Oracle Cloud Free Tier VPS: Run Your Own Server for Free
Oracle Cloud gives you a real Linux server for free, for good. Here are the current limits (many guides still show the old ones), how to create the server, the firewall trap that blocks every port, how to keep it from being reclaimed, and what to run on it.
Oracle Cloud's free tier is the only big cloud that gives you a real Linux server free for good, not for a 12-month trial. It is enough for a website, a personal VPN, a chat server or a small game server. It also has two traps that stop most people: the server is often “out of capacity”, and Oracle's Ubuntu image blocks every port you open until you change one more firewall.
This guide uses the limits from Oracle's own page as of October 2026, which are smaller than many older guides say, and walks through creating the server, opening ports properly, and keeping it.
What you get for free
| Resource | Always Free amount |
|---|---|
| Arm server (Ampere A1) | 1,500 OCPU hours and 9,000 GB hours a month, which Oracle says equals 2 OCPUs and 12 GB of memory. One server, or two smaller ones. |
| AMD servers (E2.1.Micro) | Up to 2 servers, each with 1/8 OCPU and 1 GB of memory |
| Disk | 200 GB in total for boot and block volumes |
| Outbound traffic | 10 TB a month |
Many guides still say 4 cores and 24 GB: Oracle's page now lists half of that for Always Free accounts. Free resources only exist in your home region, the region you choose when you sign up, and that choice cannot be changed later.
Before you sign up
- You need a credit or debit card for identity checks. Oracle places a small temporary charge and does not bill you for Always Free resources. Prepaid and virtual cards are often refused.
- Choose the home region carefully: close to your visitors, because every free server lives there. Popular regions run out of free Arm servers more often.
- One free account per person. Accounts that look like duplicates are closed.
Create the server
- In the Oracle Cloud console, open Compute, Instances, Create instance.
- Image: choose Canonical Ubuntu 24.04.
- Shape: choose Ampere, VM.Standard.A1.Flex, and set 2 OCPUs and 12 GB of memory (or 1 OCPU and 6 GB if you want two servers). For a tiny job, the AMD VM.Standard.E2.1.Micro also works.
- Networking: let it create a new virtual cloud network with a public subnet, and keep Assign a public IPv4 address on.
- SSH keys: choose Generate a key pair and download the private key. Without it you cannot log in.
- Click Create. After a minute or two the server shows its public IP.
“Out of host capacity”? That means there are no free Arm servers in that part of the region right now. Try another availability domain in the same screen, try a smaller shape (1 OCPU and 6 GB), or try again at a different time of day. It is not a problem with your account.
Log in from a terminal with the key you downloaded:
# Windows (PowerShell), macOS or Linux: the key file you downloaded and the server's public IP
ssh -i ~/Downloads/ssh-key.key ubuntu@203.0.113.10
# macOS and Linux only: the key must be private, or ssh refuses it
chmod 600 ~/Downloads/ssh-key.key
Open ports: there are two firewalls
This is where most people get stuck. To reach a website or VPN on the server, the port must be open in both places.
1. The security list in the cloud network. Open Networking, Virtual cloud networks, your network, the public subnet, and its Default Security List. Click Add Ingress Rules: source CIDR 0.0.0.0/0, protocol TCP, destination port 80,443. For WireGuard, add a second rule with protocol UDP and port 51820.
2. iptables on the server. Oracle's Ubuntu image comes with its own firewall rules that allow only SSH, and they end with a rule that rejects everything else. A rule added after it is never reached, so a normal iptables -A or most copy-pasted commands do nothing. Insert the new rules above the reject rule instead:
# Oracle's Ubuntu images end the INPUT rules with a REJECT. Find its line number:
N=$(sudo iptables -L INPUT --line-numbers | awk '$2 == "REJECT" {print $1; exit}')
# Insert the new rules above it (web, HTTPS, WireGuard)
sudo iptables -I INPUT "${N:-1}" -p tcp --dport 80 -m state --state NEW -j ACCEPT
sudo iptables -I INPUT "${N:-1}" -p tcp --dport 443 -m state --state NEW -j ACCEPT
sudo iptables -I INPUT "${N:-1}" -p udp --dport 51820 -j ACCEPT
# Keep them after a reboot, then check the order
sudo netfilter-persistent save
sudo iptables -L INPUT --line-numbers
| Part | What it does |
|---|---|
iptables -L INPUT --line-numbers | Lists the rules with their numbers; on a new server the REJECT rule is the last one |
awk '$2 == "REJECT"' | Finds that rule's number, so the commands work even if your list is a little different |
iptables -I INPUT "$N" | Inserts each rule at that position, which pushes the REJECT rule down below it |
${N:-1} | If there is no REJECT rule, the rule simply goes first |
netfilter-persistent save | Saves the rules, so they come back after a reboot |
Do not switch on ufw on top of these rules: the two firewalls get in each other's way, and a mistake can lock you out of SSH. Check that everything works with a test web server:
sudo apt update
sudo apt install -y nginx
# Now open http://203.0.113.10 in your browser: you should see "Welcome to nginx!"
Keep your free server from being reclaimed
Oracle's page says that idle Always Free servers may be reclaimed. A server counts as idle when, over 7 days, its CPU use (95th percentile) and network use are below 20%, and on Arm servers memory use is too. In practice:
- A server that does real work, such as a website with visitors, a VPN you use, or a game server, is rarely idle by that rule. Memory counts on Arm, and most real programs use more than 20% of it.
- A server you only touch once a month is at risk. Keep backups of anything you would miss, for example by copying your files and database dumps to your own computer.
- Upgrading the account to Pay As You Go keeps the Always Free resources free and often makes it easier to get Arm capacity. Set a budget alert first, so nothing paid starts by mistake.
What to run on it
| Use | How |
|---|---|
| A personal VPN | Our WireGuard VPS guide has a setup script that already works with Oracle's firewall rules. Open UDP 51820 in the security list. |
| Websites | Install Apache, MySQL and PHP, or a free control panel if you prefer clicking to typing |
| A chat server | An XMPP server with a TURN server for calls, as in our ejabberd and TURN guide. The TURN server needs its UDP ports open in both firewalls. |
| A Minecraft server | 2 Arm cores and 12 GB are enough for a small group of friends. Open TCP 25565 in both firewalls. See below. |
The Arm server runs Arm (aarch64) programs. Almost everything in Ubuntu's own packages works, but check that a program you download separately offers an Arm build; if it does not, use the AMD micro server.
A Minecraft server on the free tier
Copy the current server download link from the official Minecraft Java server page, then run:
sudo apt install -y openjdk-25-jre-headless # Minecraft 26.1 and newer need Java 25
mkdir ~/minecraft && cd ~/minecraft
wget -O server.jar 'PASTE-THE-SERVER-DOWNLOAD-LINK-FROM-minecraft.net'
java -Xmx8G -jar server.jar nogui # the first run creates eula.txt and stops
sed -i 's/eula=false/eula=true/' eula.txt # you accept Minecraft's EULA
java -Xmx8G -jar server.jar nogui
If openjdk-25 is not found, your Ubuntu version is too old for it: create the server with a newer Ubuntu image. To keep the server running after you log out, start it inside screen or tmux, or make it a systemd service.
From a free server to a service with users
The free tier is perfect for learning and personal use. For an app or website that strangers depend on, plan for more:
- A paid VPS without reclaim rules or capacity waits; our VPS comparison shows the cheap options
- Servers in more than one region, so users far away also get good speed
- Automatic backups and monitoring, so you know about problems before your users do
- Software built for many users, where devices and accounts are added automatically instead of by hand
Apps that run on your own server
A free Oracle server is a good first home for the server side of our apps:
- VPN app source code: WireGuard and OpenVPN in one list, with a registration script and IP pool that run on your WireGuard server, so every phone gets its own key and address automatically
- Live video chat app and video dating app: chat and calls on your own XMPP and TURN servers, with no per-minute fees