Chapter 13 · Multitenant Architecture: CDBs, PDBs, Services, Cloning, and Lifecycle
PDB Cloning, Snapshot/Refresh Concepts, Unplug/Plug, Relocation, and Portability
Compare full clone, snapshot copy, refreshable clone, unplug/plug, and relocation by file ownership, storage, downtime, compatibility, undo, service, and topology requirements before moving any production PDB.
Learning outcomes
ServiceHub needs a copy of production-like metadata for a test, then later must move a tenant to another CDB. “Clone the PDB” can mean a full file copy, a storage snapshot copy, a refreshable copy fed by redo, or the first phase of relocation. Unplug/plug is different again: it separates PDB metadata/files from one CDB and validates them against another. Choosing the mechanism requires storage, undo, downtime, compatibility, service, encryption, and topology evidence.
Compare full clone, snapshot copy, refreshable clone, unplug/plug, and relocate by mechanism and dependencies.
Check local undo and OMF/storage state before attempting a hot local clone.
Use DBMS_PDB.DESCRIBE/CHECK_PLUG_COMPATIBILITY and PDB_PLUG_IN_VIOLATIONS as portability gates.
Explain why snapshot copy depends on storage capabilities and why refreshable/relocate workflows require database-link/topology planning.
Keep the mandatory Free path non-destructive while providing an optional local clone only when SH13LAB/capacity prerequisites are satisfied.
Mandatory work targets Oracle AI Database Free 26ai, reviewed against RU 23.26.3, SQL Developer 26.2, and SQLcl 26.2.1. The August 2026 Licensing Information manual lists Oracle Multitenant as included in Free with a maximum of 16 PDBs, although the practical number can be lower because Free is capped at 2 foreground CPU cores, 2 GB RAM, and 12 GB user data. Free permits one installation per logical environment and receives no Oracle patches or Support service requests. The course baseline CDB is FREE and the default application PDB/service is FREEPDB1. Administrative PDB lifecycle commands require root/PDB-specific administrative privileges; application SQL remains in FREEPDB1 or an explicitly created disposable PDB.
1. Full clone creates a new independent PDB copy
A normal
CREATE PLUGGABLE DATABASE ... FROM source_pdb
copies source PDB files to create an independent clone. If the
source is open read/write, local undo mode is required for
supported hot-clone workflows. If local undo is unavailable, use
the documented source open-mode requirements rather than
improvising.
ALTER SESSION SET CONTAINER=CDB$ROOT;SELECT property_name,property_valueFROM database_propertiesWHERE property_name='LOCAL_UNDO_ENABLED';SELECT value AS db_create_file_destFROM v$parameterWHERE name='db_create_file_dest';SELECT name,open_mode,total_sizeFROM v$pdbsWHERE name IN ('SH13LAB','FREEPDB1');
DBCA-created modern CDBs normally use local undo, but verify the actual property. Local undo means each PDB has its own undo tablespace and enables operations such as hot cloning/relocation more cleanly.
2. Optional local clone of the small disposable PDB
Run this only if Lesson 2 created a small SH13LAB,
OMF is configured, LOCAL_UNDO_ENABLED=TRUE, and the
Free 12-GB data limit/storage headroom are safe.
CREATE PLUGGABLE DATABASE sh13cloneFROM sh13lab;ALTER PLUGGABLE DATABASE sh13clone OPEN READ WRITE;ALTER PLUGGABLE DATABASE sh13clone SAVE STATE;SELECT pdb_name,status,source_pdb_nameFROM dba_pdbsWHERE pdb_name='SH13CLONE';SELECT name,open_modeFROM v$pdbsWHERE name='SH13CLONE';
The clone receives a new identity/GUID and default service. A successful clone does not prove that external connection pools or service naming are conflict-free across hosts/CDBs.
3. Snapshot copy is storage-dependent copy-on-write—not a generic fast clone
SNAPSHOT COPY uses storage snapshots so Oracle does
not copy every source block initially. Current SQL syntax
requires supported snapshot-capable storage configurations such
as Oracle ACFS or Direct NFS arrangements, with additional rules
depending on CLONEDB. Snapshot-copy clones depend
on the source/snapshot relationship and have restrictions such
as not being unplug-able.
CREATE PLUGGABLE DATABASE test_snapFROM source_pdbSNAPSHOT COPY;
The current licensing matrix separately lists PDB Snapshot Carousel as unavailable in Free. Do not equate every syntax containing the word snapshot with an entitlement to automated snapshot-carousel functionality.
4. Refreshable clones replay source redo and are normally read-only
A refreshable PDB is created from a remote source over
a database link with REFRESH MODE MANUAL or a timed
interval. Refresh applies source changes accumulated since the
last refresh; the refreshable clone is opened read-only and must
be closed for refresh. This is a topology workflow, not a second
same-process Free database shortcut.
CREATE PLUGGABLE DATABASE servicehub_refreshFROM servicehub_prod@prod_root_linkREFRESH MODE EVERY 60 MINUTES;ALTER PLUGGABLE DATABASE servicehub_refresh CLOSE;ALTER PLUGGABLE DATABASE servicehub_refresh REFRESH;ALTER PLUGGABLE DATABASE servicehub_refresh OPEN READ ONLY;
The current licensing matrix says Refreshable PDB switchover is not available in Free. Also, Free permits only one installation per logical environment, so a two-CDB test requires separate logical environments if you use Free.
5. Unplug/plug separates metadata/files from CDB membership
Unplug writes PDB metadata to XML (or archive workflows) after the required close/state preparation. Plugging into a target CDB must pass compatibility checks covering versions, options/components, character sets, patch state, encryption/keystore details, and other constraints.
BEGIN DBMS_PDB.DESCRIBE( pdb_descr_file => '/u01/app/oracle/oradata/sh13lab.xml', pdb_name => 'SH13LAB' );END;/
The path must be writable/readable by the Oracle database OS account and appropriate for your platform/container mount. Do not copy this Linux-style path blindly to Windows or an Oracle container with different mounts.
SET SERVEROUTPUT ONDECLARE l_ok BOOLEAN;BEGIN l_ok := DBMS_PDB.CHECK_PLUG_COMPATIBILITY( pdb_descr_file => '/u01/app/oracle/oradata/sh13lab.xml', pdb_name => 'SH13LAB' ); DBMS_OUTPUT.PUT_LINE( 'compatible=' || CASE WHEN l_ok THEN 'YES' ELSE 'NO' END );END;/SELECT name,cause,type,status,message,actionFROM pdb_plug_in_violationsWHERE name='SH13LAB'ORDER BY time,line;
A TRUE result is an important prerequisite, not
proof that copy/move/NOCOPY file placement, services, TDE keys,
backup catalog, network routing, or application cutover are
correct.
6. Relocation combines remote clone, synchronization, and source removal
RELOCATE moves a PDB from a source CDB to a target
CDB using a database link. The source can remain read/write
during much of the operation; local undo and target/source
prerequisites matter. The target CDB needs
CREATE PLUGGABLE DATABASE, the link
identity/privileges must be correct, and service/start-state
planning is part of cutover.
Relocation needs two CDBs plus networking/database-link/storage planning. The mandatory Free lab therefore models its prerequisites rather than pretending one Free installation is two independent CDBs.
7. Deliberately wrong: plug first, investigate violations later
Ignoring compatibility and patch warnings can leave a PDB unable
to open normally or requiring upgrade/datapatch remediation
during the outage. The repair is to generate/validate the
descriptor in advance, review
PDB_PLUG_IN_VIOLATIONS, verify target
release/patch/options/TDE/storage/service assumptions, and run a
rehearsal using a disposable copy.
8. Optional cleanup
ALTER SESSION SET CONTAINER=CDB$ROOT;ALTER PLUGGABLE DATABASE sh13clone CLOSE IMMEDIATE;DROP PLUGGABLE DATABASE sh13clone INCLUDING DATAFILES;
9. Production judgment
Use a full clone for independent copies, snapshot copy only when
storage and lifecycle dependencies are acceptable, refreshable
clones for lagged read-only copies with remote topology,
unplug/plug for portability, and relocate for planned CDB-to-CDB
movement. Record source/target CDB version, RU,
COMPATIBLE, local-undo mode, character set,
options/components, TDE/keystore mode, storage type, service
names, file paths, and rollback.
No clone/relocation command is required for the mandatory path beyond metadata/compatibility design. Lesson 4 turns to runtime isolation: a PDB is an administrative/security boundary, but CPU, memory, redo, instance processes, and some identities/resources remain shared at the CDB/host layer.
Check your understanding
- What additional condition is important for cloning a source PDB while it is open READ WRITE?
- What does SNAPSHOT COPY depend on?
- What does DBMS_PDB.CHECK_PLUG_COMPATIBILITY prove?
- Why is relocation not a single-Free-instance lab?
- What does a refreshable clone consume from the source?
Review the answers
Local undo mode is required for supported hot-clone/read-write source workflows.
Supported snapshot-capable storage/filesystem configuration and continued source/snapshot dependencies.
It checks whether the described PDB is compatible with the target CDB; it does not validate every file/network/application cutover detail.
Relocation requires source and target CDBs/database-link topology, while Free allows only one installation per logical environment.
It refreshes by applying source changes/redo accumulated since the prior refresh.
Authoritative references
- CREATE PLUGGABLE DATABASE — clone, snapshot copy, refresh and relocate syntax/prerequisites
- Cloning a PDB — full and refreshable clone workflows
- Relocating a PDB — relocation topology and privileges
- Plugging In an Unplugged PDB — compatibility checking and plug lifecycle
- PDB_PLUG_IN_VIOLATIONS — compatibility warning/error evidence