About Infrastructure Maintenance

Oracle periodically updates all Oracle-managed infrastructure components on Oracle Data Infrastructure Cloud@Customer.

Oracle uses automated processes that follow best practices to apply product fixes and security fixes. These updates help protect data and support database availability, integrity, security, and Oracle Cloud compliance requirements. Automated maintenance also reduces the effort required to maintain the infrastructure.

Oracle-managed components can include physical server hosts, storage, network cards, Integrated Lights Out Management (ILOM) interfaces, and control plane Proxy Services VMs.

Oracle performs quarterly maintenance every three months and can include product fixes, enhancements, and security fixes.

Oracle provides advance notice for scheduled maintenance except in rare exceptional circumstances. Oracle also provides notifications for corresponding recommended updates for VMs in the VM Cluster.

Oracle schedules maintenance to preserve service availability when possible. Some updates can temporarily affect performance and throughput while individual components are unavailable. For example, server patching typically requires a restart. Oracle restarts servers in a rolling sequence when possible so the service remains available during the update process. Each server remains unavailable for a short time during restart, which reduces overall service capacity. Plan mitigations when applications cannot tolerate restarts. For example, shut down an application during server patching.

Quarterly maintenance

Oracle minimizes the impact of quarterly maintenance on your applications by using rolling maintenance operations that preserve database availability throughout the update process. Applications designed for high availability automatically and transparently migrate database connections to available instances without disruption, eliminating the need to schedule downtime.

Oracle schedules maintenance according to Oracle-defined maintenance policies. You can reschedule maintenance if unexpected business requirements arise.

By default, infrastructure maintenance is performed using rolling updates, starting with servers and then updating the storage.

Servers are updated one at a time, with at most one server offline at any time. For each host, the VMs are shut down, the server is updated and restarted, and then the VMs are started, while other servers remain operational. This approach does not impact applications designed for high availability, but older applications that are not written to handle rolling instance restarts can be impacted. This process continues until both the servers are updated.

After server maintenance is complete, storage maintenance begins. Storage disks are updated one at a time. Patching storage has no effect on database availability and therefore has no impact on your applications. However, rolling storage maintenance can reduce I/O performance while a storage disk is offline (reducing available I/O capacity) and while it is resynchronized after it returns to service (with small overhead on the Data Infrastructure servers). Properly sizing the database and storage to accommodate the additional work on servers not under maintenance will minimize, or eliminate, any performance impact.

While databases are expected to be available during rolling maintenance, automated maintenance verifies that Oracle Clusterware is running but does not verify that all database services and Pluggable Databases (PDBs) are available after a server is brought back online. Availability of database services and PDBs after maintenance can depend on the service definition. For example, a database service configured with preferred and available nodes may be relocated during maintenance and may not automatically relocate back to its original node after maintenance completes. Oracle recommends reviewing the documentation on achieving continuous availability for your applications to reduce potential impact. By following the guidelines, the impact of infrastructure maintenance should be limited to minor service degradation as servers are updated sequentially.

Oracle recommends following Maximum Availability Architecture (MAA) best practices and using Data Guard to ensure the highest availability for critical applications. For databases with Data Guard enabled, Oracle recommends separating the maintenance windows for the Data Infrastructures running the primary and standby databases. You may also perform a switchover before maintenance on the Data Infrastructure hosting the primary database to avoid impact on your primary database during infrastructure maintenance.

Prechecks are performed on Oracle Data Infrastructure Cloud@Customer infrastructure components before the maintenance window begins to identify issues that could prevent maintenance from succeeding. The infrastructure and all components remain online during prechecks. An initial precheck runs approximately two weeks before maintenance starts, and another runs approximately 24 hours before maintenance starts. If prechecks identify an issue that requires rescheduling, a notification is sent to the users who have subscribed to notifications.

Minimizing Maintenance Windows