ORACLE CLOUD INFRASTRUCTURE (OCI)
OCI for Enterprises
Use Case: OCI Active-Active Cloud Database Implementation
This is a full Multi-Region High Availability + Disaster Recovery architecture on OCI — Primary in Riyadh, DR in Jeddah.
1. Overall Concept
Top box = OCI Region Riyadh (Primary). Bottom box = OCI Region Jeddah (DR). Same design duplicated to survive a full region failure. If Riyadh goes down, Jeddah takes over.
The IP ranges are intentionally non-overlapping:
- Riyadh VCN: 10.0.0.0/16
- Jeddah VCN: 192.168.0.0/16
- Customer Data Center: 172.16.0.0/16 — so they can talk without conflict.
2. Inside Each Region (same on both sides)
A. VCN — Virtual Cloud Network
Your isolated data center in OCI.
B. Public Subnet (10.0.1.0/24 in Riyadh / 192.168.0.0/24 in Jeddah)
- Internet Gateway: Entry/exit to Open Internet.
- Security List: Virtual firewall. Controls what ports (80, 443) are allowed.
- Load Balancer: Distributes user requests to both Web Servers. If one server dies, the other serves.
C. Private Subnets for Compute & Data
- Private Subnet 1 (10.0.2.0/24) & Private Subnet 2 (10.0.3.0/24): — Each contains a Web Server. They are placed in different Availability Domains / Fault Domains.
- Database: — In the most private subnet. Only Web Servers can access it. Not reachable from Internet.
- Route Table: Rules like 0.0.0.0/0 -> Internet Gateway for public, 0.0.0.0/0 -> NAT Gateway for private.
D. Gateways for private access:
- NAT Gateway: Allows Web Servers/Database to go OUT to internet for yum update, patches, but blocks incoming traffic.
- Service Gateway: Private path to Oracle Service Network (OSN) -> Object Storage. This lets DB do RMAN backups to Object Storage without ever touching the internet. Secure and free.
- Dynamic Routing Gateway (DRG): The hub for all private connectivity outside VCN.
E. Hybrid Connectivity (left side):
- Customer Data Center (172.16.0.0/16) -> Private instances -> CPE (Customer Premises Equipment) — Your on-prem router.
- Site-to-Site VPN / FastConnect: Encrypted private line from CPE to DRG. So your Dammam office can manage OCI servers as if they are local.
3. The Most Important Part — The Red Line Between Regions
This is an Active Data Guard between the two regions. Active means the DR database is available on read-only mode for business analytics queries.:
- Database in Riyadh -> via red arrow labeled Active Data Guard.
- How does it travel?DRG in Riyadh -> Remote Peering -> DRG in Jeddah.This is a private, high-speed backbone between OCI regions, not over public internet.
- Riyadh is Primary (read-write), Jeddah is Standby (read-only, synced in near real-time). If Riyadh fails, you failover to Jeddah in minutes with zero data loss.
4. Traffic Flows
- Normal User:Users -> Internet Gateway -> Security List -> Load Balancer -> Web Servers -> Database
- Backup: Database -> Service Gateway -> Object Storage
- Updates: Private Subnet -> NAT Gateway -> Open Internet
- On-prem admin: Private instances -> CPE -> FastConnect -> DRG -> Web Servers / Database
- Replication: Riyadh DB -> DRG -> Remote Peering -> DRG -> Jeddah DB
This is production-grade architecture for banking, e-commerce apps, anything that needs 99.95%+ uptime and compliance with Saudi data residency (Riyadh + Jeddah both inside KSA).