• /
  • EnglishEspañolFrançais日本語한국어Português
  • ログイン今すぐ開始

Uninstall the OCI integration

|View as Markdown (English)

Use this guide when you want to stop monitoring OCI with New Relic. It walks you through removing the resources the integration created in your OCI tenancy, then disconnecting your account from New Relic.

Delete your OCI resources before you unlink the account in New Relic. Unlinking deletes the record that stores your compartment and stack OCIDs, and you need those to find the resources.

Work through Uninstall metrics resources and Uninstall logs resources for whichever data types you instrumented.

Uninstall metrics resources

How you remove the metrics resources depends on how you created them. Select the option that matches your setup:

Uninstall logs resources

How you remove the logs resources depends on how you created them. Select the option that matches your setup:

Verify the logs teardown

To confirm a clean teardown, check both platforms:

  • No inbound log volume — in New Relic, open Logs and query oracle.tenantid = '<YOUR_TENANCY_OCID>'. Confirm no new log events arrive after your teardown timestamp.
  • Zero function invocations — in the OCI Console, under Metrics, confirm FunctionInvocationCount for the log forwarder function drops to 0.
  • No orphaned IAM resources — confirm no dynamic groups or policies referencing newrelic remain under Identity & Security.

Troubleshoot deprovisioning issues

If teardown doesn't go cleanly, match what you're seeing to one of these causes:

OCI Resource Manager returns a 409 conflict or active-lock error

Destroying the stack fails with HTTP 409 Conflict: Resource is being used by another process. This usually means an active Service Connector Hub batch or function execution is holding a lock on the underlying compartment or subnet resources. In Analytics & AI > Messaging > Service Connector Hub, select the connector and select Deactivate, wait 2–3 minutes for active function invocations to drain, then re-run the ORM Destroy action.

IAM policy deletion fails with AuthorizationFailed or a scope lock

The stack destroy fails when deleting oci_identity_policy or oci_identity_dynamic_group. This usually means the user or service principal running the destroy job lacks tenancy-level policy management rights — for example, policies deployed at the tenancy root require manage policies in tenancy. Confirm the user performing the teardown belongs to the Administrators group, or has these tenancy-root rights directly:

Allow group <Admin_Group> to manage policies in tenancy
Allow group <Admin_Group> to manage dynamic-groups in tenancy

If that doesn't resolve it, delete the policy statement manually in the OCI Console under Identity & Security > Identities > Policies, then re-run the destroy operation to clear the state.

You delete a stack, but New Relic still shows partial log volume or historical metric cards

This usually means a secondary connector — an audit connector or a manual log connector created outside the ORM stack — is still active. Run an OCI Search query across the tenancy to find active connectors:

query serviceconnector resources

Delete any connector whose target is Functions pointing to oci-log-forwarder.

A vault secret shows "Pending Deletion" instead of OCI removing it immediately

This is expected OCI behavior, not an error. OCI Vault secrets enforce a mandatory minimum 7-day retention period before hard deletion, to prevent accidental key destruction — but OCI disables the secret payload for reads as soon as you schedule deletion, so the log forwarder can't use it during the retention window either.

Verify nothing is left

Resources created by Resource Manager or Terraform carry a freeform tag. In the OCI Console, go to Governance & Administration > Search and run each of these structured queries:

query all resources where (freeformTags.key = 'newrelic-orm-terraform' && freeformTags.value = 'true')
query all resources where (freeformTags.key = 'newrelic-terraform' && freeformTags.value = 'true')

Two different tag keys are in use: the metrics and policy stacks tag newrelic-orm-terraform, and the logging stack tags newrelic-terraform. Run both, in every region you instrumented.

重要

An empty result doesn't mean your tenancy is clean. These queries won't find:

  • The workload identity federation resources from Step 6, which neither setup method tags.

  • Anything you created by hand, which carries no Terraform tag at all.

    Verify those by name instead, using Resource name reference.

Once your OCI resources are gone:

  1. Go to one.newrelic.com > All capabilities > Infrastructure > Oracle Cloud Infrastructure.
  2. Select your linked account.
  3. Select Unlink this account, then confirm.

This disables all OCI monitoring for that account and affects any dashboards, alerts, and tags that depended on it. You can't undo this.

Resource name reference

<id> is a short random suffix generated at deploy time, so match on the prefix rather than the full name. <prefix> defaults to newrelic.

Stack

Scope

Tag key

Resources

Policy

Tenancy

newrelic-orm-terraform

Compartment, KMS vault, KMS key, ingest secret, user secret, dynamic group, and the metrics, logs, and common policies — all named newrelic_*_ORM_DO_NOT_REMOVE_<id>

Metrics

Per region

newrelic-orm-terraform

Service Connector Hub, newrelic-<prefix>-<region>-metrics-function-app, newrelic-<prefix>-<region>-metrics-function, newrelic-<prefix>-<region>-metrics-vcn plus its NAT gateway, service gateway, NRMetricsInternetGateway, and private subnet

Logs

Per region

newrelic-terraform

Service Connector Hub, logging function application, logging function, log group, log, VCN, and gateways

Identity federation

Tenancy

none

newrelic-ida-app-orm, newrelic-token-exchange-app-orm, newrelic-wif-svc-user-orm, newrelic-svc-user-group-orm, newrelic-svc-user-policy-orm, and the identity propagation trust configurations

Copyright © 2026 New Relic株式会社。

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.