
Want a low-cost, reliably fast remote desktop but don’t want to pay TeamViewer or AnyDesk subscriptions? This guide walks you through using Oracle Cloud's ARM Always Free tier to host a remote desktop (Ubuntu 22.04 arm64), with practical steps for RDP, SSH tunneling and a self-hosted Tenvo server option.
Oracle Cloud’s ARM Always Free tier will run a usable Linux desktop, and this guide walks it end to end on Ubuntu 22.04 arm64: Xfce, xrdp, SSH tunnelling, hardening. It also answers the question most tutorials skip — when a free ARM instance is genuinely the right call, and when connecting to a machine you already own through a managed relay is the shorter path.
Why use Oracle's ARM Always Free for remote desktop
Always Free Ampere A1 earns its place when you actually need an extra Linux box — a scratch dev machine, a jump host, an always-on Linux desktop you do not otherwise own. The Free Tier gives you an Arm-based compute allocation suitable for light-to-moderate desktop workloads: pick an arm64 OS image (Ubuntu 22.04 LTS works well), install a lightweight desktop like Xfce, and reach it over RDP through an SSH tunnel. If what you actually want is access to machines you already have, a new server is not the answer to that.
Honest note: Always Free is another vendor’s free tier — one region, no SLA, and idle instances can be reclaimed. That is fine for a lab box and wrong for anything that has to be up. If you need full GPU acceleration or low-latency pro graphics, plan on a paid GPU shape or a local workstation. This tutorial is for general desktop use, admin tasks, and remote support on the cheap.
What you’ll build — minimum components
- An Always Free Ampere (arm64) instance running Ubuntu 22.04 LTS (jammy).
- A lightweight desktop environment (Xfce) and xrdp for RDP connections.
- Secure access via SSH tunnel or restricted VCN security lists — no RDP port facing the internet.
Step 1 — create an Oracle Free account and pick the right image
Create an Oracle Cloud Free account (the Always Free tier is the option you want). In the OCI console: Compute > Instances > Create Instance. Make sure to select an Always Free–eligible Ampere (ARM) shape — the VM.Standard.A1.Flex family — and choose an amd64/arm64 image tagged as "Always Free eligible".
Pick an OS image: Ubuntu 22.04 LTS (arm64) is a stable choice with wide package support. When creating the instance, add your public SSH key for the default user (opc or ubuntu depending on image). Note the public IP assigned (or allocate a reserved public IP if you prefer a persistent address).
Step 2 — basic instance hardening and initial update
SSH into the instance from your workstation. Replace opc@PUBLIC_IP with the instance address and your key path as appropriate:
ssh -i ~/.ssh/id_rsa opc@PUBLIC_IP
Once connected, update the OS and set a permissive locale if needed:
sudo apt update && sudo apt upgrade -y sudo apt install -y curl ufw fail2ban
Enable UFW but keep SSH allowed for now:
sudo ufw allow OpenSSH sudo ufw enable sudo ufw status
Step 3 — install a desktop and xrdp (RDP)
For a remote desktop on ARM, pick a lightweight DE for responsiveness. Xfce is a common balance of features and speed:
sudo apt install -y xfce4 xfce4-goodies
Install xrdp (the package in Ubuntu 22.04 repositories works fine on arm64):
sudo apt install -y xrdp sudo systemctl enable --now xrdp
Configure xrdp to use Xfce. Create or replace ~/.xsession for the remote user:
echo "startxfce4" > ~/.xsession chmod +x ~/.xsession
Adjust /etc/xrdp/startwm.sh so it launches Xfce (edit as sudo): remove or comment the last two lines and add startxfce4 before exit 0. Also add the xrdp user to the ssl-cert group:
sudo adduser xrdp ssl-cert
Restart xrdp:
sudo systemctl restart xrdp
Step 4 — secure access: prefer SSH tunnel or tight security lists
Opening RDP (TCP/3389) to the internet is convenient but increases attack surface. Two safer options:
- SSH tunnel (recommended): keep 3389 closed in your VCN security lists and forward it over an SSH session from your workstation.
- Use OCI network security groups to restrict 3389 to a known IP range (not recommended for roaming clients).
SSH tunnel example (from your workstation):
ssh -i ~/.ssh/id_rsa -L 3389:localhost:3389 opc@PUBLIC_IP # Then point your local RDP client to 127.0.0.1:3389
With the tunnel active you’ll RDP to localhost as if the server were local. This avoids opening 3389 publicly and is easy to script or wrap in an SSH config entry.
Where Tenvo fits, and where it does not
Straight answer so you do not lose an afternoon to it: our Linux client ships as a Debian/Ubuntu package for amd64, so it does not install on an Ampere arm64 instance. On this box, RDP over an SSH tunnel is the setup. Tenvo is for the machines that are not this one — the Windows, macOS and amd64 Linux desktops you actually need to reach — and the question there is who operates the relay in between:
- Self-host the relay when a requirement forces it — a written compliance obligation that session traffic must not cross third-party infrastructure, isolated networks where an external relay is unreachable, or residency rules naming a jurisdiction you have to stay inside.
- Use the managed relay when nothing does — being on call, OS patching, key custody, certificate renewal and one region with no failover add up to a standing operations job that costs more than the subscription it replaces.
The full arithmetic — the VPS bill versus what running it actually costs — is broken down in our self-hosted remote desktop guide. If you land on the managed side, the tiers are Free $0, Lite $2.99/mo and Pro $7.99/mo on the pricing page.
Step 5 — performance tuning and tips
- Use a lightweight desktop (Xfce, LXDE) for responsiveness on lower OCPU counts.
- On the RDP client, reduce color depth to 16-bit and turn off desktop effects to lower bandwidth and CPU use.
- Enable compression in xrdp if available; also consider alternative protocols (VNC over SSH, or Tenvo) for different latency/quality trade-offs.
- If your workflow is GUI-heavy (video, 3D), Oracle’s free ARM instances won’t match a GPU-backed desktop; plan on a paid GPU instance or local workstation in that case.
Cost management and Oracle billing notes
The Always Free tier lets you run the Ampere instance at no charge while you stay within the Always Free limits. Watch the OCI console for any resources not marked "Always Free" (block volumes, public IPs and egress can incur charges if you exceed the free allowances). To avoid surprise bills, stop or terminate the instance when not in use and check the "Costs" view in the console.
If you outgrow Always Free and need larger shapes, Oracle bills compute by OCPU-hour and storage by GB-month — rates vary by region. If you plan to scale up, validate pricing in the OCI console before switching shapes.
Troubleshooting common issues
- Black screen after RDP login: ensure
~/.xsessioncontainsstartxfce4and that/etc/xrdp/startwm.shis set to launch it. - Connection refused on 3389: check that xrdp is running (
sudo systemctl status xrdp) and that you’re tunneling if 3389 is blocked by security lists. - Slow responsiveness: reduce desktop effects, lower RDP color depth, or switch to an even lighter desktop.
Security checklist before you go live
- Use SSH keys only; disable password authentication in
/etc/ssh/sshd_config. - Keep the machine updated: configure automatic security upgrades or run regular
apt update && apt upgrade. - Use fail2ban to throttle brute-force attempts and monitor logs in /var/log/auth.log.
- Never expose 3389 to the internet — tunnel RDP over SSH. On the machines where you run Tenvo instead, sessions are carried over TLS with a per-device certificate; a direct P2P path stays between the two endpoints, and on the relay fallback path TLS terminates at the relay. See our security primer at is remote desktop secure and the broader tips in Remote Desktop Security: What You Need to Know.
When to pick other tools
Quick cases where alternatives are better:
- You need low-latency remote access for GPU-bound graphics work: a paid GPU shape or a local workstation will beat a free ARM instance.
- You are supporting many seats and want central accounts, roles and one bill: that is what the business plans cover, rather than a hand-rolled VM.
- You want zero-setup help for a non-technical relative: skip the server entirely — install the client at both ends and connect by ID.
For a direct comparison of trade-offs among remote tools check our articles on best teamviewer alternatives and rustdesk vs anydesk.
Wrapping up — what you’ll have and next steps
By following this guide you’ll have an Always Free Oracle ARM instance running a usable remote desktop (Xfce + xrdp) with secure access via SSH tunneling. From here you can harden the instance, script start/stop to save resources, and expand to paid shapes if you need more CPU or GPU power. Worth keeping in view what comes with it: one region, no SLA, and a box you patch yourself.
So pick by your reason, not by the price tag. If a compliance rule, an isolated network or a residency requirement puts the infrastructure in your hands, keep going — our self-hosted remote desktop guide covers the relay side and the running costs, and the remote access setup guide has the hands-on notes. If nothing forces it, reach the machines you already have instead: Free $0, Lite $2.99/mo, Pro $7.99/mo on the pricing page, or the business plans for a team.
When you’re ready, spin up an Always Free Ampere VM in the OCI console and follow the steps above — and stop it when you are not using it, which is the honest cost of a free tier. For the desktops you already run, download the client and connect to them directly instead of standing up another server first.
Ready to try it yourself?
Free for 30 devices, no credit card. Up and connected in two minutes.