ORACLE CLOUD INFRASTRUCTURE (OCI)


OCI for SMBs


Use Case: OCI Basic Implementation


This is a classic 3-tier HA architecture in OCI Riyadh Region. Let me break it by flow:

1. The Container:

  • OCI Region (Riyadh) - your whole cloud boundary
  • VCN 10.0.0.0/16 - Your virtual data center. Like your own private network in Oracle.

2. Internet Access - Top part:

  • Internet Gateway - The door to Open Internet.
  • Public Subnet (10.0.1.0/24) - Public facing
    • Security List - Firewall for the subnet
    • Load Balancer - Distributes traffic to your 2 web servers. If one dies, other takes over.
  • Private Subnets:
    • Private Subnet 1 (10.0.2.0/24) + Private Subnet 2 (10.0.3.0/24) - Each in a different AD/Fault Domain for HA
    • Web Servers - Your app lives here. Not directly accessible from internet, only via Load Balancer.
    • Database - In even more private zone. Only web servers can talk to it.
  • Route Tables - Tell where traffic should go (e.g. 0.0.0.0/0 -> Internet Gateway)

3. Outbound only access:

  • NAT Gateway - Lets private servers go OUT to internet for updates/patches, but internet cannot come IN.
  • Service Gateway - Private, secure path from Database to Object Storage without going over internet. No public IP needed.

4. Hybrid - Bottom left:

  • Customer Data Center (172.16.0.0/16) on-premise
  • CPE - Customer equipment (your router)
  • DRG (Dynamic Routing Gateway) - Hub for connecting OCI to on-premise
  • DRG (Dynamic Routing Gateway) - Hub for connecting OCI to on-premise
  • Connection via Site-to-Site VPN / FastConnect - Encrypted private line from your office to OCI. So private instances can talk to OCI securely.

Traffic Flows:

  1. Users -> Internet Gateway -> Security List -> Load Balancer -> Web Server -> Database
  2. Database -> Service Gateway -> Object Storage (for backups)
  3. Private Subnet -> NAT Gateway -> Internet (for yum update)
  4. On-prem Private instances -> CPE -> FastConnect -> DRG -> Web Servers/Database










ORACLE CLOUD INFRASTRUCTURE (OCI)


OCI for Enterprises


Use Case: OCI Active-Active Cloud Database Implementation


This is a full Multi-Region High Availability + Disaster Recovery architecture on OCI — Primary in Riyadh, DR in Jeddah.

1. Overall Concept

Top box = OCI Region Riyadh (Primary). Bottom box = OCI Region Jeddah (DR). Same design duplicated to survive a full region failure. If Riyadh goes down, Jeddah takes over.

The IP ranges are intentionally non-overlapping:

  • Riyadh VCN: 10.0.0.0/16
  • Jeddah VCN: 192.168.0.0/16
  • Customer Data Center: 172.16.0.0/16 — so they can talk without conflict.

2. Inside Each Region (same on both sides)

A. VCN — Virtual Cloud Network
Your isolated data center in OCI.

B. Public Subnet (10.0.1.0/24 in Riyadh / 192.168.0.0/24 in Jeddah)

  • Internet Gateway: Entry/exit to Open Internet.
  • Security List: Virtual firewall. Controls what ports (80, 443) are allowed.
  • Load Balancer: Distributes user requests to both Web Servers. If one server dies, the other serves.

C. Private Subnets for Compute & Data

  • Private Subnet 1 (10.0.2.0/24) & Private Subnet 2 (10.0.3.0/24): — Each contains a Web Server. They are placed in different Availability Domains / Fault Domains.
  • Database: — In the most private subnet. Only Web Servers can access it. Not reachable from Internet.
  • Route Table: Rules like 0.0.0.0/0 -> Internet Gateway for public, 0.0.0.0/0 -> NAT Gateway for private.

D. Gateways for private access:

  • NAT Gateway: Allows Web Servers/Database to go OUT to internet for yum update, patches, but blocks incoming traffic.
  • Service Gateway: Private path to Oracle Service Network (OSN) -> Object Storage. This lets DB do RMAN backups to Object Storage without ever touching the internet. Secure and free.
  • Dynamic Routing Gateway (DRG): The hub for all private connectivity outside VCN.

E. Hybrid Connectivity (left side):

  • Customer Data Center (172.16.0.0/16) -> Private instances -> CPE (Customer Premises Equipment) — Your on-prem router.
  • Site-to-Site VPN / FastConnect: Encrypted private line from CPE to DRG. So your Dammam office can manage OCI servers as if they are local.

3. The Most Important Part — The Red Line Between Regions

This is an Active Data Guard between the two regions. Active means the DR database is available on read-only mode for business analytics queries.:

  • Database in Riyadh -> via red arrow labeled Active Data Guard.
  • How does it travel?DRG in Riyadh -> Remote Peering -> DRG in Jeddah.This is a private, high-speed backbone between OCI regions, not over public internet.
  • Riyadh is Primary (read-write), Jeddah is Standby (read-only, synced in near real-time). If Riyadh fails, you failover to Jeddah in minutes with zero data loss.

4. Traffic Flows

  • Normal User:Users -> Internet Gateway -> Security List -> Load Balancer -> Web Servers -> Database
  • Backup: Database -> Service Gateway -> Object Storage
  • Updates: Private Subnet -> NAT Gateway -> Open Internet
  • On-prem admin: Private instances -> CPE -> FastConnect -> DRG -> Web Servers / Database
  • Replication: Riyadh DB -> DRG -> Remote Peering -> DRG -> Jeddah DB

This is production-grade architecture for banking, e-commerce apps, anything that needs 99.95%+ uptime and compliance with Saudi data residency (Riyadh + Jeddah both inside KSA).