Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Docs / DCA Hardened Key-Value Store — for Valkey™

DCA Hardened Key-Value Store — for Valkey™ — documentation & support card

Valkey 9.1 on loopback with protected mode on and a password generated on each VM's first boot — none ships in the image.

Install Configure Troubleshoot Security

At a glance

TypeHardened VM image
Upstream / licenseValkey (BSD-3-Clause) — see licenses
VersionValkey 9.1.2 (official prebuilt Ubuntu 24.04 x86-64 binaries from download.valkey.io, sha256-verified) on Ubuntu 24.04 LTS; Google Cloud image built 2026-10-07. Exact image version: see the listing. Current builds: release notes.
Architecturex86-64
SizingAny current-generation instance with ≥ 4 vCPU (pay-as-you-go floor); 8 vCPU recommended for production.

Marketplaces

Network ports

PortPurposeState
22SSH — key-only, OS Login (IAM); the deployment package adds no SSH ruleyour VPC's firewall rules
6379Valkey — bound to 127.0.0.1 and ::1 (bind in /etc/valkey/valkey.conf)customer-must-open (config + firewall toggle)

"customer-must-open" means a cloud firewall rule and, where noted, an in-image configuration change — both deliberate. Closed by default is the design.

Access & credentials

No shared or default credentials are included in this image. Access uses the SSH key you supply at launch; any application credential is generated uniquely on your instance at first boot and stored only there — we never know it.

Log in: SSH in with OS Login (gcloud compute ssh INSTANCE_NAME --zone ZONE --tunnel-through-iap), then use valkey-cli with this VM's password in VALKEYCLI_AUTH.

A 32-character password generated on THIS VM's first boot by valkey-firstboot.service: requirepass for the default user in /etc/valkey/auth.conf (root:valkey 0640), with your copy in /root/valkey-credentials.txt (root-only, 0600). No password exists in the image.

sudo sed -n 's/^VALKEY_PASSWORD=//p' /root/valkey-credentials.txt

Rotation: Edit requirepass in /etc/valkey/auth.conf, run sudo systemctl restart valkey, then update /root/valkey-credentials.txt (or your secret store) and every client.

Step-by-step: first login / credentials.

Data & dependencies

Operate

Known limitations

Single node: no replicas, Sentinel or TLS listener are configured. The deployment package creates one boot disk and no separate data disk.

Support

Email support@dcassociatesgroup.com — first response within 1 business day (US Eastern), most tickets same-day. To escalate an open ticket, reply "ESCALATE"; it is reviewed by the founder within 1 business day. Security reports: vulnerability disclosure.

Privacy: policy · Terms: terms · Security practices: security & trust · Vulnerability reports: disclosure policy

Valkey™ names the open-source software this image packages. Derek Coleman & Associates Inc is not affiliated with or endorsed by the Valkey project.