# How to Integrate Multicloud Providers (AWS, Azure, Google) with Oracle AI Database: A Complete Guide

> Seamlessly integrate AWS Azure and Google Cloud with Oracle AI Database using standard protocols Run identical Python code across clouds just update connection details and auth

- Repository: [Oracle Developers/oracle-ai-developer-hub](https://github.com/oracle-devrel/oracle-ai-developer-hub)
- Tags: how-to-guide
- Published: 2026-05-10

---

**Oracle AI Database supports multicloud deployment through standard client protocols, enabling you to run identical Python code across AWS, Azure, and Google Cloud by changing only the connection string and authentication method.**

Oracle AI Database (23ai/26ai) provides a converged, self-contained engine for relational data, hybrid vector indexes, and in-database ONNX embeddings that deploys seamlessly on AWS, Azure, and Google Cloud Platform. Because it exposes the standard Oracle client protocol, you can migrate AI workloads between clouds without rewriting application logic—only the data source name (DSN) and credential retrieval change. This guide demonstrates the implementation patterns found in the `oracle-devrel/oracle-ai-developer-hub` repository, including specific notebooks for each cloud provider.

## Deployment Models Across AWS, Azure, and Google Cloud

Oracle AI Database supports distinct deployment architectures on each cloud platform while maintaining identical SQL and vector search capabilities.

### AWS Deployment Options

On **Amazon Web Services**, you can deploy Oracle AI Database as a managed **RDS Oracle** instance or run the `gvenzl/oracle-free:23-full` Docker container on **EC2**. The connection endpoint follows the standard format `host:port/service_name` for RDS, or `localhost:1521` for containerized local development.

The reference implementation in [`notebooks/multicloud/oracle-aws-similarity-search.ipynb`](https://github.com/oracle-devrel/oracle-ai-developer-hub/blob/main/notebooks/multicloud/oracle-aws-similarity-search.ipynb) demonstrates similarity search against an RDS-hosted instance using `cx_Oracle` and local sentence-transformer embeddings.

### Azure Autonomous Database

**Microsoft Azure** offers **Autonomous Database @ Azure**, a fully managed service that exposes TLS-enabled endpoints at `adbinstance_high.adb.<region>.oraclecloud.com:1522/adbinstance_high`. This deployment eliminates infrastructure management while providing automatic patching and scaling.

See [`notebooks/multicloud/oracle-azure-similarity-search.ipynb`](https://github.com/oracle-devrel/oracle-ai-developer-hub/blob/main/notebooks/multicloud/oracle-azure-similarity-search.ipynb) for Azure-specific connection handling using Azure Active Directory tokens.

### Google Cloud Platform

On **Google Cloud**, deploy either **Autonomous Database @ GCP** (OCI-hosted) or container-based free-tier instances. The fully qualified TLS endpoints follow the same pattern as Azure, enabling consistent connection logic across both platforms.

The notebook [`notebooks/multicloud/create_ai_agent_memory_google.ipynb`](https://github.com/oracle-devrel/oracle-ai-developer-hub/blob/main/notebooks/multicloud/create_ai_agent_memory_google.ipynb) implements the **Oracle AI Database Agent Memory Package (OAMP)** against a Google-hosted instance.

## Cross-Cloud Authentication Strategies

Each cloud provider requires distinct credential handling, though all implementations follow the principle of *no hard-coded secrets*.

### AWS IAM Integration

The AWS notebook uses **`boto3`** to fetch temporary credentials from IAM roles or access keys. These credentials integrate with the Oracle JDBC driver via OCI's token-based authentication, allowing secure, rotating credential access without embedding passwords in connection strings.

### Azure Active Directory Tokens

For Azure deployments, the **`azure.identity`** library obtains Azure AD tokens through `DefaultAzureCredential()`. The token becomes the password in the TLS connection string, authenticated when calling `cx_Oracle.connect(dsn, mode=cx_Oracle.SYSDBA)`.

### Google Cloud Service Accounts

On GCP, **`google.auth`** loads service-account JSON keys via `google.auth.default()`. The resulting token authenticates the TLS connection to the Autonomous Database endpoint, ensuring secure access without manual password management.

## Implementing Vector Search (Same Code, Different Cloud)

The core vector search workflow remains identical across all three providers. After establishing the cloud-specific connection, you create **Hybrid Vector Indexes** that fuse vector similarity with keyword search through Reciprocal Rank Fusion.

### Creating the Hybrid Vector Index

Run this SQL once per table to enable approximate nearest neighbor search:

```python
import cx_Oracle

# DSN varies by cloud (AWS example shown)

dsn = "admin/Password123@//my-aws-oracle.c9p2k8z6p4h0.us-east-1.rds.amazonaws.com:1521/ORCLPDB1"
conn = cx_Oracle.connect(dsn)
cur = conn.cursor()

cur.execute("""
    CREATE VECTOR INDEX docs_vec_idx
    ON docs (vector_embedding)
    USING HNSW
    WITH (dim = 384, metric = 'COSINE')
""")

```

### Inserting Embeddings

Generate embeddings locally or via cloud LLMs, then persist them as binary data:

```python
from sentence_transformers import SentenceTransformer
import numpy as np

model = SentenceTransformer('all-MiniLM-L6-v2')
text = "Multicloud database integration example"
emb = model.encode(text)

cur.execute(
    "INSERT INTO docs (id, content, vector_embedding) VALUES (:1, :2, :3)",
    (1, text, emb.tobytes())
)
conn.commit()

```

### Performing Similarity Search

Query across vectors using native SQL functions:

```python
query_emb = model.encode("search query").tobytes()

cur.execute("""
    SELECT id, content, VECTOR_DISTANCE(vector_embedding, :1) AS dist
    FROM docs
    ORDER BY dist
    FETCH FIRST 5 ROWS ONLY
""", [query_emb])

for row in cur:
    print(f"ID: {row[0]}, Distance: {row[2]}")

```

## Integrating AWS Bedrock for LLM Embeddings

For AWS-specific deployments, generate embeddings using **Amazon Bedrock** before persisting to Oracle AI Database. The notebook [`notebooks/multicloud/oracle-db-aws-bedrock.ipynb`](https://github.com/oracle-devrel/oracle-ai-developer-hub/blob/main/notebooks/multicloud/oracle-db-aws-bedrock.ipynb) demonstrates this pattern:

```python
import boto3

bedrock = boto3.client('bedrock-runtime', region_name='us-east-1')
response = bedrock.invoke_model(
    body={'text': my_text}, 
    modelId='amazon.titan-embed-text-v1'
)
embedding = response['embedding']

# Store in Oracle AI Database using standard INSERT

```

## Building AI Agents with OAMP

The **Oracle AI Database Agent Memory Package** (`oracleagentmemory`, documented in [[`agent_memory/README.md`](https://github.com/oracle-devrel/oracle-ai-developer-hub/blob/main/agent_memory/README.md)](https://github.com/oracle-devrel/oracle-ai-developer-hub/blob/main/agent_memory/README.md)) provides a unified memory layer for LLM agents across all three clouds.

Once connected, the same API manages:

- **Episodic memory**: Chat logs stored in relational tables
- **Semantic memory**: Vectors stored in hybrid indexes  
- **Procedural memory**: Stored procedures exposed as `@Tool` methods

```python
from oracleagentmemory import MemoryManager

mm = MemoryManager(conn)
thread = mm.create_thread(name="multicloud-demo")
thread.add_memory(text="User asked about AWS integration")

```

This abstraction makes agents portable—moving from AWS to Azure requires only changing the connection initialization, not the memory management logic.

## Summary

- **Oracle AI Database** deploys on AWS (RDS/EC2), Azure (Autonomous Database), and GCP (Autonomous/Containers) using identical SQL and vector search capabilities.
- **Authentication differs by cloud**: AWS uses `boto3` IAM tokens, Azure uses `azure.identity` AD tokens, and GCP uses `google.auth` service accounts—none require hard-coded passwords.
- **Hybrid Vector Indexes** created with `CREATE VECTOR INDEX ... USING HNSW` enable cosine similarity search across all platforms with the same query syntax.
- **Reference notebooks** in `oracle-devrel/oracle-ai-developer-hub` provide working implementations: `oracle-aws-similarity-search.ipynb`, `oracle-azure-similarity-search.ipynb`, and `create_ai_agent_memory_google.ipynb`.
- **OAMP** provides a cloud-agnostic memory layer for AI agents, enabling episodic, semantic, and procedural memory persistence regardless of underlying infrastructure.

## Frequently Asked Questions

### How do I choose between RDS Oracle and Autonomous Database for multicloud deployment?

**RDS Oracle suits workloads requiring OS-level access or specific patch control**, while **Autonomous Database @ Azure and GCP** provide zero-administration operation with automatic tuning and scaling. For AI development, Autonomous Database simplifies TLS configuration and credential rotation, whereas RDS offers more flexibility for custom extensions.

### Is the vector distance calculation identical across AWS, Azure, and Google Cloud deployments?

**Yes.** The `VECTOR_DISTANCE` function and **Hybrid Vector Index** behavior are identical because they execute within the Oracle AI Database engine, not the underlying cloud infrastructure. Whether running on AWS RDS or Azure Autonomous Database, `ORDER BY VECTOR_DISTANCE(vector_embedding, :query)` returns the same mathematical results using the specified metric (COSINE, EUCLIDEAN, or DOT).

### Can I migrate an AI agent's memory from AWS to Azure without data loss?

**Yes.** Since OAMP stores memory in standard Oracle tables and vector indexes, you can export the schema using Oracle Data Pump or use Oracle GoldenGate for real-time replication between cloud instances. The `MemoryManager` class requires only a valid `cx_Oracle` connection, so pointing it to the new Azure endpoint instantly resumes operation with existing data.

### Does Oracle AI Database support native cloud IAM roles, or must I use database users?

**Oracle AI Database supports both models.** While traditional database users work everywhere, Autonomous Database @ Azure and GCP accept cloud identity tokens (Azure AD and Google IAM) as authentication credentials. AWS deployments typically use IAM to generate temporary database credentials or use **Oracle Cloud Infrastructure (OCI) Identity** integration when running Autonomous Database on dedicated infrastructure.