Understand the free allowance
Learn how the account plan and free allowances fit together, and why this guide uses Pay As You Go. You’ll see how one 4-OCPU / 24-GB A1 stays within the monthly allowance, so you can choose your server with the costs understood.
Expand sectionCollapse section
Expect to upgrade out of the free plan to get an A1, then stay within the free tier. A1 capacity available to free-plan accounts can be difficult to obtain. For this guide’s audience, upgrading is the practical path; don’t build your plans around a free-plan slot opening soon. We’ll start with a standard Free Tier signup, then upgrade to Pay As You Go before creating the server.
The distinction is simple: the account plan determines whether you can use billable services; the free tier provides allowances that still apply after upgrading. OCI is Oracle Cloud Infrastructure—the collection of services you’ll manage. Oracle confirms that paid accounts have different capacity limits, although an upgrade does not guarantee an available machine. Oracle’s capacity and upgrade FAQ.
The training wheels are off: you could be billed. Upgrading authorizes paid usage. Eligible resources within the current free allowances still cost $0, and those allowances apply automatically each month. But this is not an account-wide spending cap: extra usage or paid services can charge your card.
| Name | What it means for you |
|---|---|
| Free plan | An account you have not upgraded. Paid usage is restricted, and free-plan A1 capacity can be difficult to obtain. |
| Free Trial | A temporary US$300 credit, valid for up to 30 days. A resource covered by trial credit can still be a paid resource. |
| Free tier / Always Free | Ongoing free allowances with limits, available on free and paid accounts. The setup here is designed to fit those allowances after the trial finishes. |
| Pay As You Go (PAYG) | The account upgrade recommended here. You keep free allowances and gain access to paid usage. There is no minimum spend; usage outside the allowances can be billed. |
For a standard Free Tier signup, eligible Always Free resources continue after the trial. You don’t need to activate every free service now to keep the option of using it later. There is no “unlock everything free forever” switch: services have their own limits, regional availability, and activity rules. Some special promotional trials have different end-of-trial terms; check the offer you accept.
Sources: Free Tier and trial expiry · Free Tier FAQ
The limits that matter for this server
| Resource | Current allocation |
|---|---|
| A1 processing | PAYG: 3,000 OCPU-hours/month, enough for 4 OCPUs continuously. Free-only: 1,500 OCPU-hours/month, enough for 2 continuously. |
| A1 memory | PAYG: 18,000 GB-hours/month, enough for 24 GB RAM continuously. Free-only: 9,000 GB-hours/month, enough for 12 GB continuously. |
| Boot + block volumes | 200 GB combined in the home region. |
| Volume backups | 5 total, combining boot and block backups. |
| Internet data sent out | 10 TB/month. |
| Virtual cloud networks | 2 on an Always Free-only account. |
Allocation sources: Always Free resources · Price list, including paid-tenancy A1 allowances. Recheck these before following the guide at a later date.
Why one 4-OCPU / 24-GB server fits
We’ll choose 4 OCPUs and 24 GB of RAM on PAYG. A1’s free allowance is a monthly budget of processing and memory time, measured in OCPU-hours and GB-hours. One OCPU allocated for one hour uses one OCPU-hour; one GB of RAM allocated for one hour uses one GB-hour. The meter counts the size allocated over time, even when the server is mostly idle.
| Resource | Monthly usage and PAYG free allowance |
|---|---|
| Processing | 4 × 744 = 2,976 OCPU-hours Free allowance: 3,000 OCPU-hours |
| Memory | 24 × 744 = 17,856 GB-hours Free allowance: 18,000 GB-hours |
Both fit, using 99.2% of their allowances in the longest month. Shorter months use less. The allowance is shared across A1 virtual machines, bare-metal servers, and container instances throughout your tenancy. Assume this server uses your A1 budget: creating another A1 draws from the same pool, and deleting one does not erase the hours already used that month.
Source for PAYG allowances and shared usage: Oracle price list. The figures above are this guide’s calculation for continuous operation.
Already running a 4/24 A1 on PAYG? If it is your only A1 usage, its processing and memory fit the currently published paid-account allowance. That allowance applies to paid tenancies without a signup-date condition; you do not need to rely on grandfathering. The smaller 2/12 figures elsewhere in Oracle’s documentation are explained in the source note.
Stay within the allowances and you won’t be charged. Oracle applies them automatically: you don’t renew them each month or shut this server down at night. With this configuration and no other A1 usage, its processing and memory fit every month’s current allowance. Keep total disks within 200 GB, volume backups within five, and outgoing traffic within 10 TB/month too. Before adding services or changing settings, check their separate limits. Keep all your usage eligible and within the current free allowances, and the bill stays at $0.
Where free ends
On PAYG, a larger server, extra disks, excess traffic, or another paid service can incur charges. Trial credit can temporarily hide those costs; a $0 payment during the trial is not proof that the setup fits ongoing free allowances. We’ll add a billing alert, but alerts do not switch resources off or cap the bill.
If you prefer to stay on the free-only plan: use 2 OCPUs / 12 GB instead, provided capacity is available. Running continuously for 31 days uses 1,488 OCPU-hours and 8,928 GB-hours, within that plan’s smaller allowance. You keep the restriction against paid usage, but may be unable to obtain an A1. Before trial expiry, bring the combined A1 usage within that allowance. Oracle warns that excess A1 allocation on an unupgraded account can result in all its A1 instances being disabled and later deleted.
Sources: A1 trial-expiry rules · Account upgrades · Budget alerts
Checkpoint: You understand that PAYG enables charges, while eligible usage inside its free allowances remains $0 automatically.
Get a few things ready
Gather your account details, check that your Linux computer can connect, and choose a safe place for your connection key. A little preparation now makes signup and your first login easier.
Expand sectionCollapse section
- Your Linux computer, a web browser, and a reliable Internet connection.
- An email address you check, your phone, accurate contact details, and a supported credit card or debit card that works like a credit card.
- A password manager or another safe place for account details and recovery information.
- Some uninterrupted time. You can pause between sections; account approval and available A1 capacity can take longer than the hands-on work.
Oracle uses the card for verification. Signup and upgrade can place temporary authorization holds; these are different from purchases. Once you upgrade, Oracle can also charge the card for billable usage. Prepaid, virtual, and PIN-only debit cards are not accepted under the current FAQ.
Open your computer’s applications menu and look for Terminal. Enter this and press Enter:
On your computer
ssh -V
A response containing OpenSSH means the connection tool is available. If it says “command not found,” install your distribution’s OpenSSH client. On Ubuntu or Debian, the command is sudo apt install openssh-client; other distributions use different package managers. Your computer does not have to use Ubuntu just because the server will.
Use your file manager to create a folder named oci-a1 inside your Home folder. It will hold your connection key. Keep a small note with the home region, instance name, public IP address, and username. Keep the key file itself private.
Sources: Signup requirements · Card verification · Ubuntu OpenSSH installation
Checkpoint: Your terminal recognizes SSH, and you have somewhere safe to put the key.
Create, secure, and upgrade your account
Create and secure your account, choose its home region, upgrade to Pay As You Go, and add a billing alert. These choices determine where your server lives, how you recover access, and how you notice unexpected spending.
Expand sectionCollapse section
- Open Oracle Cloud Free Tier and follow its signup link. Use the standard Free Tier offer. If you already have an Oracle Cloud free account, use it; Oracle permits one free account per person.
- Verify your email and complete the identity and card checks. Save the cloud account name as well as your email and password; the cloud sign-in page may ask for that name.
- Choose your home region carefully. Pick an available commercial region near you that offers the services you want. This choice is permanent. Free A1 compute belongs in that region; choosing another region later is not a free-capacity workaround. See Oracle’s regions.
- Once the account is ready, sign in at the OCI Console. Choose the account/identity domain named in your welcome information if prompted. Give newly enabled services a few minutes to appear.
- Complete two-step verification when prompted. In your profile’s security settings, check account recovery and save a bypass code if that option is offered. Keep recovery information somewhere you can reach if you lose your phone.
The browser interface is the Console. Its navigation menu takes you to services such as Compute and Networking. The region selector controls which region you’re looking at. Your tenancy is your overall cloud account; a compartment is an organizational container inside it.
For this first server in a new personal account, use the existing compartment shown as your account name (root) throughout. If you’re using someone else’s account, use their assigned compartment and permissions instead.
Make this easy to find again. Bookmark the Console and record your home region. If a resource seems to disappear later, first check the region and compartment filters.
Sources: Signup and home-region choice · First sign-in · Recovery and two-step verification
Upgrade to Pay As You Go
If you deliberately chose the free-only route, skip the upgrade and billing alert and continue to network setup.
Already on PAYG? Skip to the billing alert below. Otherwise, read the terms before accepting: this enables billable services, and Oracle says you cannot downgrade back to Free Tier. Upgrade FAQ.
- Using your administrator account, open Billing & Cost Management → Billing → Upgrade and Manage Payment.
- Review your account details, payment method, and the Pay As You Go terms. Choose the appropriate account type and accept the terms when ready.
- Select Upgrade your account, complete any country-specific tax fields, then review and confirm the upgrade.
- Wait for the confirmation email and for Plan Type to show Pay As You Go. Oracle says this can take a day or two. Then continue with the server setup.
Oracle documents a temporary US$100 card authorization, or local equivalent, at upgrade. It reverses the authorization immediately; your bank controls when the hold disappears. This is separate from charges for billable usage.
Source: Upgrade steps and card authorization. That page also links the alternative process for older accounts and accounts outside the US if these controls are unavailable.
Add a small billing alert
This gives you an email warning if spending appears. It is a reminder to investigate, not a spending limit.
- Find Budgets through Console search, then select Create Budget. Choose Compartment scope and your account’s root compartment as the target, so child compartments are included too.
- Name it
a1-cost-watch. Set a Monthly budget of 1 in your billing currency, the minimum allowed, starting on day 1. - Add an alert rule: Actual Spend, Absolute Amount, 1. Enter an email address you check, then select Create. If a root budget already exists, add this alert to it instead.
Oracle describes budget alerts as periodic checks, not real-time protection. Costs can accumulate before an email arrives and can exceed the budget. Review Cost Analysis after setup, after changes, and when trial credit ends.
Sources: Create a budget and alert · Budget scope and soft limits
Checkpoint: You can identify your home region and compartment, your plan shows PAYG, and your billing alert has a recipient. If you deliberately kept the free-only plan, you understand that A1 capacity may remain unavailable.
Make a network for your server
Create the server’s cloud network and allow connections from your own computer. This gives you a working route to the server while keeping its sign-in doorway limited to your Internet address.
Expand sectionCollapse section
Think of this as giving your cloud computer a home network and a controlled doorway to the Internet.
- Check that the Console’s selected region is your home region. Open Networking → Virtual cloud networks.
- Select Start VCN Wizard, possibly inside Actions. Choose Create VCN with Internet Connectivity.
- Name the VCN
a1-network. Use the same compartment as above. Keep DNS enabled and leave IPv6 disabled for this walkthrough. - Keep the wizard’s default IPv4 ranges. Common defaults are
10.0.0.0/16for the VCN,10.0.0.0/24for its public subnet, and10.0.1.0/24for its private subnet. These are internal addresses, not your home Internet address. - Review and create. Open the completed VCN. The wizard builds its subnets, gateways, and routes. We’ll use the public subnet.
Sources: VCN wizard · Oracle’s first-instance tutorial
Allow your computer to connect
SSH uses network port 22. Narrow the wizard’s SSH rule to your connection before creating the server.
- Find your current public IPv4 address. For example, open this public-IP lookup on the computer you’ll connect from. It should display four numbers separated by dots. A VPN or browser-only proxy can make browser and terminal traffic use different addresses; use the address for the connection SSH will actually use.
- In
a1-network, open its public subnet, then the associated Security Lists and its default security list. Locate the inbound TCP rule whose destination port is22. - Edit that rule to match the settings below. If the interface requires replacing it, add the narrow rule, then remove the old unrestricted port-22 rule.
| Stateless | Unchecked: use a stateful rule. |
|---|---|
| Source type | CIDR |
| Source CIDR | Your public IPv4 followed by /32. For example, 198.51.100.27/32—replace this example. |
| IP protocol | TCP |
| Source port range | All; leave blank if blank means All. |
| Destination port range | 22 |
| Description | SSH from my computer |
The /32 notation means “this one IPv4 address.” 0.0.0.0/0 means “any IPv4 address.” Security-list and network-security-group permissions are additive: adding a narrow rule does not cancel a broad rule. Leave unrelated default ICMP and outbound rules in place.
Sources: Security lists · Security-rule behavior
Checkpoint: The public subnet has an Internet route, and SSH is allowed from your public IP. You haven’t needed to open ports on your home router.
Create your A1 instance
Choose the A1 hardware, Ubuntu image, and disk size, then save your private connection key before creating the server. Getting these settings right keeps the setup within the free allowances and gives you the key needed to sign in.
Expand sectionCollapse section
Open Compute → Instances → Create instance. Oracle’s layout changes occasionally; the field names below matter more than where they sit on the page.
| Setting | Choose |
|---|---|
| Name / compartment | my-a1 / the same compartment used for the network. |
| Placement | An available availability domain in your home region; let Oracle choose the fault domain. |
| Image | Standard Canonical Ubuntu 24.04 LTS platform image for Arm / aarch64. Avoid Minimal and Marketplace variants here. |
| Shape | Virtual machine → Ampere → VM.Standard.A1.Flex. Check the exact name; A2 is different. |
| OCPUs / memory | 4 OCPUs / 24 GB on PAYG. If deliberately remaining on the free-only plan, choose 2 OCPUs / 12 GB. Account for any other A1 usage this month before using either full allocation; see the monthly calculation. |
| Capacity type | Ordinary on-demand capacity; no preemptible instance or capacity reservation. |
| Networking | Existing a1-network, its public subnet, and assignment of a public IPv4 address enabled. |
| Boot volume | 50 GB, Balanced performance (10 VPUs/GB). Keep Oracle-managed encryption; leave replication, performance auto-tuning, and scheduled backup policies off. |
| Other options | Keep recommended launch and agent defaults. No extra disks, extra network cards, startup scripts, or advanced placement features. |
A shape describes the hardware allocation; an image supplies the operating system. A1 uses Arm, so software you install later needs an Arm-compatible version. Your own computer can use a different processor.
Sources: Instance creation fields · Compatible platform images · Ubuntu 24.04 image releases · Default storage settings
Save the key before creating the instance
In Add SSH keys, select Generate a key pair for me. Save the private key; save the public key too for your records. Using your file manager, move the private file to your Home folder’s oci-a1 directory and rename it a1-private.key. Rename the public file a1-public.key.pub.
Don’t swap the files: the one ending in .pub is the public half. The private half is the one SSH needs. Oracle won’t offer the same generated private key for download after creation. Keep a protected backup outside this server; never email it or paste it into a support post.
Review, then create
Recheck region, exact shape, image, CPU, RAM, disk, and saved key. Count any other resources and this month’s A1 usage against the shared allowances. “Always Free eligible” on an image means the image can be used with free resources—it does not make every hardware choice free. A1 labels and estimated costs can also differ by account and Console version. If the review is unclear or shows unexpected costs, compare the selected resources with the free limits before proceeding; don’t use trial credit as proof of long-term eligibility. PAYG will permit choices that cost money.
Select Create. Wait for Running, then record its public access IP address from the instance details. If Oracle reports insufficient host capacity, go to troubleshooting; do not switch to a random paid shape.
Checkpoint: You have a running A1 instance, a public IP address, and the private key saved on your own computer.
Connect from Linux
Use your saved key to connect from Linux and check that you have reached the right server. You’ll learn when commands are running on your own computer and when they are running on the remote machine.
Expand sectionCollapse section
Open the terminal on your computer. First protect the key file so only your user can read it:
On your computer
chmod 400 "$HOME/oci-a1/a1-private.key"
No output usually means success. $HOME stands for your Home folder; leave that part as written. If the file is missing, check its name and location in the file manager.
Now connect. Replace YOUR_SERVER_PUBLIC_IP with the instance’s public IP from the Console. Keep ubuntu@ in front of it.
On your computer · replace the IP placeholder
ssh -o IdentitiesOnly=yes -i "$HOME/oci-a1/a1-private.key" ubuntu@YOUR_SERVER_PUBLIC_IP
-i tells SSH which key to use. IdentitiesOnly=yes keeps it from trying unrelated keys you may already have. There are no angle brackets to type, and the username is ubuntu, not your email or cloud-account name.
The first-connection question
The first time, SSH usually says it can’t establish the host’s authenticity and shows a fingerprint. This is the server identifying itself. Confirm that the IP is the one on your new instance’s page. For stronger verification, compare the fingerprint with the server’s host-key fingerprint in its boot/console output using Oracle’s console-history tools. Accepting an unchecked fingerprint is trust on first use; matching the IP alone is not cryptographic proof.
When satisfied you are connecting to your new server, type yes and press Enter. SSH remembers the host key. An unexpected “host identification has changed” warning on a later visit deserves investigation—see troubleshooting.
You should see an Ubuntu welcome message and a prompt something like ubuntu@my-a1:~$. You’re now typing into the remote computer.
On your server
whoami
uname -m
Expect ubuntu and aarch64, respectively. Type one line, press Enter, then the next. Don’t copy a displayed prompt such as $ as part of a command.
Sources: Connecting to a Linux instance · OpenSSH key selection
Checkpoint: The server tells you that you are ubuntu on an aarch64 machine. You have your first working connection.
Update, reboot, and reconnect
Install Ubuntu updates, restart the server, and reconnect. You’ll bring the new system up to date and practice the routine you’ll use to maintain it.
Expand sectionCollapse section
Give a newly started image a moment to finish its setup. This command waits for cloud-init to finish:
On your server
cloud-init status --wait
Continue when it reports done. If it reports an error, inspect the message rather than repeatedly recreating the instance.
Refresh the software list, then install the available updates:
On your server · run one line at a time
sudo apt update
sudo apt upgrade
sudo runs an administrative task. apt update checks what is available; apt upgrade actually installs updates. Read the summary and answer Y when ready. On the default OCI Ubuntu account, sudo normally doesn’t ask for a password. If you see an unexpected password prompt, don’t enter your Oracle web password.
If asked whether to replace an existing SSH configuration file, keep the currently installed local version for this walkthrough. If another update process holds a lock, let it finish and retry; don’t delete lock files. Some updates can be deferred by Ubuntu’s phased rollout, which does not necessarily mean anything is broken.
Once the update command has finished and the prompt returns, restart:
On your server
sudo reboot
The connection closing is expected. Wait a minute or two, then run your same ssh command on your computer. If the first attempt fails, give the server a little more time.
To disconnect without turning off the server:
On your server
exit
You’re back on your own computer. The server keeps running. Reconnect whenever you need it.
An OCI-specific Ubuntu detail: don’t enable UFW as a generic “first server” step. Oracle warns that it can remove firewall rules needed for boot/block-storage access. Keep the supplied system firewall configuration. The Console’s SSH rule is already controlling who can reach port 22. Oracle’s firewall guidance.
Sources: Waiting for cloud-init · Ubuntu software updates · Phased updates
Checkpoint: Updates finished, the server rebooted, and you connected again. The basic setup is complete; the following chapters help you look after it.
Understand your disk space
Learn the difference between disk space used inside Ubuntu and disk capacity allocated by Oracle. Checking both helps you avoid running out of space or exceeding the shared storage allowance.
Expand sectionCollapse section
Block storage acts like a disk attached to the server. Its boot volume contains Ubuntu and your files. An additional block volume would be a separate disk you attach later. Object Storage is a different service for uploading files into buckets.
Two measurements matter: how much disk capacity Oracle has allocated, and how full the disk is inside Ubuntu. Deleting files frees space inside Ubuntu; it does not reduce the allocated disk size.
On your server
df -h /
Read Size, Used, and Avail. The last column, /, means the main filesystem. A result smaller than the advertised disk size is normal because of unit differences, partitions, and filesystem overhead.
In the Console, use Storage → Block Storage → Boot Volumes and Block Volumes to review allocated disks. Some layouts show Block Storage directly in the navigation. Check the compartment and availability-domain filters. Detached disks and disks retained from deleted servers still exist and still use allocation.
| Disks you keep | Allocated total | Room left |
|---|---|---|
| One 50 GB boot disk | 50 GB | 150 GB |
| That disk + a 50 GB restored disk | 100 GB | 100 GB |
| One 100 GB boot disk + a 100 GB restored disk | 200 GB | 0 GB |
These examples assume no other boot or block volumes. A backup is governed by the backup allowance; restoring it creates another allocated disk. Leave recovery room instead of immediately expanding your only disk to the maximum.
For this guide, enlarge the boot disk only if you need more room. A separate data disk requires attachment, filesystem creation, and mounting; those are worthwhile later topics. See Block Volume overview and attaching a block volume.
Checkpoint: You can check actual free disk space and distinguish it from Oracle’s allocated-storage total.
Make a backup
Save a recovery copy of your server’s disk and check that the backup has finished. You’ll know what it protects, what needs a separate copy, and how to stay within the backup allowance.
Expand sectionCollapse section
A volume backup records the disk at a particular time. Make one after setup and before significant changes. It does not back up your entire cloud configuration or the private key on your own computer.
- In your instance details, find its boot-volume link, or open Storage → Block Storage → Boot Volumes. Select the disk attached to
my-a1; check its name and size. - Open Backups → Create Boot Volume Backup. Give it a useful name such as
my-a1-after-setup-2026-10-06, using today’s date. - Select Full for this first backup. Keep it in your home region. Choose No retention period (keep until deleted); leave retention locks, Prevent deletion, and Indefinite hold off.
- Create the backup and wait until its state is Available. A request being accepted is not the same as a completed backup.
- Record the name and date. Before making future backups, count existing boot and block backups together. Remove only older recovery points you genuinely no longer need.
A backup taken while the machine runs is crash-consistent. That is suitable for this freshly configured server, but later applications—especially databases—may need their own backup procedure to make their data consistent.
Keep irreplaceable files on another computer or another independent backup service as well. A backup held inside the same Oracle account won’t help you while you’re locked out of that account. A successful restore is the strongest check that a recovery point is useful.
Sources: Create a boot-volume backup · What boot-volume backups contain
Checkpoint: The named backup is Available, and you know which server and date it belongs to.
Restore a backup when needed
Learn how to recover from a backup while keeping the current disk available until you have checked the result. This optional procedure gives you a way back after a problem; you can leave it for when you need it.
Expand sectionCollapse section
This is an optional recovery procedure. You don’t need to replace a healthy disk just to finish the setup.
A restore takes the server back in time. Save any newer files you need first. Plan for downtime. Keep the current disk until you’ve confirmed the restored server works.
Restore the backup to a new disk
- Check space for both the existing disk and a restored copy, using the storage examples. If the total would exceed the free allowance, pause and resolve that first. Don’t delete your only working disk just to make space.
- Open Boot Volume Backups, find the chosen backup, and select Actions → Restore Boot Volume.
- Name it
my-a1-restored. Select the same availability domain as the existing instance. Keep the original size, Balanced performance, Oracle-managed encryption, no scheduled backup policy, and replication/auto-tuning off. - Restore and wait for the new boot volume to become Available. At this point you have a recovered disk, but the server is still using its old disk.
Source: Restoring a boot volume
Use the restored disk on the existing instance
- Open the original instance’s page. Choose More Actions → Replace Boot Volume (or the equivalent Actions menu).
- Enable Preserve Boot Volume. Under Replace by, choose Boot Volume, then select
my-a1-restored. Carefully check the selected volume. - Confirm replacement. OCI stops the instance, swaps the disk, and returns it to its previous running/stopped state. This reuses the instance; it does not require a second A1 allocation.
- If it was running, wait for it to be ready and reconnect with the key valid at the backup’s date. If it was stopped, start it first. Check your files, updates, and any application you later install.
- Only after verification, consider deleting the preserved old disk to recover storage allocation. Until then, it is a rollback option. If necessary, repeat the replacement procedure to select that preserved disk.
This route uses a compatible backup of this same Ubuntu instance. Boot-volume replacement has image, operating-system, and attachment restrictions. If the option is unavailable or Oracle rejects compatibility, follow the linked requirements rather than terminating the instance. Automatic rollback is attempted on replacement failure, but Oracle does not guarantee it always succeeds.
Source: Boot-volume replacement and rollback
Checkpoint: You have logged into the restored system and checked its contents before discarding the previous disk.
Make the boot disk larger
When you need more space, grow the boot disk from 50 GB to 100 GB and check that Ubuntu can use it. You’ll plan for backups and recovery space first, because this size increase cannot simply be reversed.
Expand sectionCollapse section
Use this when the disk is getting full. Our example grows 50 GB to 100 GB, leaving room for a same-sized recovery disk if you have no other volumes. Volume enlargement is one-way; you cannot simply turn 100 GB back into 50 GB.
- Make a fresh backup and wait for Available. Check the combined allocated size of all your boot and block volumes.
- Open the current boot volume, choose Edit, and set Volume size to 100 GB. Leave performance and other settings unchanged. Save.
- Wait until the disk has finished updating. OCI may offer disk-rescan commands. Those tell Linux that the virtual disk is bigger; they are not the same as enlarging its filesystem.
- For this standard Ubuntu image, reboot and reconnect as in section 7. Cloud-init normally grows the root partition and filesystem at boot. Check the result:
On your server, after reconnecting
cloud-init status --wait
df -h /
lsblk -o NAME,SIZE,TYPE,MOUNTPOINTS
If df now shows roughly the larger size, you’re done. Exact figures vary. If the disk is larger in lsblk but the filesystem is still the old size, use the following checks.
If Ubuntu hasn’t grown the filesystem
First identify the root filesystem and disk. The commands below only inspect them:
On your server
findmnt -no SOURCE,FSTYPE /
lsblk -o NAME,SIZE,TYPE,MOUNTPOINTS
command -v growpart
The following example applies only if root is /dev/sda1, its filesystem is ext4, and its parent sda shows the new disk size. If your output differs, stop here and use the documentation below or get help interpreting it. Do not guess a device name.
If growpart is absent, install its Ubuntu package with sudo apt install cloud-guest-utils. Then preview the partition change:
On your server · only for the confirmed layout above
sudo growpart -N /dev/sda 1
-N is a dry run. If it proposes enlarging partition 1 into the new free space, apply that change, then enlarge the ext4 filesystem:
On your server · after checking the preview
sudo growpart /dev/sda 1
sudo resize2fs /dev/sda1
df -h /
If the partition already occupies the expanded space, growpart may report NOCHANGE; the filesystem can still need resize2fs. If the disk itself still shows the old size, revisit OCI’s completed resize and its rescan instructions first. Don’t format the disk or delete partitions.
Sources: OCI volume enlargement · Disk rescanning · Cloud-init partition growth · Filesystem growth · growpart · resize2fs
Checkpoint: Ubuntu’s df -h / reports the larger usable filesystem, and all allocated disks still fit the free allowance.
Understand network access
Follow the path a connection takes through Oracle’s network rules and Ubuntu’s firewall. This helps you restore access after your Internet address changes and understand what a future application needs to be reachable.
Expand sectionCollapse section
Your working SSH connection passes through several pieces:
Your computer → the server’s public IP → OCI’s network rules → Ubuntu’s firewall → the SSH service.
The public subnet and Internet gateway provide a path. The security list permits traffic through that path. Ubuntu’s own firewall and the program listening on the server have to allow it too. Opening a port does not install a program or make a website appear.
If you change networks
After a router reconnect, a move to another Wi-Fi network, or a VPN change, your public IP may change. Update the existing port-22 rule’s source /32 in the Console. You can do that in the browser even while SSH is unavailable. Test a new SSH connection before closing any working session.
If you later host an application
Use that application’s instructions to identify its port and intended audience. A public website typically needs TCP 443 and sometimes 80; a private administration page should not automatically be open to everyone. Add only the needed OCI rule, configure the Ubuntu firewall according to Oracle’s guidance, and confirm that the application is actually listening.
A network security group is another way to group network rules. This walkthrough uses the subnet’s security list, so you don’t need to add an NSG just to finish. If one is added later, remember that permissions from both sources combine.
Use the public IP shown in the Console for connections from home. A private address such as 10.0.0.10 is for the cloud network. Don’t assume you can connect to the private address directly from your home Internet connection.
Sources: OCI security rules · Essential system firewall rules
Checkpoint: You know where to update SSH access, and why a future app may need both network and operating-system changes.
Keep the account and server useful
Build a small routine for updates, backups, account notices, and usage checks. You’ll also learn what disconnecting, restarting, stopping, and deleting actually do, so everyday maintenance does what you intend.
Expand sectionCollapse section
A small maintenance routine
- Read Oracle account emails and Console announcements. Keep your contact and payment-verification information current.
- Periodically reconnect, check
df -h /, install updates, and reboot when required. On standard Ubuntu Server, unattended security updates are normally enabled; they don’t remove the need to check failures or pending reboots. Ubuntu automatic updates. - Before major changes, take a backup. Keep an independent copy of important files and of your private connection key.
- Use Governance & Administration → Tenancy Management → Limits, Quotas and Usage, or Console search for that page, to inspect limits and current allocation. Check Compute and Block Volume in the home region.
- Use Billing & Cost Management → Cost Analysis to review costs after setup and changes, when trial credit ends, and as part of monthly upkeep. Investigate unexpected costs or budget alerts promptly. A service limit is permission to allocate resources, not a promise that all of them are free.
Sources: Service limits · Cost Analysis
“Always Free” is not a reservation forever
Oracle may reclaim idle free compute. Its published seven-day test requires all of these: CPU usage’s 95th percentile below 20%, network utilization below 20%, and—for A1—memory utilization below 20%. A successful occasional login is not a guarantee against reclamation. Idle-instance policy.
For accounts that remain on Free Tier, Oracle’s FAQ also describes abandonment after 30 days of inactivity, no availability SLA, and limited support. Upgraded accounts can open support requests. Keep independent backups whichever plan you use; an account upgrade does not promise permanent capacity or data retention. Account activity and support FAQ.
Disconnecting, restarting, stopping, deleting
| Action | What happens |
|---|---|
exit | Your SSH session ends; the server keeps running. |
| Reboot / Restart | The operating system restarts; the disk remains. Your SSH connection ends while it reboots. |
| Stop | The server powers down. Its disks remain allocated. Starting again can encounter a capacity problem; stopping is not a guarantee of future access or zero charges for every attached resource. |
| Terminate | The instance is deleted. Its boot volume is normally preserved unless you choose to delete it. Review retained disks and backups separately. |
For a normal stop or restart, use the instance page’s action and allow a graceful shutdown. Reserve forced actions for a machine that is genuinely unresponsive. You do not have to stop this correctly sized server every night to fit the monthly allocation.
If you decide to remove it permanently, save needed data first, then use Instances → Actions → Terminate. Read the disk-deletion checkboxes carefully. Preserved disks can be useful for recovery, but they still consume storage allocation. Keep the network if you plan to create another server.
Sources: Instance lifecycle · Termination and retained disks
Checkpoint: You have a maintenance habit and a recovery plan, and you know that eligibility, availability, and permanent retention are different things.
When something doesn’t work
Match common error messages to the next thing to check, from unavailable A1 capacity to a failed login or unexpected charge. A focused check can get you unstuck without rebuilding a working part of the setup.
Expand sectionCollapse section
Read the exact message first. A capacity error, an account limit, and a connection timeout are different problems.
| What you see | What to check next |
|---|---|
| “Out of host capacity” | If still on the free-only plan, the recommended next step is the PAYG upgrade, with billing enabled. If already upgraded, verify the upgrade has completed, try another availability domain in the same home region, or retry later. Paid accounts can ask support about capacity. Don’t repeatedly recreate networks and disks. Upgrading still does not guarantee an A1 slot. |
| A1 is missing or disabled | Confirm the home region, an Arm-compatible Ubuntu image, the availability domain, and your A1 service limits. Recheck image selection after changing shape. Don’t select A2 just because it is also Arm. |
| Limit exceeded | Review all existing A1 allocations and all disks, including detached or retained ones. Distinguish your resource allocation limit from an availability shortage. Don’t delete useful resources blindly. |
| No public IP | Check the instance’s primary network interface, public subnet, and IPv4 assignment. Follow Oracle’s public-IP assignment instructions. |
| SSH times out | Wait for boot completion. Confirm the server’s public IP, its Running state, the subnet’s Internet route, and TCP 22 allowed from your current public IP. A VPN or workplace network can also block SSH. |
| “Connection refused” | The address responded, but SSH isn’t accepting the connection. Check the address, allow boot to finish, and use Oracle’s SSH troubleshooting or console recovery if it persists. |
| “Permission denied (publickey)” | Use ubuntu, the matching private key, and the current instance’s IP. Check that you selected a private file, not the .pub file. This is not asking for the Console password. |
| “Unprotected private key file” | On your own computer, repeat the chmod 400 command from section 6 for the actual key file. |
| “Host identification has changed” | Check whether you intentionally rebuilt/replaced the server or changed its IP. Verify the new host fingerprint using trusted Console access. Don’t automatically erase the old key warning or disable checking. |
| Lost private key | Check your protected backup first. The private key cannot be downloaded again. Key recovery through the serial console is possible but more advanced; don’t terminate a server containing your only copy of needed data. |
| Trial ended; a resource vanished | Check region and compartment first, then your account plan, trial notices, and resource eligibility. On an unupgraded account, trial-only resources and excess A1 allocations can be reclaimed. On PAYG, retained resources outside free allowances can instead become billable when credit runs out. |
| Unexpected charge or budget alert | Open Cost Analysis and identify the service and resource responsible. Check total A1 hours, disks, backups, outgoing traffic, and any extra services against their allowances. Stop adding resources while investigating; retained storage can remain billable even when a VM is stopped. PAYG support can help with billing questions. |
| Signup/card verification failed | Recheck accurate details and supported card type; use the signup support/chat route. Don’t create duplicate free accounts to work around the problem. |
If you ask for help, share the error wording, operating system, and the step you were on. Remove private keys, passwords, recovery codes, and other account details from screenshots or pasted commands.
Sources: Capacity and signup FAQ · SSH troubleshooting · Connection and console options · Shape availability
Checkpoint: You can identify which layer needs attention without starting the whole setup again.
What else can this account do for free?
Take a first look at other useful services and their free allowances. This helps you decide what to explore next while recognizing that each service has its own limits.
Expand sectionCollapse section
You don’t have to provision these to complete the guide. This is a small introduction to useful options, not a setup walkthrough or the entire catalog. These services have their own allocations; a managed database is separate from installing database software on your A1.
The table describes ongoing free allowances, with account-type differences called out. On an upgraded paid account, additional usage or paid configurations may be billed. On an unupgraded account, features may instead be unavailable or limited. Always check the service’s creation screen and linked documentation.
| Service / everyday purpose | Free allowance and boundary |
|---|---|
| AMD micro instances Other small cloud computers | Up to two VM.Standard.E2.1.Micro instances, 1 GB RAM each. They have much less processing power than A1 and still need disks from the shared disk allowance. Other AMD shapes are not included. Compute allowances. |
| Object + Archive Storage A place to upload files | PAYG: 10 GB each in Standard, Infrequent Access, and Archive; these are separate pools, not 30 GB of Standard. Free-only after trial: 20 GB combined. Both include 50,000 requests/month. Prefer Standard for files you need promptly; other tiers involve retrieval or retention considerations. Object Storage · Exact free-tier distinctions. |
| Autonomous Database / APEX Organized data and browser-based apps | Up to two Always Free Autonomous databases, approximately 20 GB per database. APEX uses that underlying database allocation. Select the Always Free option; larger/paid database configurations are different products. Always Free APEX and database limits. |
| MySQL HeatWave A managed MySQL database | One eligible free DB system with a single-node HeatWave cluster; 50 GB database/log storage and 50 GB backup storage. This is a specific free configuration, not any MySQL server size. Regional and service restrictions apply. MySQL guide · Free allocation. |
| Flexible Load Balancer A front door that directs web traffic | One eligible load balancer with both minimum and maximum bandwidth set to 10 Mbps. Increasing its range or creating another is outside this allocation. You don’t need one just for SSH. Load balancing · Free configuration. |
| Monitoring + Notifications Measurements and alerts | Per month: 500 million monitoring data points ingested and 1 billion retrieved; Notifications includes 1 million HTTPS deliveries and 1,000 email deliveries. Beyond those allowances, paid usage may apply. Notification email is distinct from the Email Delivery service. Monitoring · Notifications · Allowances. |
| Bastion A temporary route into a private server | The Bastion service is free for free and paid accounts; sessions and service limits still apply, and target resources have their own costs. It is useful when you later want a server without a public IP. Bastion overview. |
Check your account type before uploading files. On the recommended PAYG route, start with Standard storage and stay within its 10 GB allowance and the request allowance. For free-only accounts, Oracle warns that excess stored objects at trial expiry can lead to deletion of all objects, not just the excess. Trial-storage descriptions differ within the reference page, so verify the transition and keep independent copies.
Other entries include Logging, Vault, Email Delivery, NoSQL, and Resource Manager. Start with Oracle’s complete Always Free catalog when one becomes useful. “Free” in the name of a tool does not make every resource that tool creates free.
Back to contents ↑Plain-language glossary
Find plain-language explanations of the cloud, Linux, storage, and networking terms used in this guide. Use this as a quick reference whenever an unfamiliar word slows you down; the same definitions appear in the yellow-underlined hovertips.
Expand sectionCollapse section
Dotted-underlined terms throughout the guide show these explanations on hover, keyboard focus, or tap. Press Escape or tap outside to close a tip. Without JavaScript, the terms link here instead. This glossary also prints with the guide.
- Instance / virtual machine (VM)
- A computer provided by Oracle that you control remotely. It behaves like its own machine, even though the physical hardware may be shared with other virtual machines.
- Terminal
- A window where you type instructions instead of clicking buttons. It starts on your own computer; after an SSH connection, the instructions go to the remote server.
- OCI
- Oracle Cloud Infrastructure: Oracle’s collection of online services, including the computers, disks, and networks used in this guide.
- Pay As You Go (PAYG)
- An account plan that lets Oracle bill you for paid usage. Free allowances still apply automatically, but the account no longer prevents you from creating billable resources or exceeding those allowances.
- OCPU
- Oracle’s unit of processing capacity. On an Ampere A1, one OCPU is one processor core and one vCPU. More cores let the server do more work at once.
- RAM / memory
- The server’s working space while programs run—like the clear space on a desk. Disk storage is the filing cabinet. RAM contents do not survive a shutdown.
- OCPU-hours / GB-hours
- Processing capacity or RAM multiplied by time. Four OCPUs running for ten hours use 40 OCPU-hours; 24 GB of RAM for ten hours uses 240 GB-hours. All A1 resources in your account share the monthly allowance, even when they are mostly idle.
- Region / home region
- A geographic area where Oracle runs cloud services. Your home region is chosen at signup and cannot be changed; it matters for free compute and disk eligibility.
- Availability domain (AD)
- An isolated data-center location within a region. A region may have one or several. Your instance and its attached boot disk need compatible placement.
- Two-step verification / MFA
- An extra check at sign-in, such as a code or approval on your phone, as well as your password. A recovery or bypass code helps if your usual method is unavailable.
- Console
- Oracle’s management website, where you create and manage cloud resources. This is different from the Linux terminal inside your server.
- Tenancy
- Your overall Oracle Cloud account space. Think of it as the container that holds your users, permissions, and cloud resources.
- Compartment
- An organizational container inside your tenancy, somewhat like a folder for cloud resources. It also helps control permissions. The root compartment is the top level.
- Virtual cloud network (VCN)
- Your network inside Oracle Cloud. It plays a similar organizing role to a home network, with addresses and rules for connecting its computers.
- Subnet
- A section of a network with its own address range. OCI public subnets allow public IP addresses; private subnets do not. A public subnet alone does not grant Internet access.
- Gateway
- A route out of a network. An Internet gateway connects the public subnet to the Internet; the wizard also creates gateways for other kinds of connections.
- Route / route table
- A direction telling network traffic where to go next. A route table is the set of those directions; a firewall separately decides which traffic is allowed.
- SSH (Secure Shell)
- An encrypted connection that lets you use the server’s terminal from your own computer. In this guide, your private key proves you are allowed to sign in.
- Port
- A numbered doorway to a particular network service. SSH normally uses 22; secure websites normally use 443. Opening a doorway does not install the service behind it.
- Stateful rule
- A network rule that remembers an allowed connection and automatically permits its replies. You don’t need to write a second rule for every response.
- CIDR / /32
- A compact way to describe a range of IP addresses. For IPv4, /32 means exactly one address; 0.0.0.0/0 means every IPv4 address.
- Shape
- Oracle’s name for a server’s hardware configuration: processor family, processing capacity, memory, and related features. “Flex” lets you choose CPU and memory amounts.
- Image
- A prepared operating-system template used to create the server’s starting disk. Here it supplies Ubuntu; it isn’t a picture or screenshot.
- Arm / aarch64
- The processor family used by Ampere A1. “aarch64” identifies 64-bit Arm. When downloading programs, choose an Arm64/aarch64 build rather than an x86-64/amd64 build.
- Private key / public key
- A matched pair of files used for sign-in. The public half is installed on the server. Keep the private half on your own computer, like a key to your front door; anyone holding it may be able to get in.
- Host-key fingerprint
- A short identifying summary of the server’s SSH key. It helps you check which server you are talking to. It is different from the private key you use to sign in.
- cloud-init
- The startup helper that prepares a new cloud Linux machine: users, keys, networking, and other first-boot tasks. Some tasks, such as disk growth, can also run on later boots.
- sudo
- A way to run one command with administrator privileges. Use it for tasks such as installing updates. It applies to Linux administration, not your Oracle web-account login.
- Block storage / volume
- Think of block storage like your computer’s hard drive: to the virtual machine, that is the job it does. A volume is one of those virtual disks, and it can outlive the server attached to it.
- Boot volume
- The disk the server starts from. It contains Ubuntu and, unless you put them elsewhere, your programs and files. It counts toward the shared block-storage allowance.
- Object Storage / bucket
- A service for uploading and retrieving files as objects. A bucket groups them, rather like a named container. It is separate from the disk Ubuntu boots from.
- Volume backup
- A recoverable copy of a disk at a particular time. Restoring it creates a disk with those contents; it does not automatically restore every network or account setting.
- Crash-consistent
- A disk snapshot comparable to what was on disk when a machine suddenly lost power. Files saved on disk are represented, but an application may still need recovery of work that was in progress.
- Firewall / ingress / egress
- Rules controlling network traffic. Ingress is traffic coming in; egress is traffic going out. OCI’s network rules and Ubuntu’s own firewall are separate layers.
- Network security group (NSG)
- A set of OCI network rules applied to selected network interfaces. Security lists apply at subnet level. When both apply, an allow rule in either can permit traffic.
- IP address / IPv4 / IPv6
- A network address used to reach a computer. A public address is reachable through the Internet; a private one is used inside a network. IPv4 uses four dotted numbers. IPv6 is a newer address format; this walkthrough uses IPv4.
- DNS
- The system that translates names into network addresses, rather like looking up a person’s phone number. Keeping the network’s DNS setting enabled lets it use names as well as numeric addresses.
- TCP
- A method computers use to send data reliably over a network. Choose it here because SSH uses TCP. It is a protocol choice, separate from the port number.
- LTS
- Long Term Support: an Ubuntu release intended for years of maintenance. This guide uses Ubuntu 24.04 LTS so its instructions follow one specific, supported release.
- VPU
- Volume Performance Unit: Oracle’s setting for how much performance a disk is allocated. It is separate from disk capacity. Leave it at Balanced here rather than selecting a faster, potentially chargeable tier.
- Encryption
- Scrambling stored data so it can only be read with the proper key. With Oracle-managed encryption, Oracle handles that storage key for you. It is different from your SSH sign-in key.
- Filesystem / ext4
- The way an operating system organizes files and folders on a disk. ext4 is one common Linux filesystem. Increasing a virtual disk’s capacity may also require growing its filesystem before the extra room is usable.
- Partition
- A defined section of a disk. A disk can hold several partitions, and the main Linux filesystem occupies one of them. Enlarging that section does not mean erasing or formatting it.
Sources and verification notes
Find the official documentation behind the instructions and see how this guide handles conflicting wording. These sources help you check current limits and adapt when Oracle’s screens or terms change.
Expand sectionCollapse section
Documentation checked: 6 October 2026. This guide was checked against Oracle’s current public documentation and Ubuntu/OpenSSH/cloud-init references. These instructions have not been verified by provisioning a new OCI account or instance.
Limits and Console screens can change. Follow the linked current sources and your account’s actual eligibility before creating resources. Where the Console uses tabs instead of a sidebar, look for the same resource or action name.
Documentation details handled deliberately
- Capacity and upgrade advice: the recommendation to expect a PAYG upgrade reflects practical experience obtaining A1 capacity. Oracle documents free-capacity shortages and different limits for paid accounts, but no release schedule or probability of success.
- A1 allocation and inconsistent wording: the Always Free reference says “All tenancies” before giving 1,500 OCPU-hours / 9,000 GB-hours, then describes 2 OCPUs / 12 GB for Always Free tenancies. The price list explicitly gives each paid tenancy 3,000 / 18,000. For PAYG, this guide follows that specific pricing statement and recommends one 4-OCPU / 24-GB server. This is a documented current allowance, with no grandfathering condition stated.
- Automatic allowance versus a spending cap: eligible usage within current free allowances costs $0, including on PAYG. Usage elsewhere in the account can still be billed. Budget alerts provide notification, not a guarantee of no charges.
- Boot-volume size: Oracle’s free-resource page uses both 47 GB and 50 GB in different passages. This guide explicitly chooses 50 GB and budgets from that allocation.
- Object Storage: trial, paid, and post-trial descriptions differ, including within the free-resource page. Section 15 distinguishes paid accounts’ 10 GB per tier from free-only accounts’ 20 GB combined after trial expiry.
Core references
- Oracle: Always Free resource allocations
- Oracle: Free Tier and what happens after the trial
- Oracle: Free Tier FAQ
- Oracle: current price list
- Oracle: PAYG upgrade and payment authorization
- Oracle: creating a budget and alert
- Oracle: budgets are soft limits
- Oracle: creating an instance
- Oracle: platform images and essential firewall rules
- Oracle: virtual networking wizards
- Oracle: connecting to a Linux instance
- Ubuntu: managing software
- Oracle: boot-volume backups
- Oracle: replacing a boot volume
- Oracle: enlarging a volume
- cloud-init: partition and filesystem growth
Additional task-specific sources appear beside their instructions throughout the guide. Illustrative resource names, addresses, prompts, and commands are labeled as examples.
Back to contents ↑