1Z0-1123-25 exam dumps

1Z0-1123-25 practice question 95 of 150

Oracle Cloud Infrastructure 2025 Migration Architect Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1123-25 Question 95

Single answer

Your development team is setting up a private repository in Oracle Cloud Infrastructure Registry (OCIR) to store container images for an application that will be deployed on an OCI Container Engine for Kubernetes (OKE) cluster. They want the cluster to pull images from the private repository without requiring manual credentials each time. Which action must the team take to ensure automatic authentication between OKE and the private OCIR repository?

  1. A

    Invite each developer to generate their own Auth Token and store it as a Kubernetes secret in every namespace of the cluster

  2. B

    Configure an IAM policy that grants the OKE cluster� dynamic group or instance principal the right to read from the private OCIR repository

  3. C

    Enable VCN-native registry routing on the OKE cluster to bypass authentication for all private repositories in the same region

  4. D

    Configure a separate OCIR instance in each OKE node pool to synchronize container images with the private repository automatically

Show answer and explanation

Correct answer: B

Explanation

To allow Container Engine for Kubernetes (OKE) to pull images from a private Oracle Cloud Infrastructure Registry (OCIR) repository without manual credentials, you must configure a dynamic group for the worker nodes or instance principals and write a policy that allows read access to the specific repository or compartment. This approach provides secure, scalable authentication and authorization for all nodes in the cluster. Refer to Oracle� official documentation on how to configure IAM policies for dynamic groups and instance principals with OCI Container Engine for Kubernetes and OCIR.

  • A. Incorrect.

    Option 1: While using an Auth Token in a Kubernetes secret is a valid way for individual developers to push and pull images, it places the burden of manual credential management on every developer and enforces separate access secrets per namespace. This does not scale well for production environments and is not the recommended method for allowing the cluster itself to pull images automatically.

  • B. Correct.

    Option 2 (Correct): Defining an IAM policy and using a dynamic group or instance principal for the OKE nodes is the recommended and most secure method of granting the cluster access to pull images without manual intervention. By placing the OKE nodes in a dynamic group and writing a policy that allows that group to read from the repository, clusters can seamlessly authenticate to pull container images from private repositories in OCIR.

  • C. Incorrect.

    Option 3: There is no feature called 'VCN-native registry routing' that automatically bypasses authentication for private repositories. OKE still needs proper IAM-based authentication and authorization to pull images from a private repository.

  • D. Incorrect.

    Option 4: Simply creating a separate OCIR instance or replicating container images on each node pool is not a recognized or efficient approach. Images must still be pulled from a valid repository using the correct permissions. Having disparate repository copies also complicates lifecycle management of container images.

Timed practice exam

Take a 1Z0-1123-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam