In Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.
At a glance
| Status | In Oracle certification review |
|---|
| Version | 5.0.9 |
|---|
| Platform | Oracle Linux 9 |
|---|
| Ports open in the host firewall | SSH (22/tcp), 9042/tcp |
|---|
| Category | Databases |
|---|
| Upstream licence | Apache-2.0 |
|---|
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
|---|
Quick start
This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.
After launch:
- Connect over SSH as the opc user with the key you supplied at launch:
ssh opc@PUBLIC_IP
- Cassandra runs as a systemd service bound to loopback (CQL 9042; inter-node 7000 and JMX 7199 are loopback too). First boot takes two to three minutes: the node starts, then cassandra-firstboot.service creates your superuser and retires the stock one. Check both:
sudo systemctl status cassandra cassandra-firstboot
nodetool status (UN = Up/Normal)
- The superuser dcaadmin and its password were generated uniquely for this instance at first boot. Read them (root only):
sudo cat /root/.cassandra_default_credentials
The stock cassandra/cassandra role was given a random password with LOGIN and SUPERUSER revoked; it cannot be used.
- Smoke-test from the instance (cqlsh prompts for the password, so it never lands in shell history):
cqlsh -u dcaadmin 127.0.0.1 -e 'SELECT release_version FROM system.local'
- To reach the node from your application tier, expose it deliberately — in /etc/cassandra/conf/cassandra.yaml set rpc_address: 0.0.0.0 and broadcast_rpc_address: PRIVATE_IP (the instance's private IP) (so the 127.0.0.1 commands in steps 4 and 7 keep working), then:
sudo systemctl restart cassandra
Port 9042 is already permitted in the host firewall. Restrict it in your VCN security list to the application tier's CIDR; never expose it to the internet, and configure client_encryption_options with your own certificate before traffic crosses a subnet boundary. The inter-node (7000/7001) and JMX (7199) ports remain blocked by the host firewall even after this change. To add nodes, set listen_address and seeds on every node, keep cluster_name identical, and open 7000/tcp in firewalld to cluster members only.
- Data lives in /var/lib/cassandra (data, commitlog, hints, saved_caches). For anything beyond evaluation, attach a block volume: stop the service, copy the directory to the volume preserving ownership (rsync -a), mount it at /var/lib/cassandra, and start the service. The first-boot marker /var/lib/cassandra/.initialized travels with the data; starting from an empty directory re-runs the rotation at the next reboot and rewrites /root/.cassandra_default_credentials.
- Rotate the superuser password at any time:
cqlsh -u dcaadmin 127.0.0.1 -e "ALTER ROLE dcaadmin WITH PASSWORD = 'NEW_PASSWORD'"
then update /root/.cassandra_default_credentials. Create least-privilege roles for applications with CREATE ROLE and GRANT.
- The Java heap is auto-sized by cassandra-env.sh (half of RAM, capped at 31744 MB with the G1 collector this image uses): 8 GB on a 16 GB shape. To pin it, set -Xms and -Xmx together in /etc/cassandra/conf/jvm-server.options and restart the service.
The image is CVE-patched at build time. Apply ongoing updates, including Cassandra 5.0.x fixes from the Apache repository, with:
sudo dnf -y update && sudo systemctl restart cassandra
Your cassandra.yaml edits survive package updates (new defaults arrive as .rpmnew files beside them).
What the image provides
- Apache Cassandra 5.0.9, the current General Availability release, installed from the Apache Software Foundation's official RPM repository for the 5.0 series with repository-signature and package-signature verification enforced against the project's published signing keys, running on OpenJDK 17 from the Oracle Linux 9 AppStream channel as the dedicated unprivileged cassandra service. The repository remains enabled so 5.0.x security fixes flow through dnf update.
- Safe-by-default network posture: the node listens on loopback until you expose it deliberately with one documented configuration change. The CQL port (9042) is declared in the host firewall; the inter-node (7000/7001) and JMX (7199) ports stay behind the firewall's default-deny.
- Authentication and authorization on from the first boot, with an instance-unique superuser generated on first boot and surfaced to the operator over SSH. The stock cassandra/cassandra superuser every Cassandra installation ships with is neutralized before the node finishes initializing — never a shared secret baked into the image.
- A locked-down systemd service and security hardening aligned to the Oracle Cloud Marketplace image standards: SELinux enforcing, host firewall default-deny with only SSH and 9042 permitted, no account with a usable password, no stray keys, and the image fully patched at build time.
Still stuck?
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.
Apache®, Apache Cassandra® and Cassandra® are registered trademarks or trademarks of The Apache Software Foundation. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by The Apache Software Foundation.