Chapter 13 · Multitenant Architecture: CDBs, PDBs, Services, Cloning, and Lifecycle
Resource Management, Isolation, Storage, Security, and Operational Boundaries Across PDBs
Separate what a PDB isolates from what remains CDB/instance shared, including memory, CPU, redo, undo mode, services, storage, common privileges, keystores, lockdown profiles, and licensed Resource Manager controls.
Learning outcomes
ServiceHub and an analytics PDB share one CDB. The analytics workload consumes CPU and temporary space, while an application administrator assumes that “different PDB” means different instance memory, redo logs, OS identity, and patch cycle. Multitenant isolation is substantial but not absolute. Effective consolidation design distinguishes per-PDB namespaces/resources from CDB/instance/storage layers that remain shared.
Classify instance/CDB resources that remain shared versus PDB-local namespaces and storage.
Inspect local-vs-shared undo mode and explain its operational impact.
Use services, local users/roles, storage metadata, and CON_ID as practical isolation controls/evidence.
Introduce PDB lockdown profiles and shared-identity risks without changing a production security policy in a lab.
Respect the current licensing boundary that Database Resource Manager is unavailable in Oracle AI Database Free.
Mandatory work targets Oracle AI Database Free 26ai, reviewed against RU 23.26.3, SQL Developer 26.2, and SQLcl 26.2.1. The August 2026 Licensing Information manual lists Oracle Multitenant as included in Free with a maximum of 16 PDBs, although the practical number can be lower because Free is capped at 2 foreground CPU cores, 2 GB RAM, and 12 GB user data. Free permits one installation per logical environment and receives no Oracle patches or Support service requests. The course baseline CDB is FREE and the default application PDB/service is FREEPDB1. Administrative PDB lifecycle commands require root/PDB-specific administrative privileges; application SQL remains in FREEPDB1 or an explicitly created disposable PDB.
1. PDB isolation is logical/administrative, not a separate instance
| Layer | Typically PDB-scoped | Typically CDB/instance shared |
|---|---|---|
| Identity/objects | Local users/roles, schemas, object namespace | Common users/roles and root administration |
| Storage | PDB datafiles/tablespaces, temp configuration, quotas | Control files, online redo logs, Oracle home/filesystem capacity |
| Undo | Own undo in local-undo mode | Can be shared when CDB is configured for shared undo |
| Memory/processes | PDB session/workload consumption and some PDB parameters | One instance SGA/background processes and host CPU/RAM |
| Networking | PDB-associated services | Listener/host/network stack |
| Patching | SQL patch completion/status can be container-sensitive | Oracle home binary patch level shared by CDB |
A runaway workload in one PDB can therefore consume resources needed by another unless the offering/topology provides and configures appropriate controls.
2. Local undo is an isolation and lifecycle decision
ALTER SESSION SET CONTAINER=CDB$ROOT;SELECT property_name,property_valueFROM database_propertiesWHERE property_name='LOCAL_UNDO_ENABLED';SELECT con_id,tablespace_name,contents,statusFROM cdb_tablespacesWHERE contents='UNDO'ORDER BY con_id,tablespace_name;
In local undo, every PDB has its own undo tablespace for each instance where needed. It improves isolation and enables/streamlines operations such as hot clone, relocation, unplug, and PDB point-in-time recovery. In shared undo, the CDB's active undo contains records for multiple PDBs, which changes recovery mechanics.
3. Redo, control files, SGA, and background processes remain CDB/instance concerns
PDB transactions generate redo into the CDB's redo stream. The CDB shares control files and the database instance's System Global Area (SGA) and background-process architecture. PDBs are not separate operating-system database instances just because they expose separate services.
SELECT con_id,name,open_mode,total_sizeFROM v$containersORDER BY con_id;SELECT name,pdb,network_nameFROM v$servicesORDER BY name;SELECT con_id, COUNT(*) AS sessionsFROM v$sessionWHERE type='USER'GROUP BY con_idORDER BY con_id;
Session counts are concurrency evidence, not CPU attribution. For precise resource governance/diagnostics, use mechanisms supported and licensed for the target offering.
4. Storage boundaries still meet at the same host/filesystem
SELECT con_id,tablespace_name,contents,statusFROM cdb_tablespacesORDER BY con_id,tablespace_name;SELECT con_id,file_id,tablespace_name,bytes,maxbytes,autoextensibleFROM cdb_data_filesORDER BY con_id,tablespace_name,file_id;
A PDB can have its own datafiles and storage limits, but all files can still compete for the same physical filesystem/ASM disk group/container volume. A per-PDB autoextend policy cannot create capacity that the shared storage does not have.
5. Security isolation requires more than separate local users
Use local application identities and narrow grants. Common users, powerful administrative privileges, shared OS identities, network-capable packages, directory paths, keystore design, and external procedures can cross PDB assumptions if not controlled deliberately.
A PDB lockdown profile is a multitenant
security mechanism that can restrict statements,
features/options, packages, and related operations in a PDB.
Profiles are created in root/application root and enabled with
PDB_LOCKDOWN. The setting takes effect without an
instance restart, but it is a security policy change and should
be tested like one.
SELECT name,value,ispdb_modifiableFROM v$parameterWHERE name='pdb_lockdown';SELECT profile_name,rule_type,rule,clause,statusFROM dba_lockdown_profilesORDER BY profile_name,rule_type,rule;
If your Free installation or privileges do not expose the dictionary view, record that limitation; do not grant broad privileges just to make the query succeed.
6. Database Resource Manager is a licensed/offering boundary here
Oracle Database Resource Manager can allocate CDB resources among PDBs and then consumer groups within a PDB. CDB plans can use shares/utilization/parallel limits; PDB plans manage workloads inside their PDB. However, the current 26ai licensing matrix marks Database Resource Manager = N for Oracle AI Database Free. Therefore this course does not create/enable resource plans in the mandatory Free lab.
SELECT name,valueFROM v$parameterWHERE name='resource_manager_plan';-- On an entitled deployment, a DBA might inspect:SELECT plan,pluggable_database,shares,utilization_limit,parallel_server_limitFROM dba_cdb_rsrc_plan_directivesORDER BY plan,pluggable_database;
Free's two-core/two-GB cap is useful for learning container visibility, not for deriving production PDB resource-share values. Resource plans require an offering where Database Resource Manager is available.
7. Deliberately wrong: assume separate PDB means separate redo/SGA/patching
This mistake produces false failure-domain assumptions. A CDB-level instance crash, storage exhaustion, binary patch outage, or shared listener problem can affect multiple PDBs. The repair is to document each dependency layer and decide whether consolidation meets the required blast radius, maintenance window, and regulatory separation.
8. Mandatory isolation inventory lab
SELECT SYS_CONTEXT('USERENV','CON_NAME') AS current_container FROM dual;SELECT property_name,property_valueFROM database_propertiesWHERE property_name='LOCAL_UNDO_ENABLED';SELECT con_id,name,open_mode,total_sizeFROM v$containersORDER BY con_id;SELECT name,pdbFROM v$servicesORDER BY name;SELECT name,valueFROM v$parameterWHERE name IN ( 'resource_manager_plan', 'pdb_lockdown', 'db_create_file_dest')ORDER BY name;
9. Production judgment
Consolidate only after mapping shared failure/resource/security dependencies. PDBs are strong administrative and data namespaces, not separate instances. Use local users/services/storage limits, local undo where operationally appropriate, lockdown profiles where supported and justified, and Resource Manager only on entitled offerings. Test cross-PDB privilege and OS/storage paths explicitly.
No mandatory setting is changed in this lesson. Lesson 5 applies the same scope discipline to maintenance and recoverability: binaries are CDB-home level, SQL patch application can be PDB-sensitive, and RMAN can back up or recover selected PDBs under exact prerequisites.
Check your understanding
- Do two PDBs have separate SGAs?
- What operational benefit does local undo provide?
- Can separate PDB datafiles still exhaust the same filesystem?
- Is Database Resource Manager available in current Oracle AI Database Free?
- What does a lockdown profile control?
Review the answers
No. PDB workloads run inside the same database instance and share its SGA/background-process architecture.
It gives each PDB its own undo and improves isolation/operations such as hot clone, relocation and PDB PITR.
Yes. Logical per-PDB file ownership does not isolate underlying host/ASM/container storage capacity.
No. The August 2026 26ai licensing matrix marks Database Resource Manager unavailable in Free.
It restricts selected operations/features/options/packages for users in a PDB, providing an additional multitenant security boundary.
Authoritative references
- Database Concepts — CDB/PDB architecture, local undo and shared-instance concepts
- Managing Resources with Database Resource Manager — CDB/PDB resource-plan mechanics
- PDB_LOCKDOWN — lockdown-profile parameter scope
- Security Guide — PDB Lockdown Profiles — multitenant security restrictions
- Licensing Information — Database Resource Manager and Multitenant offering matrix