .kb-hero h1 { font-size:27px !important; } .toc-grid { columns:1 !important; } .kb-grid.two,.kb-grid.three,.check-grid { grid-template-columns:1fr !important; } .kb-panel { padding:16px !important; } .kb-section-title { font-size:18px !important; } .portal-tools label,.search-status { display:none; } th,td { min-width:145px; } } @media print { body { background:#fff; padding:0; } .portal-tools { display:none; } .kb-section { break-inside:avoid; } details > div { display:block !important; } } Find in article 17 sections Clear ServiceNow Discovery • Oracle Cloud Infrastructure OCI Discovery setup readiness, validation, API testing, and troubleshooting A release-neutral, customer-safe handoff guide for preparing OCI, the MID Server, credentials, patterns, schedules, and CMDB validation—plus read-only Postman, Linux, CMD, PowerShell, and OCI CLI tests. Readiness and handoffs 19 primary/helper patterns MID-host API tests Contents Purpose and scopeHow OCI Discovery worksOwnership and handoffsReadiness gateServiceNow prerequisitesOCI IAM and credentialsMID, network, proxy, and timeService accounts and schedulePattern and API catalogCMDB outputs and operational tablesValidation and expected evidencePostman and MID-host API testingTroubleshooting by divergent layerEvidence package and securityAcceptance criteria and operationsAuthoritative sources 1. Purpose and scope Use this article before onboarding an OCI tenancy or when cloud CIs are missing. It defines what each team must supply, how to prove every layer, and what evidence is needed for a clean handoff. This is a readiness, validation, and troubleshooting guide—not a tenant-specific implementation script. Exact menus and content versions can change; use the current product documentation and the installed pattern content in the target instance as the final authority. Included Ownership, prerequisites, IAM, credentials, endpoints, schedule design, patterns, APIs, CMDB classes, validation, errors, and evidence. API diagnostics A safe test ladder using Postman plus commands executed from the MID host or its network context. Not included Write/delete cloud calls, customer secrets, fixed tenant policy text, database/GLAS discovery, guest-OS discovery, or custom pattern development. 2. How OCI Discovery works Schedulescope and cadence → ECC outputwork is queued → MID Serverruns patterns → OCI REST APIssigned read calls → ECC inputresults return → Pattern + IREidentify/reconcile → CMDBCIs and relations Cloud API discovery inventories OCI control-plane resources. It does not automatically inspect the operating system inside a compute instance. If guest-level details are required, create and operate a separate server discovery design with appropriate network paths and OS credentials. Triage rule: find the first layer whose expected evidence is absent. A successful Postman call from a laptop does not prove the MID can resolve, connect, trust, sign, or authorize the same OCI call. 3. Ownership and handoffs Team / roleOwnsMust provide before testAcceptance evidenceOCI tenancy / cloud platform ownerTenancy, compartments, regions, service inventoryTenancy OCID, root or scoped compartment OCID, target regions, realm, expected resource samplesSigned read-only API results match known OCI resourcesOCI IAM / securityUser, group, policy, API signing keyUser OCID, public-key upload, fingerprint, approved read policy, key rotation ownerNo unauthorized or over-privileged access; key provenance documentedNetwork / proxy / PKIDNS, TCP 443, proxy, TLS trust, NTPOCI endpoint allowlist or proxy path, trusted CA chain, time synchronizationTests pass from the MID host under the effective service contextServiceNow platform / Discovery adminApplications, credential, service account, MID, schedule, logsValidated Up MID with Cloud Management capability; credential and account linkage; schedule scopePattern chain completes, ECC returns, Discovery status closesCMDB / CSDM ownerCI classes, IRE, reconciliation, lifecycle and ownershipIdentification and reconciliation review; duplicate policy; data ownershipExpected CIs and relationships update without duplicatesOperations / supportMonitoring, rotations, failures, evidence retentionRunbook, alert routing, key-expiry owner, retest cadenceRepeat run succeeds and failure ownership is unambiguous 4. Readiness gate Do not begin production onboarding until every mandatory item is green. The boxes are a working checklist in the standalone portal; record durable approvals in the implementation record. Scope names the tenancy, compartment root, regions, realm, and expected resources. Dedicated OCI discovery user and API signing key are approved. Least-privilege read policy covers every enabled pattern API. Required ServiceNow applications/content are installed and current per support policy. MID is Up, validated, and has Cloud Management capability. DNS, TCP 443, proxy, TLS trust, and NTP pass from the MID host. Credential validates against the correct user, tenancy, key fingerprint, and private key. Service account uses the intended compartment OCID and realm-aware endpoint. Pilot region/compartment and known sample resources are agreed. IRE/reconciliation and duplicate handling are reviewed before bulk population. Evidence is redacted and excludes private keys, tokens, and full payloads with sensitive tags. Rollback/disable plan and operational owners are documented. 5. ServiceNow prerequisites RequirementWhy it is neededReadiness checkDiscovery entitlement and cloud discovery capabilityCreates schedules, launches patterns, and processes cloud results.Confirm entitlement and production support policy with the platform owner.Cloud Access InterfaceProvides cloud credential/account integration used by cloud discovery.Installed, active, and compatible with the other discovery content.Visibility ContentSupplies shared visibility and cloud-discovery content.No failed installs or skipped dependencies.CMDB CI Class ModelsSupplies target CI classes and model definitions.OCI/cloud target tables exist and are active.Discovery and Service Mapping PatternsSupplies OCI logical patterns, tag extensions, trigger rules, and updates.Current supported content is installed; customizations are reviewed separately.Discovery Admin Workspace cloud wizardGuides account validation, region selection, MID selection, and scheduling.Administrator can open the cloud discovery workflow and see OCI.discovery_admin or approved equivalentRequired for credential, account, and schedule administration.Use least privilege; separate setup rights from read-only operations. Update applications through the supported application lifecycle. Do not mix unsupported content levels or copy individual pattern records between instances. 6. OCI IAM and credential design Credential components ComponentExpected valueCommon failureTenancy OCIDThe target OCI tenancy identifier.Copied from another tenancy or truncated.User OCIDA dedicated non-human discovery user where organizational policy permits.User deleted, disabled, or in the wrong tenancy.Key fingerprintFingerprint of the public key uploaded to that OCI user.Fingerprint does not match the private key.RSA private keyCorresponding API signing private key, stored only in an approved secret boundary.SSH key used by mistake, encrypted key unsupported by the selected client, line breaks damaged, or key exposed.Compartment OCIDRoot or approved parent compartment used as the ServiceNow account scope.Region or tenancy name supplied instead of an OCID.Region and realmOCI region identifier and correct realm domain for commercial, government, or dedicated regions.Commercial endpoint suffix used for a different realm. Policy strategy ServiceNow documents a read-only baseline across the Oracle services queried by the installed OCI patterns. OCI policy verbs are cumulative: inspect lists metadata and read includes inspect plus get operations. A broad onboarding baseline may resemble the following, but the OCI IAM owner must tailor it to the approved scope and the exact quarterly pattern/API list: Allow group <DISCOVERY_GROUP> to inspect compartments in tenancy Allow group <DISCOVERY_GROUP> to read all-resources in tenancy Security control: the broad example is a diagnostic baseline, not a universal mandate. Reduce scope where supported, document any tenancy-wide reads, never grant write/manage solely for discovery, and revalidate every active pattern after tightening the policy. Place policies at the tenancy or parent compartment that can see the intended descendants.Remember that some identity/region enumeration is tenancy-scoped even when resources are compartment-scoped.For a zero-result response, prove the compartment, region, lifecycle state, pagination, and policy scope before assuming success.Rotate keys under change control and retest credential validation plus one known-resource API call. 7. MID Server, network, proxy, TLS, and time MID readiness Status is Up and Validated.Cloud Management capability is present.Service account can read its keystore/configuration and use the proxy.Capacity supports the selected compartment/region scope.Logs have sufficient retention for the pilot. Network readiness Forward DNS resolves every required regional service hostname.Outbound TCP 443 succeeds through the effective proxy path.TLS chain is trusted without bypassing verification.System clock is synchronized; OCI rejects materially skewed signed requests.No TLS interception breaks hostname/SNI or request signing behavior. Endpoint model Allow the regional services actually used by the installed patterns, not one fixed hostname. Build endpoints from the OCI realm and region: https://identity.<REGION>.<REALM_DOMAIN> https://iaas.<REGION>.<REALM_DOMAIN> https://database.<REGION>.<REALM_DOMAIN> Commercial OCI commonly uses the oraclecloud.com endpoint suffix; government and dedicated realms use different domain suffixes. Confirm the realm in Oracle's region/endpoint documentation and the ServiceNow OCI datacenter URL guidance. A browser test from an administrator workstation is not evidence of MID reachability. Execute network and signed API tests on the MID host under the same service-account, proxy, DNS, and trust context whenever possible. 8. OCI service account and discovery schedule Create or select the OCI credential. Supply the tenancy OCID, user OCID, key fingerprint, and matching RSA private key. Validate without displaying the private key.Create the OCI cloud service account. Use the intended root/parent compartment OCID as the account identifier and link the validated credential.Set the OCI datacenter endpoint. Use a realm-correct service endpoint for the chosen region. For example, ServiceNow documents commercial and government endpoint forms; do not transplant a commercial suffix into another realm.Validate and discover account structure. Confirm the master account, descendant compartments, and logical datacenters/regions appear.Select MID execution. Choose a specific qualified MID, a qualified cluster, or supported auto-selection. Only Up, validated Cloud Management MIDs should be eligible.Start with a pilot. Select one region and the smallest representative compartment scope with known compute, network, storage, and database samples.Set cadence and window. Avoid overlapping broad cloud runs; size by observed duration, API throttling, ECC volume, and MID capacity.Separate guest discovery. If OS-level inventory is required, design a distinct server schedule after cloud API discovery has established the compute CIs. UI note: older interfaces may not expose the same explicit MID selector. Use the current Discovery Admin Workspace cloud wizard where available. If no MID is offered, validate status and Cloud Management capability before treating it as a UI defect. 9. OCI pattern, API, and dependency catalog The baseline OCI inventory contains 17 functional discovery patterns. Current content also includes the newer Cloud OS Image and Cloud Hardware Type model patterns, tag extensions, and parsing utilities. Pattern names, endpoints, and classes can evolve; compare this map with the installed active pattern content and the current ServiceNow quarterly API spreadsheet. Observed trigger chain Service Account Validation → Sub Account Sub Account → Datacenter + Active Datacenters Active Datacenters → Autonomous DB, Availability Domain, Cloud Hardware Type, Cloud OS Image/Image, DB Home, Network, NIC Attachment, Storage Attachment, Storage Volume, Subnet, Virtual Machine Availability Domain → Fault Domain | DB Home → Exadata | NIC Attachment → NIC #Pattern / purposePrimary REST call familyPrimary CMDB targetDependency / expected result1Service Account ValidationGET /20160918/compartments/{id} or tenancy lookupcmdb_ci_cloud_service_accountProves credential and root account context; triggers Sub Account.2Sub AccountGET /20160918/compartments?compartmentId=...&accessLevel=ANY&compartmentIdInSubtree=truecmdb_ci_cloud_service_account, cmdb_key_valueEnumerates descendant compartments; triggers datacenter discovery.3DatacenterGET /20160918/regionscmdb_ci_oci_datacenterBuilds the region catalog and account relationships.4Active DatacentersGET /20160918/tenancies/{tenancyId}/regionSubscriptionscmdb_ci_oci_datacenterFinds subscribed regions; triggers regional resource patterns.5Autonomous DBGET /20160918/autonomousDatabases?compartmentId=...cmdb_ci_cloud_database, tagsRegional database endpoint; valid zero only if scope truly has no autonomous databases.6Availability DomainGET /20160918/availabilityDomains?compartmentId=...cmdb_ci_availability_zoneRequires valid compartment and region context; triggers Fault Domain.7DB HomeGET /20160918/dbHomes?compartmentId=...cmdb_ci_cmp_resourceProvides parent objects used by Exadata database discovery.8Exadata / database resourcesGET /20160918/databases?compartmentId=...&dbHomeId=...cmdb_ci_cloud_database, tagsRequires DB Home output and database read permission.9Fault DomainGET /20160918/faultDomains?compartmentId=...&availabilityDomain=...cmdb_ci_availability_zoneChild of Availability Domain.10Image / Cloud OS ImageGET /20160918/images?compartmentId=...cmdb_ci_os_template or cmdb_ci_cloud_os_image, tagsTarget model depends on completed image-model migration and active content.11Cloud Hardware TypeCompute shape/hardware enumerationcmdb_ci_cloud_hardware_typeCurrent model helper used by virtual-machine relationships.12NetworkGET /20160918/vcns?compartmentId=...cmdb_ci_network, tagsCreates VCN inventory and subnet parent relationships.13NIC AttachmentGET /20160918/vnicAttachments?compartmentId=...cmdb_ci_nic, endpoint relationsLinks VM, subnet, and VNIC; triggers per-VNIC lookup.14NICGET /20160918/vnics/{vnicId}cmdb_ci_nic, tagsRequires VNIC identifiers from attachments.15Storage AttachmentGET /20160918/volumeAttachments?compartmentId=...cmdb_ci_storage_volume, endpoint relationsLinks block volumes to compute instances.16Storage VolumeGET /20160918/volumes?compartmentId=...cmdb_ci_storage_volume, tagsRequires regional block-storage read scope.17SubnetGET /20160918/subnets?compartmentId=...cmdb_ci_cloud_subnet, tagsRelates subnet to VCN and regional datacenter.18Virtual MachineGET /20160918/instances?compartmentId=...cmdb_ci_vm_instance, image, zone, tagsRequires compute read access and correct region/compartment. Counting note: the table has 18 rows because the current Cloud Hardware Type helper is shown explicitly and the legacy/current image model is represented together. The functional workbook baseline remains 17 patterns; active current content commonly adds both Cloud OS Image and Cloud Hardware Type. Tag and utility content Supporting OCI content can include Autonomous DB Tags, Exadata DB Tags, Image Tags, NIC Tags, Network Tags, Storage Volume Tags, Sub Account Tags, Subnet Tags, VM Tags, Parse Tags, Parse definedTags Tags, and Set API and API Version. These extensions normalize free-form and defined tags into CMDB key/value data and centralize endpoint selection. A missing tag is therefore not always a failure of the parent resource pattern. 10. CMDB outputs and operational tables LayerImportant records/classesWhat to validateAccount and locationcmdb_ci_cloud_service_account, cmdb_ci_oci_datacenter, cmdb_ci_availability_zoneCorrect compartment hierarchy, subscribed regions, availability/fault domains, and account relationships.Compute and imagescmdb_ci_vm_instance, cmdb_ci_cloud_hardware_type, cmdb_ci_cloud_os_image or cmdb_ci_os_templateOCI identifiers, lifecycle state, shape/image links, region and compartment.Networkcmdb_ci_network, cmdb_ci_cloud_subnet, cmdb_ci_nic, endpoint relationship classesVCN → subnet → VNIC → VM relationships and IP data.Storagecmdb_ci_storage_volume, block-volume endpoint relationshipsVolume state, availability domain, and attachment to VM.Databasecmdb_ci_cloud_database, cmdb_ci_cmp_resourceAutonomous/Exadata resources, DB Home parentage, state and compartment.Tagscmdb_key_valueFree-form/defined tag key, value, source CI, and refresh behavior.Executiondiscovery_schedule, discovery_status, discovery_log, ecc_queue, ecc_agent, sa_patternSchedule launch, MID pickup, input return, pattern completion, and first error.CMDB governancecmdb_identifier, cmdb_identifier_entry, cmdb_reconciliation_definition, sys_object_sourceStable OCI identifiers, source ownership, precedence, and duplicate prevention. CMDB acceptance is relational. A count of VM records is insufficient. Validate account, region, zone, image/hardware, VCN, subnet, NIC, storage, database, and tag relationships for known samples. 11. Validation sequence and expected evidence GateActionPass evidenceIf absent1. MIDConfirm the selected MID is Up, validated, and Cloud Management capable.MID is eligible in the cloud schedule workflow.Fix MID/capability before OCI testing.2. NetworkResolve and connect to identity, compute/network, and database endpoints from MID.DNS answer, TCP 443 success, trusted TLS chain.Network/proxy/PKI owner.3. Signed identityList region subscriptions and get the root compartment.HTTP 200 and correct tenancy/region identifiers.Key, fingerprint, clock, user, realm, or identity policy.4. ScopeList compartments recursively and one known regional resource.Expected compartment and sample resource appear.Region, compartment, lifecycle, pagination, or policy scope.5. Account validationValidate ServiceNow credential and service account.Master account, subaccounts, and logical datacenters populate.Compare ServiceNow fields with the successful signed test.6. ECCRun a pilot schedule.Output work is consumed by MID and correlated input returns.Output ready suggests MID did not consume; inspect agent/selection/capacity.7. PatternReview Discovery status/log and pattern logs.Validation → subaccount → region → resources completes.Stop at the first failed parent pattern.8. CMDBCompare known resources and relations.Correct CIs update via IRE with source tracking and no duplicates.Review payload normalization, identifiers, reconciliation, and class model.9. RepeatabilityRun again after a safe OCI attribute change or agreed interval.Existing CI updates; no duplicate is created.IRE/source-key or scope drift. 12. Read-only API testing: Postman, MID shell, CMD, and PowerShell Guardrails: use GET/list operations only; never paste a private key, token, or unredacted response into a ticket; never disable TLS validation as a fix; and stop testing if the endpoint or account is not explicitly in scope. 1DNS 2TCP 443 3TLS trust 4Signed identity 5Scoped resource 6ServiceNow parity A. Postman—signed OCI API comparator Postman is optional and useful for isolating signing, authorization, and response structure. It is not an OCI Discovery prerequisite. For a result to prove the MID network path, run Postman on the MID host only if desktop tooling is permitted; otherwise prefer OCI CLI on the MID host. Recommended environment variables VariableExample formSecret?region<REGION>Norealm_domainoraclecloud.com or approved realm suffixNotenancy_ocid<TENANCY_OCID>Treat as sensitive configurationuser_ocid<USER_OCID>Treat as sensitive configurationkey_fingerprint<KEY_FINGERPRINT>Treat as sensitive configurationprivate_keyLocal secret variable or approved key referenceYes—never sync/share/exportcompartment_ocid<COMPARTMENT_OCID>Treat as sensitive configurationapi_version20160918 for the OCI APIs in these examplesNo Use a security-reviewed OCI Signature Version 1 pre-request signer that implements Oracle's documented RSA-SHA256 canonicalization. Do not reuse an AWS signer or an OAuth-only Identity Domains collection.For GET requests, sign at least (request-target), host, and date or x-date exactly as Oracle documents.Start with region subscriptions or compartment get, then list a known resource in one region/compartment.Assert HTTP 200, record the redacted opc-request-id, verify response schema/count, and compare identifiers with OCI Console and ServiceNow. GET https://identity.<REGION>.<REALM_DOMAIN>/20160918/tenancies/<TENANCY_OCID>/regionSubscriptions GET https://identity.<REGION>.<REALM_DOMAIN>/20160918/availabilityDomains?compartmentId=<URL_ENCODED_COMPARTMENT_OCID> GET https://iaas.<REGION>.<REALM_DOMAIN>/20160918/instances?compartmentId=<URL_ENCODED_COMPARTMENT_OCID> Interpretation: HTTP 200 with an empty array proves authentication and authorization for that call, but it does not prove the expected resources were in the chosen region/compartment or returned after pagination/filtering. B. Linux or UNIX on the MID host—network and TLS nslookup identity.<REGION>.<REALM_DOMAIN> curl --silent --show-error --output /dev/null --write-out 'HTTP %{http_code}\n' \ "https://identity.<REGION>.<REALM_DOMAIN>/20160918/regions" openssl s_client \ -connect identity.<REGION>.<REALM_DOMAIN>:443 \ -servername identity.<REGION>.<REALM_DOMAIN> \ -verify_return_error An unsigned OCI request may return 401. That can prove DNS/TCP/TLS and endpoint reachability, but it does not validate the RSA key, fingerprint, user, policy, region scope, or ServiceNow credential. C. Windows CMD on the MID host—network and TLS nslookup identity.<REGION>.<REALM_DOMAIN> curl.exe -sS -o NUL -w "HTTP %{http_code}\n" "https://identity.<REGION>.<REALM_DOMAIN>/20160918/regions" If curl.exe is not approved or installed, use the PowerShell checks below. A TCP success alone does not prove certificate trust or signed API authorization. D. Windows PowerShell on the MID host—network and TLS $OciHost = "identity.<REGION>.<REALM_DOMAIN>" Resolve-DnsName $OciHost Test-NetConnection -ComputerName $OciHost -Port 443 try { Invoke-WebRequest -Uri "https://$OciHost/20160918/regions" -Method Get -UseBasicParsing } catch { $_.Exception.Response.StatusCode.value__ } Do not add callbacks that ignore certificate validation. If the host uses an outbound proxy, test with the same proxy configuration and service identity used by the MID. E. OCI CLI on the MID host—preferred signed fallback The OCI CLI uses the same API signing model and is the most practical command-line comparator when approved. Protect the CLI config/private key and use a temporary diagnostic profile with minimum permissions. oci iam region-subscription list \ --tenancy-id <TENANCY_OCID> \ --profile <PROFILE> \ --region <HOME_REGION> oci iam compartment get \ --compartment-id <COMPARTMENT_OCID> \ --profile <PROFILE> \ --region <HOME_REGION> oci iam compartment list \ --compartment-id <ROOT_COMPARTMENT_OCID> \ --compartment-id-in-subtree true \ --access-level ANY \ --all \ --profile <PROFILE> oci compute instance list \ --compartment-id <COMPARTMENT_OCID> \ --region <REGION> \ --all \ --profile <PROFILE> oci network vcn list \ --compartment-id <COMPARTMENT_OCID> \ --region <REGION> \ --all \ --profile <PROFILE> Use oci raw-request only when a service-specific CLI command is unavailable and the exact ServiceNow endpoint needs comparison: oci raw-request \ --http-method GET \ --target-uri "https://identity.<REGION>.<REALM_DOMAIN>/20160918/availabilityDomains?compartmentId=<URL_ENCODED_COMPARTMENT_OCID>" \ --profile <PROFILE> \ --region <REGION> On Windows CMD or PowerShell, call the same commands as oci.exe. In PowerShell, variables may be used safely: $Region = "<REGION>" $Compartment = "<COMPARTMENT_OCID>" oci.exe iam availability-domain list --compartment-id $Compartment --region $Region --profile "<PROFILE>" oci.exe compute instance list --compartment-id $Compartment --region $Region --all --profile "<PROFILE>" F. Result capture template FieldCaptureExecution pointMID hostname alias and OS; never expose public/customer hostname in a public KB.Effective contextMID service identity or approved test identity; proxy path.EndpointService, region, realm domain, API version; redact compartment identifiers where required.TimeUTC timestamp and clock/NTP status.ResultHTTP status, OCI error code, redacted opc-request-id, result count, known sample present yes/no.ComparisonOCI Console count, CLI/Postman count, ServiceNow pattern count, CMDB count. 13. Troubleshooting by first divergent layer No ECC output?schedule/scope Output stays ready?MID selection/consumption No OCI response?DNS/proxy/TLS/time OCI error?signing/IAM/scope API good, CMDB wrong?pattern/IRE/reconciliation No MID appears in the OCI schedule Likely layer: MID eligibility. Confirm the MID is Up, validated, has Cloud Management capability, and is allowed by the selected application/service. Check cluster membership and capability synchronization. Older schedule interfaces can differ; use the current cloud wizard before concluding the picker is defective. ECC output remains ready Likely layer: MID did not consume the work. Verify the selected agent, MID service status, instance connectivity, queue backlog, capability, and whether the job targets another MID/cluster. Do not interpret an input queue record in ready using the same rule; direction and topic matter. DNS failure, connection timeout, or proxy refusal Likely layer: network. Test each actual identity, compute/network, and database regional endpoint from the MID service context. Confirm proxy authentication, no restrictive PAC behavior, and egress to the correct realm domain. TLS handshake, hostname, or certificate-path failure Likely layer: PKI/trust or interception. Validate SNI hostname, full chain, expiration, trust store, and proxy inspection. Do not disable verification. Import only organization-approved CA material into the correct runtime trust boundary. HTTP 400: cannot parse, missing, or invalid parameter Likely layer: request construction. Check API version, path, URL encoding, compartment OCID, region-specific parameters, query spelling, and signer canonicalization. With raw requests, query order/encoding must match what was signed. HTTP 401 NotAuthenticated Likely layer: signing. Compare user OCID, tenancy OCID, public-key fingerprint, private key, signing algorithm/headers, endpoint host, and system time. OCI can reject requests when client time differs materially from server time. An unsigned reachability test is expected to fail authentication. HTTP 403 NotAuthorized, NotAllowed, or home-region error Likely layer: IAM or region. Check group membership, policy placement/inheritance, verb/resource family, compartment scope, and home-region requirements for identity operations. Reproduce the exact call with the same user—not an administrator. HTTP 404 NotAuthorizedOrNotFound Likely layer: ambiguous resource visibility. OCI intentionally combines not-found and unauthorized outcomes for some calls. Confirm OCID, resource lifecycle, region, compartment, and read policy without assuming the resource is absent. HTTP 429 TooManyRequests Likely layer: throttling/concurrency. Reduce overlapping schedules and scope, use supported retry/backoff behavior, review MID concurrency, and stagger regions/compartments. Do not retry in a tight custom loop. HTTP 431 or request header too large Likely layer: proxy/header/signing construction. Inspect added proxy headers, authorization size, duplicate headers, and client implementation. Reproduce with OCI CLI to isolate the custom signer. HTTP 5xx or OCI service unavailable Likely layer: provider/transient service or endpoint. Record UTC time and opc-request-id, test a second read-only endpoint, use bounded retry, and check OCI service health. A repeatable 5xx on one request may still indicate invalid regional routing or service state. Signed API returns 200 but an empty array Likely layer: scope rather than transport. Compare region, compartment parent, recursive behavior, lifecycle state, filters, and pagination with a known resource in OCI Console. A valid empty result is possible and should be documented, not treated automatically as failure. Account validates but no regions/datacenters appear Likely layer: region subscription or refresh. Test region-subscription API, confirm realm/home region, refresh/revalidate the account, and inspect timeout. Large account/member/LDC discovery can outlast the watcher timeout; change any timeout only after measuring duration and MID health. Parent pattern fails and child resources are all absent Likely layer: trigger dependency. Service Account Validation must lead to Sub Account and active datacenters before regional child patterns run. Fix the first parent failure instead of testing every child class independently. Some resource families are missing while others populate Likely layer: service-specific IAM, endpoint, or pattern. Compare the missing pattern API with a same-user OCI CLI call; confirm the service endpoint is allowed and the installed pattern is active. Database calls commonly use a different regional hostname than compute/network calls. Resources exist but tags are missing Likely layer: tag extension or source data. Confirm free-form/defined tags exist on OCI, the relevant tag extension completed, parsing did not reject the structure, and cmdb_key_value source relationships are correct. API and pattern succeed but CIs are missing Likely layer: post-pattern/IRE. Inspect normalized pattern output, identification result, data-source/source-key, class existence, reconciliation rejection, and payload size. Preserve the first IRE error and a redacted minimal identifier set. Duplicate CIs or unexpected class/model after rerun Likely layer: identification/source drift or image migration. Compare OCI OCID/source key, identifiers, source precedence, legacy versus current image class, and whether an unsupported customization changed the pattern payload. Never bulk-delete duplicates before identifying the authoritative record and relationship impact. Discovery duration grows or schedules overlap Likely layer: scope/capacity. Measure compartment count, subscribed regions, ECC volume, API throttling, and MID worker utilization. Split scope or stagger cadence using supported schedule design, then validate completeness and relationships. 14. Evidence package and security controls Collect UTC test window and schedule name/aliasMID status, validation, capability, and effective proxyRegion, realm, compartment scope, expected sample countsCredential validation result without secret fieldsDNS/TCP/TLS and signed CLI/Postman result summaryHTTP status, OCI error code, redacted opc-request-idFirst failed pattern step and correlated ECC input/outputDiscovery status/log and representative CI/relationship comparison Never collect or publish RSA private key or exported Postman secret environmentPasswords, session tokens, auth headers, full signaturesUnredacted customer/tenant URLs or identifiers in a public articleFull payloads containing personal, confidential, or tag dataBroad screenshots when a cropped/redacted field is sufficientUnsupported bypasses such as disabling TLS verification Use stable aliases when sharing evidence externally. Retain a private mapping only inside the authorized customer case/change record. Rotate any key or token that is accidentally exposed. 15. Acceptance criteria and operational handoff One pilot region and compartment completes without unresolved error.Same-user signed API tests and ServiceNow results agree for known samples.Account, compartment, region, compute, network, storage, database, image/hardware, and tag relationships are reviewed.A second run updates existing CIs through IRE without new duplicates.Any valid zero-result pattern is documented with OCI Console evidence.Production cadence does not overlap and does not cause sustained throttling or MID backlog.Key rotation, policy review, application/content maintenance, failure alerting, and data-owner contacts have named owners.Rollback is defined: disable the schedule/credential linkage first; do not delete CMDB data until ownership and relationship impact are reviewed. Go-live decision: approve only when network, signing, IAM, scope, pattern execution, IRE, and CMDB relationship evidence all pass. Partial API success is not full discovery acceptance. 16. Authoritative sources ServiceNow Oracle Cloud Infrastructure DiscoveryCreate Oracle API credentialsCreate OCI service accountsCreate an OCI Discovery schedule in Discovery Admin WorkspaceCloud discovery workflow and account validationOCI access and permissions using policies Oracle Request signaturesRequired keys and OCIDsOCI API errorsOCI IAM policiesOCI regions and availability domainsOCI CLI raw-request Source links are intentionally public and authoritative. The article contains no customer, instance, case, credential, record-ID, or private-source references. Reviewed 30 August 2026; verify current product documentation before production change.