1Z0-1123-25 exam dumps

1Z0-1123-25 practice question 93 of 150

Oracle Cloud Infrastructure 2025 Migration Architect Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1123-25 Question 93

Select 2

You are migrating an on-premises container-based application to Oracle Cloud Infrastructure (OCI). You decide to deploy your application on Oracle Container Engine for Kubernetes (OKE) and store the container images in Oracle Cloud Infrastructure Registry (OCIR). To ensure that your images can be securely pulled by OKE at deployment time, which two actions must you take?

  1. A

    Create a Docker registry secret within your OKE cluster that references your OCIR credentials.

  2. B

    Create an IAM policy allowing the OKE cluster� dynamic group to read from the OCIR repository in your tenancy.

  3. C

    Copy the images to an Object Storage bucket first, as OKE only supports deployments from Object Storage artifact URLs.

  4. D

    Manually install and authenticate Docker on each OKE worker node to pull the images directly from the command line.

Show answer and explanation

Correct answers: A, B

Explanation

To deploy containers from OCIR to OKE, you must configure image pull authentication and authorization. Creating a Docker registry secret in your OKE cluster ensures that the credentials for your private OCI Registry are securely stored. Additionally, an IAM policy must permit the OKE dynamic group to read from your tenancy� OCIR compartment. These steps follow OCI best practices for Kubernetes deployments, as detailed in the official OCI and OKE documentation.

  • A. Correct.

    Correct. In OKE, a Kubernetes secret is typically required to store credentials for pulling images from private OCI repositories. Without this secret, your cluster may not be able to authenticate and pull the private images.

  • B. Correct.

    Correct. You must define an IAM policy that grants the cluster's dynamic group permission to access your registry� repositories. This ensures OKE is authorized to pull images from OCIR during deployment.

  • C. Incorrect.

    Incorrect. OKE does not require you to store images in Object Storage, and it can directly pull images from OCIR if the proper credentials and IAM policies are in place.

  • D. Incorrect.

    Incorrect. Installing Docker on each OKE worker node manually is not necessary. OKE worker nodes already include the necessary container runtime to pull images when properly configured with credentials and IAM policies.

Timed practice exam

Take a 1Z0-1123-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam