Build Your First Globally Distributed Autonomous AI Database on OCI: A Console Walkthrough



What You Are Actually Creating

In the OCI Console, a Globally Distributed Autonomous AI Database is a single resource that holds the whole configuration: the nodes (shards), the catalog, the data distribution method, the replication method, connection details, and backup settings. You start from the service home page and select Create database.


Settings You Cannot Change

Two fields are fixed. Only Dedicated Infrastructure is supported as the deployment type, and only Transaction Processing is supported as the workload type. For the database version, you choose between 19c and 26ai.

The Big Decision: Distribution and Replication

This is the most important step, because the replication type is set once and cannot be changed later.

Three ways to distribute data

  • Automated: data is spread across nodes using partitioning by consistent hash, evenly and randomly.
  • User managed: you map data to specific nodes yourself. This suits cases where performance or regulation requires certain data on a particular node, and you want full control over moving it.
  • Multi-Level: you create several data spaces for different subsets of a table that is hash partitioned. A data space is a set of nodes holding a range or list of key values. The documentation says this gives better load balancing than User managed distribution.

Two ways to replicate

  • Raft: replication units made of chunks are distributed automatically across nodes. The system handles chunk assignment, movement, and balancing when you scale. User managed distribution is not available with Raft.
  • Data Guard: a node-level approach that creates a standby database for each node. You do not set it up in the initial deployment. You configure the replicas after the database is created.

The Catalog Comes Preconfigured

The catalog appears already filled in, and you can change it with Edit in the Actions menu. Raft does not apply to the catalog. Protect it by adding Data Guard replication after creation.

Locking It Down: Credentials and Encryption

You set an ADMIN password that can access every database in the configuration, including the catalog.

For encryption, you choose between OCI Vault Service and Oracle Key Vault. The rules depend on your distribution type:

  • With Automated distribution, all nodes share the same vault and key (OCI Vault) or the same OKV endpoint group name (Oracle Key Vault).
  • With User managed distribution, each node can use the same or different key details, and this is optional.
  • With Multi-Level distribution, all nodes within a data space share the same key details.

Oracle's guidance is simple: use OCI Vault if your nodes sit in fewer than three regions, and use Oracle Key Vault if they span three or more. You cannot switch between the two types once the database exists.

Network, Characters, and Ports

Pick the private endpoint you configured earlier. For character sets, AL32UTF8 is recommended by default, with AL16UTF16 as the national character set. Then enter the listener port, the local ONS port, and the remote ONS port. The remote ONS port and the TLS port must each be unique to this database. Do not reuse a number from another one until its delete operation has fully finished.

Optional Extras Under Advanced Options

You can pass settings to enable automatic backups to Object Store. You can also attach a network security group to the virtual cloud network that hosts the GSMs. The NSG must already exist.

Validate, Create, Wait

  1. Select Validate to run checks against your configuration.
  2. Fix any errors, then select Create.
  3. Watch the State column and the Work request tab for progress.
  4. Wait for the node status to show Available.

Expect a wait. Creation includes host procurement, software installation, and generating certificates for the GSMs.

One Warning to Remember

After creation, do not move the vaults and keys, or the database will stop working.

Quick Recap of the Permanent Choices

Replication type, encryption key type, and the dedicated infrastructure and transaction processing options are all fixed once set. Decide them on paper first, then build.

Post a Comment

Previous Post Next Post