Real OCI's Identity API includes Dynamic Groups (`/20160918/dynamicGroups`) — group membership matched by an instance/rule expression rather than explicit user assignment, used to grant IAM policies to compute instances/functions. Not modeled at all: the identity handler's own `Matches` test documents `"dynamic groups are not served"` (want: false), so the path isn't claimed and falls through to the dispatcher's generic plain-text 501 rather than an OCI-shaped JSON error.
Scope:
- New `DynamicGroupSpec`/`DynamicGroupInfo` types + CRUD in `providers/oci/identity/` (storage/CRUD only, mirroring Users/Groups — no matching-rule evaluation needed)
- New route family in `server/oci/identity/handler.go` under `/20160918/dynamicGroups`
- Note: policies can grant to dynamic groups, so `StatementPolicies.Evaluate` may need to know about dynamic-group membership — scope to CRUD-only first if policy evaluation against it is out of scope
Real OCI's Identity API includes Dynamic Groups (`/20160918/dynamicGroups`) — group membership matched by an instance/rule expression rather than explicit user assignment, used to grant IAM policies to compute instances/functions. Not modeled at all: the identity handler's own `Matches` test documents `"dynamic groups are not served"` (want: false), so the path isn't claimed and falls through to the dispatcher's generic plain-text 501 rather than an OCI-shaped JSON error.
Scope: