In Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.
At a glance
| Status | In Oracle certification review |
|---|
| Version | 3.3.2 |
|---|
| Platform | Oracle Linux 9 |
|---|
| Ports open in the host firewall | SSH (22/tcp), 8080/tcp |
|---|
| Category | Application development |
|---|
| Upstream licence | Apache-2.0 |
|---|
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
|---|
Quick start
This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.
After launch:
- Connect over SSH as the opc user with the key you supplied at launch:
ssh opc@PUBLIC_IP
- Apache Airflow 3.3.2 runs as four systemd services (API server with the web UI and REST API, scheduler, DAG processor, triggerer) on a local PostgreSQL 16 metadata database; the API server listens on loopback only. On this instance's first boot, airflow-firstboot generated its keys and admin account before the services started; allow a minute or two. Check status and health:
sudo systemctl status airflow-firstboot airflow-api-server airflow-scheduler airflow-dag-processor airflow-triggerer
curl -s http://127.0.0.1:8080/api/v2/monitor/health
If first boot failed, sudo journalctl -u airflow-firstboot names the cause; it runs again on every boot until it completes, and the services wait for it.
- The admin password, the Fernet key that encrypts stored connections and variables, and the session and token signing keys were all generated uniquely for this instance at first boot. Read the admin credentials (root only):
sudo cat /root/.airflow_default_credentials
Rotate the password at any time; the command prompts twice, so the password never lands in shell history or the process list:
sudo /opt/airflow/bin/airflow users reset-password --username admin
- Open the UI from your workstation through an SSH tunnel, with nothing exposed:
ssh -L 8080:127.0.0.1:8080 opc@PUBLIC_IP
then browse http://localhost:8080 and sign in as admin. For the REST API, exchange the credentials for a token, then send it as a bearer token:
curl -s -X POST http://127.0.0.1:8080/auth/token -H 'Content-Type: application/json' -d '{"username":"admin","password":"YOUR_PASSWORD"}'
curl -s http://127.0.0.1:8080/api/v2/dags -H 'Authorization: Bearer ACCESS_TOKEN'
- DAG files go in /var/lib/airflow/dags (new files are picked up within a minute). Run the included smoke-test DAG, then watch it succeed in the UI:
sudo install -o airflow -g airflow -m 0644 /opt/airflow/examples/dca_smoke_test.py /var/lib/airflow/dags/
sudo /opt/airflow/bin/airflow dags reserialize
sudo /opt/airflow/bin/airflow dags unpause dca_smoke_test
sudo /opt/airflow/bin/airflow dags trigger dca_smoke_test
- To serve the UI and REST API beyond the instance, expose the API server deliberately:
sudo sed -i 's/^host = 127.0.0.1$/host = 0.0.0.0/' /etc/airflow/airflow.cfg
sudo systemctl restart airflow-api-server
Port 8080 is already permitted in the host firewall. Restrict it in your VCN security list to your administrators' and application tier's CIDRs, and put TLS in front (an OCI load balancer or a reverse proxy) before any password crosses a network; never expose it to the internet. PostgreSQL has no TCP listener at all, and the scheduler and triggerer log servers (8793, 8794) are disabled.
- Configuration is /etc/airflow/airflow.cfg (root:airflow, mode 0640); run the Airflow CLI as sudo /opt/airflow/bin/airflow COMMAND. Task logs are in /var/log/airflow. The metadata database lives in /var/lib/pgsql/data and is reached over the local socket with peer authentication, so no database password exists. For anything beyond evaluation, attach a block volume for /var/lib/pgsql and raise [core] parallelism (8 concurrent tasks by default) to suit the shape.
The image is CVE-patched at build time. Apply ongoing operating-system, Python and PostgreSQL updates with:
sudo dnf -y update
Airflow itself is pinned in the /opt/airflow/venv virtual environment (Python 3.12); new Airflow releases ship as new versions of this image.
What the image provides
- Apache Airflow 3.3.2, the current stable release, in an isolated Python 3.12 environment. Every dependency is held to Airflow's official constraints file for this release and installed only from wheels whose published SHA-256 checksums are verified, and the Airflow core packages are additionally checked against the Apache Software Foundation's published SHA-512 checksums and the release manager's PGP signature at build time. Python 3.12 and PostgreSQL 16 come from the Oracle Linux 9 AppStream repository, so they receive security errata through dnf update.
- A complete single-node deployment: the Airflow 3 API server (web UI, REST API and the task Execution API), the scheduler with the LocalExecutor (8 concurrent task slots, adjustable), the DAG processor and the triggerer, each a locked-down systemd service running as the dedicated unprivileged airflow user, on a local PostgreSQL 16 metadata database.
- No shared secrets: the admin password, the Fernet key that encrypts stored connections and variables, and the session and token signing keys are all generated uniquely on each instance's first boot, never baked into the image, and the admin password is verified against its stored hash before it is surfaced to the operator over SSH. The metadata database is reached over a local socket with peer authentication, so no database password exists at all.
- Password-protected sign-in through the Flask AppBuilder (FAB) auth manager, with role-based access control, rate-limited UI sign-in and token-based REST API access. Example DAGs are not loaded; a small smoke-test DAG is included for you to copy in and run.
- Safe-by-default network posture: the API server listens on loopback until you expose it deliberately with one documented setting, and the UI is reachable at once through an SSH tunnel. PostgreSQL has no TCP listener, and the scheduler and triggerer log servers are disabled. Only SSH and port 8080 are declared in the host firewall.
- Security hardening aligned to the Oracle Cloud Marketplace image standards: SELinux enforcing, host firewall default-deny, SSH key-only, no account with a usable password, no stray keys, and the image fully patched at build time.
Still stuck?
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.
Apache Airflow, Apache, Airflow and the Airflow logo are either registered trademarks or trademarks of The Apache Software Foundation. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by The Apache Software Foundation.