OrFA OrFA
Coming soon

OrFA

Oracle Fleet Administration — inventory, inspect and report across an entire Oracle estate, from the terminal.

OrFA is in final testing ahead of general release. Early access is open now: tell us about your estate and we will get you a build.

Request early access →

No tracking, no mailing list, no third party — your details come to us and nowhere else.

The problem

If you run more than a handful of Oracle databases, the inventory lives in a spreadsheet and the spreadsheet is wrong. Answering one question about the estate — who is out of compliance, what has not been backed up, which databases are unencrypted — means logging into each host in turn. OrFA asks the whole fleet at once, in parallel, from one command line.

Every database, correctly counted

A Data Guard pair is two manageable rows and one database. A four-node RAC is one. Identity comes from the DBID, so a host renamed or a standby that changes role does not become a second database in your inventory.

$ orfa inv list
ID    HOSTNAME           DB_UNIQUE_NAME INSTANCE    TOPOLOGY             STATUS   CRITICAL   LIFECYCLE  IDENTITY
----------------------------------------------------------------------------------------------------------------
3     rac01-scan.exam... rac01db        rac01db1    RAC×2                ACTIVE   -          -          ✓
2     dbhost-dr01.exa... STDDB_STBY     STDDB       DG standby (mounted) ACTIVE   -          -          ✓
1     dbhost-pr01.exa... STDDB          STDDB       DG primary           ACTIVE   -          -          ✓

Total databases: 3
Licensed databases: 2  (rows sharing a DBID are one database)
  • STDDB_STBY + STDDB   (dbid 477923968)

Ask the whole estate one question

The same commands that inspect one database roll up across all of them, so "is anything past its RPO?" is a command rather than a project.

$ orfa db backup --fleet
Fleet backup currency  (2 databases, RPO 1d)
  DATABASE                                  ROLE     LAST_GOOD_BACKUP  AGE       STALE/TOTAL  STATUS
  ----------------------------------------  -------  ----------------  --------  -----------  -----------------
  rac01db                                   primary  never             never     5/5          never backed up ⚠
  STDDB_STBY + STDDB  (backed up on STDDB)  primary  2026-01-19 12:07  202d ago  4/4          behind RPO ⚠

  0 current, 2 in breach   (STALE/TOTAL = datafiles not backed up within 1d)

Least privilege, by default

OrFA reads a fixed set of data-dictionary objects and asks for exactly those — no SELECT ANY DICTIONARY, no SELECT_CATALOG_ROLE. It generates the role DDL for your DBA to read and apply, rather than asking you to trust it.

$ orfa db grants generate --id 3 --user ORFA_OPS_USER
Fleet OrFA privilege check  (2 databases)
  DATABASE  ACCESSIBLE  MISSING  FLAG
  --------  ----------  -------  ----
  RAC01DB   78/78       0
  STDDB     78/78       0
  Unreachable: STDDB

It does not change your databases

Inspection is read-only. Where a change is the point — RMAN scripts, compliance remediation, role DDL — OrFA generates a script for you to review and hands it over. It does not run it, and it never kills sessions.

Nothing leaves your network

No telemetry, no phone-home, no cloud dependency. OrFA runs where you run it and keeps its inventory in your own SQLite file or your own Oracle schema. It is a command-line tool: no agents to deploy, no repository server, no listener on your database hosts.

WHERE YOU RUN IT orfa one jar · Java 17 · no daemon Inventory your SQLite file, or your own Oracle schema Nothing is stored anywhere else. SSH :22 discovery, OS facts, RMAN scripts JDBC :1521 read-only inspection queries both outbound, from here YOUR ESTATE Database hosts standalone · RAC · Data Guard Oracle instances queried through a least-privilege role you create and review No agent. No listener. No inbound. No telemetry · no phone-home · no cloud dependency · nothing installed on a database host

Coming: OrFA AI

OrFA is being extended so an AI agent can do fleet work through it, starting with a diagnostic agent that triages before a human opens the ticket. The access path is an MCP server, so it works with the agent tooling you already use.

The parts that matter to a security review are settled already: the AI components are separate modules that simply are not installed if you do not want them, the first release is read-only, the agent uses your model account and key with Topaz never in the data path, and its tools go through OrFA's own commands — so there is no second connection to your databases with its own privileges.

Roadmap, not shipped. Described here so you can judge the direction and object early.

Request early access

Tell us about your estate and we will come back to you when the build is ready. Only the first three are needed — the rest just means our first reply is a useful one.

We use this only to contact you about OrFA. We do not sell it, share it, or add you to a mailing list. Prefer email? sales@orfa.app.