Build a fully patched Oracle home, then create a CDB and PDB
on it, with one config file and one Java command.
The problem with manual home builds
A patched 19c home traditionally means downloading the base
image, OPatch, the Release Update, OJVM, the Data Pump Bundle Patch (DPBP) and
a JDK patch, then unzipping, patching in the right order and relinking. Each
step risks a typo or version mismatch, and across servers and quarters the
environments drift.
AutoUpgrade started as an upgrade tool but now handles
patching and provisioning too. Its download and create_home modes resolve the
patch set for you, fetch it from My Oracle Support (MOS), and assemble the
home.
Read this first: Oracle Linux 10
19c predates Oracle Linux 10, and OS support arrives through
Release Updates. Before building, confirm OL10 support for your configuration
in Oracle's certification information and the RU 19.32 release notes. Check
whether oracle-database-preinstall-19c exists for OL10 and whether the
installer needs an override such as CV_ASSUME_DISTID. Use overrides only if the
notes say so. Treat the steps below as a template to validate, not a certified
recipe.
Prerequisites
|
Area |
Requirement |
|
Memory |
8 GB or more recommended, swap per the install guide |
|
Disk |
About 40 GB free for staging, the home and the database |
|
Access |
MOS account with a support entitlement for 19c patches;
outbound HTTPS to Oracle (or a proxy) |
|
Software |
Latest autoupgrade.jar and a JDK (Java 8 or later) |
|
OS user |
oracle in oinstall and dba |
Step 1: Prepare the operating system
# As root
dnf install -y java-17-openjdk unzip libnsl libaio ksh bc
binutils \
glibc-devel
libstdc++-devel make sysstat fontconfig policycoreutils
groupadd -g 54321 oinstall
groupadd -g 54322 dba
useradd -u 54321 -g
oinstall -G dba oracle
passwd oracle
If no preinstall package is available, set kernel parameters
in /etc/sysctl.d/97-oracle.conf and limits in
/etc/security/limits.d/oracle-database-19c.conf:
fs.file-max = 6815744
kernel.sem = 250 32000 100 128
kernel.shmmni = 4096
net.ipv4.ip_local_port_range = 9000 65500
fs.aio-max-nr = 1048576
oracle soft nofile 1024
oracle hard nofile 65536
oracle soft nproc
16384
oracle hard nproc
16384
oracle hard memlock unlimited
Apply with sysctl --system. Size shmall and shmmax for your
RAM, and for production configure HugePages and disable transparent HugePages.
Directory layout
/u01app/oracle/autoupgradeapp/oracle/stageapp/oracle/product/19.32.0oradata,
fraautoupgrade.jar, config, keystore, logsDownloaded gold image and patchesThe
new Oracle home (dbhome_1). Name it after the RU.Datafiles and fast recovery
areaFigure 2. Separating tooling, staging, homes and data keeps builds clean
and lets several RU homes coexist.
mkdir -p
/u01/app/oracle/{autoupgrade/{keystore,log},stage,product/19.32.0/dbhome_1}
mkdir -p /u01/oradata /u01/fra
chown -R oracle:oinstall /u01 && chmod -R 775 /u01
Step 2: Install AutoUpgrade
As oracle, place the latest autoupgrade.jar in the
autoupgrade folder and check the build. Record the version, because supported
parameters and patch keywords depend on it.
cd /u01/app/oracle/autoupgrade
java -jar autoupgrade.jar -version
Step 3: Write the config file
Save as create_home.cfg. Parameter names can differ between
AutoUpgrade builds, so check the documentation for yours.
global.global_log_dir=/u01/app/oracle/autoupgrade/log
global.keystore=/u01/app/oracle/autoupgrade/keystore
patch1.folder=/u01/app/oracle/stage
patch1.target_version=19
patch1.platform=LINUX.X64
patch1.patch=RU:19.32,OPATCH,OJVM,DPBP,JDK
patch1.target_home=/u01/app/oracle/product/19.32.0/dbhome_1
patch1.home_settings.oracle_base=/u01/app/oracle
patch1.home_settings.edition=EE
patch = RU:19.32 +
companionsRU:19.32OPATCHOJVMDPBPJDKRelease UpdateMatching OPatchJava in the
databaseData Pump fixesJDK in the homeFigure 3. What each item in the patch
list contributes. Run -help for the keywords your build supports.
|
Parameter |
Meaning |
|
patch1.folder |
Staging area for downloads |
|
patch1.target_version |
Release line (19) |
|
patch1.patch |
RU plus companion patches |
|
patch1.target_home |
Path of the home to create |
|
home_settings.edition |
EE or SE2 |
Step 4: Store MOS credentials
Credentials go in an encrypted keystore, never in the config
file.
java -jar autoupgrade.jar -config create_home.cfg -patch
-load_password
chmod 700 /u01/app/oracle/autoupgrade/keystore
Step 5: Download
java -jar autoupgrade.jar -config create_home.cfg -patch
-mode download
AutoUpgrade resolves each keyword to the right patch for
19.32 and downloads the gold image, OPatch, OJVM, DPBP and JDK patch into the
staging folder. Use lsj in the console to list jobs and status -job <n>
for detail. In restricted networks, download on a connected host and copy the
staging folder across.
Step 6: Create the patched home
java -jar autoupgrade.jar -config create_home.cfg -patch
-mode create_home
It unpacks the gold image, updates OPatch, applies the
patches in order and validates the result. Run any root scripts it prompts for,
then set the environment:
export ORACLE_BASE=/u01/app/oracle
export ORACLE_HOME=$ORACLE_BASE/product/19.32.0/dbhome_1
export PATH=$ORACLE_HOME/bin:$ORACLE_HOME/OPatch:$PATH
Step 7: Verify the home
opatch version
opatch lspatches
opatch lsinventory -detail | more
You should see the 19.32 RU, OJVM, DPBP and JDK patches.
Compare patch IDs against the RU 19.32 README on MOS.
Step 8: Create the CDB and PDB
netca -silent -responsefile
$ORACLE_HOME/assistants/netca/netca.rsp
dbca -silent -createDatabase \
-templateName
General_Purpose.dbc \
-gdbName CDB1 -sid
CDB1 \
-createAsContainerDatabase true \
-numberOfPDBs 1
-pdbName PDB1 \
-characterSet
AL32UTF8 -nationalCharacterSet AL16UTF16 \
-sysPassword
'<StrongPassword>' -systemPassword '<StrongPassword>' \
-pdbAdminPassword
'<StrongPassword>' \
-datafileDestination
/u01/oradata \
-recoveryAreaDestination
/u01/fra \
-storageType FS
-memoryMgmtType AUTO_SGA -totalMemory 4096 \
-emConfiguration
NONE
Because the home is already at 19.32, the database starts
fully patched, so the long post-install datapatch step mostly disappears. Save
the PDB state so it opens after restarts:
ALTER PLUGGABLE DATABASE PDB1 SAVE STATE;
Step 9: Validate
SELECT name, cdb, open_mode, log_mode FROM v$database;
SELECT banner_full FROM v$version;
SHOW PDBS;
SELECT con_id, comp_id, comp_name, version, status
FROM cdb_registry
ORDER BY con_id, comp_id;
SELECT con_id, COUNT(*) invalid_objects
FROM cdb_objects
WHERE status = 'INVALID'
GROUP BY con_id;
SELECT patch_id, action, status, description
FROM
dba_registry_sqlpatch ORDER BY action_time;
Expected resultOracle Database 19c at 19.32CDB1 open READ
WRITE, PDB1 openAll components VALIDNo invalid objectsdba_registry_sqlpatch
shows SUCCESSIf objects are invalid: run @?/rdbms/admin/utlrp.sqlIf a patch is
missing: run datapatch -verboseFigure 4. What a healthy build looks like.
Post-build checklist
- Register
the database in oratab and set up autostart (systemd or dbstart)
- Configure
RMAN backups and take a first backup
- Apply
hardening: password policy, auditing, network encryption
- Configure
HugePages and tune initialization parameters
- Commit
the config file and AutoUpgrade version to Git
Troubleshooting
|
Symptom |
Likely cause and fix |
|
Download authentication fails |
Wrong credentials or no entitlement. Reload with
-load_password. |
|
Downloads stall |
Proxy or firewall. Check outbound HTTPS. |
|
Unknown keyword or parameter |
AutoUpgrade build is older than your syntax. Update and
check the docs. |
|
Home creation fails |
Read logs in global_log_dir; check disk space and
permissions. |
|
OL10 prerequisite warnings |
Compare with the certification matrix and RU release notes
before overriding. |
|
Invalid objects |
Run utlrp.sql and re-check. |
Best practices
Build in a lab first and keep the config in Git next to the
AutoUpgrade version. Prefer out-of-place patching so the previous home stays
available for rollback. Each quarter, change the config line (RU:19.33 and so
on) and create a new home directory. The config-driven approach fits Ansible or
CI pipelines well.
Conclusion
AutoUpgrade turns home building into a declarative task:
describe the target, run download, run create_home, create the CDB and PDB, and
validate. On Oracle Linux 10 the extra diligence is confirming certification
and prerequisites, but the result is a repeatable, fully patched 19c
environment.
Verify OS certification, patch contents and AutoUpgrade
parameter syntax against Oracle documentation and MOS notes for your exact
build and RU. Test in non-production first.