Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / Apache Airflow

In Oracle review

DCA Hardened Data Pipeline Orchestrator for Apache Airflow — Support & Quick Start

A hardened, CVE-patched virtual machine image running Apache Airflow® — the open-source platform to author, schedule and monitor data pipelines as Python code — on Oracle Linux 9.

In Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusIn Oracle certification review
Version3.3.2
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 8080/tcp
CategoryApplication development
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@PUBLIC_IP
  2. Apache Airflow 3.3.2 runs as four systemd services (API server with the web UI and REST API, scheduler, DAG processor, triggerer) on a local PostgreSQL 16 metadata database; the API server listens on loopback only. On this instance's first boot, airflow-firstboot generated its keys and admin account before the services started; allow a minute or two. Check status and health:
    sudo systemctl status airflow-firstboot airflow-api-server airflow-scheduler airflow-dag-processor airflow-triggerer
    curl -s http://127.0.0.1:8080/api/v2/monitor/health

    If first boot failed, sudo journalctl -u airflow-firstboot names the cause; it runs again on every boot until it completes, and the services wait for it.

  3. The admin password, the Fernet key that encrypts stored connections and variables, and the session and token signing keys were all generated uniquely for this instance at first boot. Read the admin credentials (root only):
    sudo cat /root/.airflow_default_credentials

    Rotate the password at any time; the command prompts twice, so the password never lands in shell history or the process list:

    sudo /opt/airflow/bin/airflow users reset-password --username admin
  4. Open the UI from your workstation through an SSH tunnel, with nothing exposed:
    ssh -L 8080:127.0.0.1:8080 opc@PUBLIC_IP
    then browse http://localhost:8080 and sign in as admin. For the REST API, exchange the credentials for a token, then send it as a bearer token:
    curl -s -X POST http://127.0.0.1:8080/auth/token -H 'Content-Type: application/json' -d '{"username":"admin","password":"YOUR_PASSWORD"}'
    curl -s http://127.0.0.1:8080/api/v2/dags -H 'Authorization: Bearer ACCESS_TOKEN'
  5. DAG files go in /var/lib/airflow/dags (new files are picked up within a minute). Run the included smoke-test DAG, then watch it succeed in the UI:
    sudo install -o airflow -g airflow -m 0644 /opt/airflow/examples/dca_smoke_test.py /var/lib/airflow/dags/
    sudo /opt/airflow/bin/airflow dags reserialize
    sudo /opt/airflow/bin/airflow dags unpause dca_smoke_test
    sudo /opt/airflow/bin/airflow dags trigger dca_smoke_test
  6. To serve the UI and REST API beyond the instance, expose the API server deliberately:
    sudo sed -i 's/^host = 127.0.0.1$/host = 0.0.0.0/' /etc/airflow/airflow.cfg
    sudo systemctl restart airflow-api-server

    Port 8080 is already permitted in the host firewall. Restrict it in your VCN security list to your administrators' and application tier's CIDRs, and put TLS in front (an OCI load balancer or a reverse proxy) before any password crosses a network; never expose it to the internet. PostgreSQL has no TCP listener at all, and the scheduler and triggerer log servers (8793, 8794) are disabled.

  7. Configuration is /etc/airflow/airflow.cfg (root:airflow, mode 0640); run the Airflow CLI as sudo /opt/airflow/bin/airflow COMMAND. Task logs are in /var/log/airflow. The metadata database lives in /var/lib/pgsql/data and is reached over the local socket with peer authentication, so no database password exists. For anything beyond evaluation, attach a block volume for /var/lib/pgsql and raise [core] parallelism (8 concurrent tasks by default) to suit the shape.

The image is CVE-patched at build time. Apply ongoing operating-system, Python and PostgreSQL updates with:

sudo dnf -y update

Airflow itself is pinned in the /opt/airflow/venv virtual environment (Python 3.12); new Airflow releases ship as new versions of this image.

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

Apache Airflow, Apache, Airflow and the Airflow logo are either registered trademarks or trademarks of The Apache Software Foundation. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by The Apache Software Foundation.