Every time I showed people the thing I built — a chat that spins up Oracle Cloud sandboxes and deletes them when their time is up — the reply was the same. Nice, but I would need a paid tenancy and an admin to try it, so I won't.
That was fair. So I made a Free Tier edition. Pick Edition: free on the install form and it runs on an Oracle Cloud Free Tier account with no payment method attached, on Always Free resources only.
What you get on Free Tier
- An Always Free Autonomous Database 23ai — REST enabled, in-database document search
- NoSQL tables and Object Storage buckets
- Containerised applications on an Always Free Arm VM: Grafana, the React and FastAPI starters, Streamlit, an MCP server, or your own image or Git repo
- The same chat, the same priced plan before anything is built, the same expiry that destroys the sandbox when its lifetime ends
The worker is one Always Free Arm VM (VM.Standard.A1.Flex, 2 OCPU, 12 GB) running the same worker image under podman, instead of Container Instances. The assistant uses the Google Gemini API with your own free key from AI Studio, instead of OCI Generative AI. Without a key the one-click starters and the form still work.
What you don't get, said up front
Always Free doesn't include these, so the factory declines them before it builds anything rather than failing ten minutes in:
- Kafka (Streaming with Apache Kafka)
- Functions
- Data Flow (Spark, Iceberg) and Data Catalog
- Queue
- API Gateway and extra Container Instances — applications run on the worker VM instead, over plain HTTP
- Paid database tiers, and Select AI
Two more worth knowing. Always Free allows two databases per tenancy and the factory's control database is one of them, so it is one database sandbox at a time — destroy it or let it expire before the next. And Always Free capacity is shared, so a VM or database can come back "out of capacity" at a busy moment. That is Oracle, not the factory. Try again later.
Install
One Resource Manager stack, about 15 minutes, in your home region.
- Repo and the Deploy button: https://github.com/ashishsinha1602/oci-sandbox-factory
- What the Free Tier edition can and cannot build: https://github.com/ashishsinha1602/oci-sandbox-factory/blob/main/docs/FREE-TIER.md
- Overview and cost breakdown: https://ashishsinha1602.github.io/oci-sandbox-factory/
Apache-2.0. The Terraform for the install and for every sandbox type is public, so you can read exactly what lands in your tenancy before you run it.
If you try it on Free Tier and something is declined that you expected to work, tell me in the comments — that list is the part I most want to get right.
Top comments (2)
Staying inside a free tier with no card on file is the cheapest possible cost strategy, the real engineering challenge is keeping the sandbox factory from accidentally spinning up something that falls outside the free tier's limits
What guardrails stop it from drifting past the free tier boundaries?
Good question. Four layers, and one of them is off by default, which I should say plainly.
1. The edition changes what gets built, not just what is permitted. Container Instances are not Always Free, so
edition = "free"runs the same worker image under podman on one Always Free VM instead.worker_shapeis validated to the two Always Free shapes only, so Terraform refuses anything else before the API is ever called.2. Compartment quotas are the real hard stop, because OCI enforces them server-side rather than the factory policing itself:
The defaults are exactly the Always Free envelope (4 OCPU / 24 GB Arm, 2 autonomous databases), and GPU, dedicated and ExaCC are zeroed, so nobody can launch one by hand either.
The honest gap:
enable_quotasdefaults tofalse. Quota names vary between tenancies and I did not want a first apply to die on a name mismatch, so you confirm them withoci limits service listand switch it on. Out of the box that layer is off, and it is the weakest part of this.3. TTL, which in practice matters more than any single cap. On a free tier the thing that gets you is not one oversized resource, it is fifteen small ones nobody deleted. Every sandbox is tagged
sbx.expires;ttl_daysdefaults to 3 with a validated hard cap of 30, and the reaper destroys the stack after that date.4. A monthly budget on the compartment, with threshold alerts and a forecast-100% alert. Not a stop, but it tells you before the invoice does.
One design choice does more work than the caps: on the free edition a sandbox that asks for a database gets a schema in the control database rather than its own ADB. Otherwise two sandboxes would eat the entire free allowance of two autonomous databases.