Chapter 13 · Multitenant Architecture: CDBs, PDBs, Services, Cloning, and Lifecycle

Resource Management, Isolation, Storage, Security, and Operational Boundaries Across PDBs

Separate what a PDB isolates from what remains CDB/instance shared, including memory, CPU, redo, undo mode, services, storage, common privileges, keystores, lockdown profiles, and licensed Resource Manager controls.

Advanced120–140 minutesIsolation-boundary inventory labDatabase Resource Manager is not available in FreeLockdown/resource-plan changes are optional/design-onlyLast reviewed: August 2026

Learning outcomes

ServiceHub and an analytics PDB share one CDB. The analytics workload consumes CPU and temporary space, while an application administrator assumes that “different PDB” means different instance memory, redo logs, OS identity, and patch cycle. Multitenant isolation is substantial but not absolute. Effective consolidation design distinguishes per-PDB namespaces/resources from CDB/instance/storage layers that remain shared.

01

Classify instance/CDB resources that remain shared versus PDB-local namespaces and storage.

02

Inspect local-vs-shared undo mode and explain its operational impact.

03

Use services, local users/roles, storage metadata, and CON_ID as practical isolation controls/evidence.

04

Introduce PDB lockdown profiles and shared-identity risks without changing a production security policy in a lab.

05

Respect the current licensing boundary that Database Resource Manager is unavailable in Oracle AI Database Free.

Generation-time baseline and entitlement boundary

Mandatory work targets Oracle AI Database Free 26ai, reviewed against RU 23.26.3, SQL Developer 26.2, and SQLcl 26.2.1. The August 2026 Licensing Information manual lists Oracle Multitenant as included in Free with a maximum of 16 PDBs, although the practical number can be lower because Free is capped at 2 foreground CPU cores, 2 GB RAM, and 12 GB user data. Free permits one installation per logical environment and receives no Oracle patches or Support service requests. The course baseline CDB is FREE and the default application PDB/service is FREEPDB1. Administrative PDB lifecycle commands require root/PDB-specific administrative privileges; application SQL remains in FREEPDB1 or an explicitly created disposable PDB.

1. PDB isolation is logical/administrative, not a separate instance

Layer Typically PDB-scoped Typically CDB/instance shared
Identity/objects Local users/roles, schemas, object namespace Common users/roles and root administration
Storage PDB datafiles/tablespaces, temp configuration, quotas Control files, online redo logs, Oracle home/filesystem capacity
Undo Own undo in local-undo mode Can be shared when CDB is configured for shared undo
Memory/processes PDB session/workload consumption and some PDB parameters One instance SGA/background processes and host CPU/RAM
Networking PDB-associated services Listener/host/network stack
Patching SQL patch completion/status can be container-sensitive Oracle home binary patch level shared by CDB

A runaway workload in one PDB can therefore consume resources needed by another unless the offering/topology provides and configures appropriate controls.

2. Local undo is an isolation and lifecycle decision

sql · verify actual undo mode from root
ALTER SESSION SET CONTAINER=CDB$ROOT;SELECT property_name,property_valueFROM database_propertiesWHERE property_name='LOCAL_UNDO_ENABLED';SELECT con_id,tablespace_name,contents,statusFROM cdb_tablespacesWHERE contents='UNDO'ORDER BY con_id,tablespace_name;

In local undo, every PDB has its own undo tablespace for each instance where needed. It improves isolation and enables/streamlines operations such as hot clone, relocation, unplug, and PDB point-in-time recovery. In shared undo, the CDB's active undo contains records for multiple PDBs, which changes recovery mechanics.

3. Redo, control files, SGA, and background processes remain CDB/instance concerns

PDB transactions generate redo into the CDB's redo stream. The CDB shares control files and the database instance's System Global Area (SGA) and background-process architecture. PDBs are not separate operating-system database instances just because they expose separate services.

sql · map sessions/services to containers
SELECT con_id,name,open_mode,total_sizeFROM v$containersORDER BY con_id;SELECT name,pdb,network_nameFROM v$servicesORDER BY name;SELECT  con_id,  COUNT(*) AS sessionsFROM v$sessionWHERE type='USER'GROUP BY con_idORDER BY con_id;

Session counts are concurrency evidence, not CPU attribution. For precise resource governance/diagnostics, use mechanisms supported and licensed for the target offering.

4. Storage boundaries still meet at the same host/filesystem

sql · root view of per-container tablespace/datafile allocation
SELECT con_id,tablespace_name,contents,statusFROM cdb_tablespacesORDER BY con_id,tablespace_name;SELECT con_id,file_id,tablespace_name,bytes,maxbytes,autoextensibleFROM cdb_data_filesORDER BY con_id,tablespace_name,file_id;

A PDB can have its own datafiles and storage limits, but all files can still compete for the same physical filesystem/ASM disk group/container volume. A per-PDB autoextend policy cannot create capacity that the shared storage does not have.

5. Security isolation requires more than separate local users

Use local application identities and narrow grants. Common users, powerful administrative privileges, shared OS identities, network-capable packages, directory paths, keystore design, and external procedures can cross PDB assumptions if not controlled deliberately.

A PDB lockdown profile is a multitenant security mechanism that can restrict statements, features/options, packages, and related operations in a PDB. Profiles are created in root/application root and enabled with PDB_LOCKDOWN. The setting takes effect without an instance restart, but it is a security policy change and should be tested like one.

sql · mandatory read-only lockdown inventory
SELECT name,value,ispdb_modifiableFROM v$parameterWHERE name='pdb_lockdown';SELECT profile_name,rule_type,rule,clause,statusFROM dba_lockdown_profilesORDER BY profile_name,rule_type,rule;

If your Free installation or privileges do not expose the dictionary view, record that limitation; do not grant broad privileges just to make the query succeed.

6. Database Resource Manager is a licensed/offering boundary here

Oracle Database Resource Manager can allocate CDB resources among PDBs and then consumer groups within a PDB. CDB plans can use shares/utilization/parallel limits; PDB plans manage workloads inside their PDB. However, the current 26ai licensing matrix marks Database Resource Manager = N for Oracle AI Database Free. Therefore this course does not create/enable resource plans in the mandatory Free lab.

sql · design/read-only evidence; do not enable a plan on Free
SELECT name,valueFROM v$parameterWHERE name='resource_manager_plan';-- On an entitled deployment, a DBA might inspect:SELECT plan,pluggable_database,shares,utilization_limit,parallel_server_limitFROM dba_cdb_rsrc_plan_directivesORDER BY plan,pluggable_database;
No noisy-neighbor performance claim from Free

Free's two-core/two-GB cap is useful for learning container visibility, not for deriving production PDB resource-share values. Resource plans require an offering where Database Resource Manager is available.

7. Deliberately wrong: assume separate PDB means separate redo/SGA/patching

This mistake produces false failure-domain assumptions. A CDB-level instance crash, storage exhaustion, binary patch outage, or shared listener problem can affect multiple PDBs. The repair is to document each dependency layer and decide whether consolidation meets the required blast radius, maintenance window, and regulatory separation.

8. Mandatory isolation inventory lab

sql · one-page multitenant boundary card
SELECT SYS_CONTEXT('USERENV','CON_NAME') AS current_container FROM dual;SELECT property_name,property_valueFROM database_propertiesWHERE property_name='LOCAL_UNDO_ENABLED';SELECT con_id,name,open_mode,total_sizeFROM v$containersORDER BY con_id;SELECT name,pdbFROM v$servicesORDER BY name;SELECT name,valueFROM v$parameterWHERE name IN (  'resource_manager_plan',  'pdb_lockdown',  'db_create_file_dest')ORDER BY name;

9. Production judgment

Consolidate only after mapping shared failure/resource/security dependencies. PDBs are strong administrative and data namespaces, not separate instances. Use local users/services/storage limits, local undo where operationally appropriate, lockdown profiles where supported and justified, and Resource Manager only on entitled offerings. Test cross-PDB privilege and OS/storage paths explicitly.

No mandatory setting is changed in this lesson. Lesson 5 applies the same scope discipline to maintenance and recoverability: binaries are CDB-home level, SQL patch application can be PDB-sensitive, and RMAN can back up or recover selected PDBs under exact prerequisites.

Check your understanding

  1. Do two PDBs have separate SGAs?
  2. What operational benefit does local undo provide?
  3. Can separate PDB datafiles still exhaust the same filesystem?
  4. Is Database Resource Manager available in current Oracle AI Database Free?
  5. What does a lockdown profile control?
Review the answers

No. PDB workloads run inside the same database instance and share its SGA/background-process architecture.

It gives each PDB its own undo and improves isolation/operations such as hot clone, relocation and PDB PITR.

Yes. Logical per-PDB file ownership does not isolate underlying host/ASM/container storage capacity.

No. The August 2026 26ai licensing matrix marks Database Resource Manager unavailable in Free.

It restricts selected operations/features/options/packages for users in a PDB, providing an additional multitenant security boundary.

Authoritative references

Keep knowledge open

Help the academy stay free and grow.

If these tutorials save you time, a small donation supports new lessons, technical review, diagrams, examples, and long-term maintenance.

ETHEthereum / ERC-20 only
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0

Send only Ethereum or ERC-20 compatible assets to this address.