You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用代码中的配置对象替代OCI配置文件?

问题

Oracle官方文档指出,OCI SDK和CLI可通过配置文件或运行时声明配置来提供用户凭证、租户OCID等基础信息,也支持在代码中使用config object替代配置文件,但未找到相关示例。本人动态获取字符串形式的账户凭证,无配置文件,当前代码使用ConfigFileAuthenticationDetailsProvider,想了解如何改用配置对象实现。

原示例代码:

import * as identity from "oci-identity"
import common = require("oci-common")

interface Account {
  cliente: string,
  cloud_provider: {
    provider_name: string,
    tenancy: string,
    configFile: string,
    keyFile: string
  },
}

// Credentials
const provider: common.ConfigFileAuthenticationDetailsProvider = new common.ConfigFileAuthenticationDetailsProvider()
const client = new identity.IdentityClient({ authenticationDetailsProvider: this.provider });

const getTenancy = (accounts: Account) => {
  // Create a request and dependent object(s).
  const request: identity.requests.GetTenancyRequest = {
    tenancyId: id
  }

  // Send request to the Client.
  const response = await client.getTenancy(request)
}

const ids = ['id', 'id2', 'id3']

ids.forEach(id => {
  getTenancy(id)
})
解决方案

你可以使用OCI JS SDK提供的SimpleAuthenticationDetailsProvider类,直接通过传入配置参数(而非配置文件)来创建认证提供者。以下是调整后的实现:

1. 调整账户结构

首先更新Account接口,包含动态获取的核心凭证字段:

interface Account {
  cliente: string,
  cloud_provider: {
    provider_name: string,
    tenancy: string, // 租户OCID
    user: string,    // 用户OCID
    fingerprint: string, // 公钥指纹
    privateKey: string,  // 字符串形式的私钥内容
    region: string       // 区域标识,比如"us-phoenix-1"
  },
}

2. 动态创建认证提供者与客户端

不再依赖配置文件,为每个账户独立生成认证提供者和客户端实例:

import * as identity from "oci-identity"
import common = require("oci-common")

// 调整后的Account接口
interface Account {
  cliente: string,
  cloud_provider: {
    provider_name: string,
    tenancy: string,
    user: string,
    fingerprint: string,
    privateKey: string,
    region: string
  },
}

// 重构为支持异步的查询函数
const getTenancy = async (account: Account) => {
  // 基于动态凭证创建认证提供者
  const authProvider = new common.SimpleAuthenticationDetailsProvider(
    account.cloud_provider.tenancy,
    account.cloud_provider.user,
    account.cloud_provider.fingerprint,
    account.cloud_provider.privateKey,
    undefined, // 私钥有密码短语则传对应字符串,否则传undefined
    account.cloud_provider.region
  )

  // 创建当前账户的Identity客户端
  const client = new identity.IdentityClient({ authenticationDetailsProvider: authProvider })

  // 构造查询请求
  const request: identity.requests.GetTenancyRequest = {
    tenancyId: account.cloud_provider.tenancy
  }

  // 发送请求并处理结果
  try {
    const response = await client.getTenancy(request)
    console.log(`${account.cliente}的租户信息:`, response.tenancy)
    return response.tenancy
  } catch (err) {
    console.error(`${account.cliente}租户查询失败:`, err)
    throw err
  }
}

// 示例账户列表(替换为你的动态获取数据)
const accounts: Account[] = [
  {
    cliente: "Client1",
    cloud_provider: {
      provider_name: "OCI",
      tenancy: "ocid1.tenancy.oc1..xxx",
      user: "ocid1.user.oc1..xxx",
      fingerprint: "aa:bb:cc:dd:ee:ff:gg:hh",
      privateKey: "-----BEGIN RSA PRIVATE KEY-----\n...私钥内容...\n-----END RSA PRIVATE KEY-----",
      region: "us-phoenix-1"
    }
  },
  // 更多账户...
]

// 批量处理账户(用Promise.all确保异步请求正确执行)
const processAccounts = async () => {
  await Promise.all(accounts.map(account => getTenancy(account)))
}

processAccounts()

关键说明

  • SimpleAuthenticationDetailsProvider直接接收租户OCID、用户OCID、指纹、私钥字符串等核心参数,完全脱离配置文件依赖
  • 每个账户独立创建认证提供者和客户端,避免多账户操作时的凭证冲突
  • 原代码中forEach结合await无法正确处理异步逻辑,改用Promise.all确保所有请求能按预期执行并等待结果

内容的提问来源于stack exchange,提问作者Samuel A. Souza

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 06:20:29