Managed Oracle Database Free
Understand the standalone Oracle Free runtime, TCPS, schema quotas and SCN-based recovery, with Enterprise limits.
Unavailable; recovery acceptance is incomplete. Oracle Database Free has development evidence for standalone lifecycle, application binding and certificate renewal. It remains unavailable until the exact release source passes its required recovery checks. Enterprise and Data Guard have a separate source implementation. Their runtime gate stays closed until the hardened controller and a licensed customer image pass native acceptance. Passing the Free tests does not open that gate.
Editions and images#
Oracle Database Free is proprietary, free-to-use software. It is not open source.
Hakopod's standalone implementation uses the full Oracle Database Free 26ai image,
version 23.26.3.0, pinned to an immutable multi-platform digest. The full image
includes SQL*Plus, Data Pump and wallet tooling; the Lite image omits tools needed
by this implementation. The platform version in a database revision is 23.26.
Free is limited by Oracle to two CPUs, 2 GB of database memory and 12 GB of user data. The container reservation is larger because it also runs the listener and management tools. These upstream limits do not become larger when a user reserves a larger container. Free does not provide a Data Guard cluster.
The Enterprise configuration contract accepts an explicit image with a SHA-256 digest, an optional registry-credential reference scoped to the database's project and environment, and license confirmation. It never asks for a license document, registry password or token inside database TOML. The runtime currently rejects Enterprise deployments: validating an image reference does not prove image compatibility, entitlement or failover safety. RAC, Active Data Guard, TDE and licensed monitoring packs are separate support decisions.
Standalone configuration#
schema_version = 1
name = "orders-oracle"
engine = "oracle"
version = "23.26"
mode = "standalone"
replicas = 0
shards = 1
cpu = "1"
memory = "4Gi"
storage_gib = 10
[tls]
mode = "required"
[oracle]
edition = "free"
The shared API and CLI parse the same versioned configuration. API creation still checks authorization, scope, allocation and runtime availability. Enterprise image, edition and resource changes cannot bypass the reviewed migration restrictions.
Each standalone database owns one StatefulSet, a data volume and a backup-staging volume of the same size. Initialization may take several minutes. Failed or partial initialization retains its data for inspection; the startup script must not silently replace it. Hosted placement uses an authorized sandboxed worker.
The APP schema's quota is the smaller of 10 GiB and the data volume minus 8 GiB. At the 10 GiB minimum volume, APP can use 2 GiB; the remaining space is reserved for system tablespaces, undo, redo and temporary work. This is a schema quota, not a guarantee that system activity can never exhaust a volume. Diagnostics use a bounded 512 MiB temporary volume and are not a persistent log archive. Writable-layer and temporary storage have an aggregate 2 GiB container limit.
Connections and trust#
The private endpoint uses Oracle TCPS on port 2484 and the FREEPDB1 service.
Applications receive the APP schema account. The independent CDB administrator
and wallet credentials remain inside the database namespace. The application
cannot create users, change instance settings or read Oracle's credential tables.
Use a client that verifies both the CA and hostname. Download the database's
public CA through /api/v1/databases/{id}/trust or mount the trust supplied by a
managed binding. A connection URL alone does not install a private CA in a driver.
SQL*Plus clients need a wallet containing that public CA and server-name matching
enabled. They do not need the server's wallet or private key.
The Go runtime uses go-ora/v3 with an explicit TLS configuration. Version 2.9.0
failed authentication against this pinned 26ai image in native testing. Version
3.0.1 passed repeated application connections with FAST LOGIN=false; every
physical connection negotiates afresh. Keep SSL=enable and SSL VERIFY=true,
load the public CA into the client's root pool, and set the endpoint hostname.
Never use InsecureSkipVerify or replace hostname verification with encryption
alone.
Readiness verifies native database role, PDB state, supported version, authenticated APP access and the issued certificate actually served. It also checks that plaintext access is rejected. Metrics use ordinary dynamic performance views; they do not query AWR, ASH, ADDM or separately licensed diagnostic packs.
Backup and recovery contract#
The initial implementation captures the APP schema with Data Pump and a flashback SCN. It is not a physical RMAN backup, archived-redo recovery or point-in-time recovery. A SYS-owned DDL guard coordinates with the capture session before the SCN is selected. Application schema changes temporarily fail with a retry message while a capture holds that guard; ordinary data changes continue against the SCN-based snapshot. Native acceptance has verified that guard, ordinary DML during capture, and cancellation after a server-side Data Pump job starts.
The bounded archive carries version, edition, source identity, revision, SCN, dump size and a SHA-256 checksum. The managed-backup service provides the outer encryption. Restore stages and validates the whole input before database writes, requires a separate empty target with the same version and edition, closes application ingress and replaces the target pod to revoke existing sessions. Import runs as APP with temporary directory access. Failed job cleanup or grant revocation prevents a successful recovery result. Access stays closed until the completed recovery has been inspected.
Native acceptance covered binary and Unicode data, concurrent DDL, corrupted input, empty-target checks, cancellation, revoked sessions, independent source and target writes, cleanup and inspection gates. Production qualification must also cover the supported workload sizes and schema features.
Current evidence and remaining work#
On September 29, the standalone development test passed native initialization, authenticated reads and writes, required TCPS, plaintext refusal, schema privilege boundaries and ordered deletion. The development environment is one physical VM; it establishes no multi-zone or multi-provider availability guarantee.
Subsequent runs verified fresh-target initialization and hardened replacement startup. The script waits for the image's completion hook and data marker before configuring TCPS and APP. It tolerates an already-stopped listener during wallet replacement but still requires the new listener to start successfully. Native renewal loaded a new server identity and issuer with zero container restarts, preserved data, and kept old-CA overlap working.
The final September 29 native recovery run passed in 617.44 seconds, including owned resource cleanup. It verified binary and Unicode data, a view, sequence, stored function and trigger, separate source/target writes, session revocation, incomplete-archive and nonempty-target refusal, and inspection-gated ingress. It also passed the public-CA-only application wallet, unbound-service denial, binding revocation, SCN/DDL guard and cancellation cleanup checks.
An earlier import failed with ORA-31685 because account grants, default roles
and quotas are separate metadata paths from object grants. Capture and import
now exclude each of those account-policy paths. The native test used a different
source quota and confirmed that restore retained the target's managed quota and
restricted application privileges. Diagnostics expose only error codes and
known metadata categories, without SQL, credentials or object names.
The passing log is work/database-enterprise/oracle-recovery-live-v6.log.
This is development acceptance, not a production release or proof of recovery
for every Oracle schema feature and workload size.
Enterprise and Data Guard still require an accepted image/runtime contract, scoped image-pull credentials, role-aware routing, transport/apply observation, split-brain fencing, switchover/failover, reinstatement and native recovery tests. Free standalone testing cannot validate those Enterprise behaviors.
References: Oracle Database Free, Oracle container image sources, and go-ora.
Source and related guides#
The implementation is in the public Hakopod repository. In the source checkout, read docs/managed-oracle.md with its corresponding engine runtime and acceptance tests. Release source references must match the version you install. Return to the database catalog to compare availability.