Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / Apache Cassandra

In Oracle review

DCA Hardened NoSQL Database for Apache Cassandra — Support & Quick Start

A hardened, CVE-patched virtual machine image running Apache Cassandra® — the open-source, masterless distributed NoSQL database built for always-on workloads that scale writes linearly across nodes, racks and regions — on Oracle Linux 9.

In Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusIn Oracle certification review
Version5.0.9
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 9042/tcp
CategoryDatabases
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@PUBLIC_IP
  2. Cassandra runs as a systemd service bound to loopback (CQL 9042; inter-node 7000 and JMX 7199 are loopback too). First boot takes two to three minutes: the node starts, then cassandra-firstboot.service creates your superuser and retires the stock one. Check both:
    sudo systemctl status cassandra cassandra-firstboot
    nodetool status        (UN = Up/Normal)
  3. The superuser dcaadmin and its password were generated uniquely for this instance at first boot. Read them (root only):
    sudo cat /root/.cassandra_default_credentials

    The stock cassandra/cassandra role was given a random password with LOGIN and SUPERUSER revoked; it cannot be used.

  4. Smoke-test from the instance (cqlsh prompts for the password, so it never lands in shell history):
    cqlsh -u dcaadmin 127.0.0.1 -e 'SELECT release_version FROM system.local'
  5. To reach the node from your application tier, expose it deliberately — in /etc/cassandra/conf/cassandra.yaml set rpc_address: 0.0.0.0 and broadcast_rpc_address: PRIVATE_IP (the instance's private IP) (so the 127.0.0.1 commands in steps 4 and 7 keep working), then:
    sudo systemctl restart cassandra

    Port 9042 is already permitted in the host firewall. Restrict it in your VCN security list to the application tier's CIDR; never expose it to the internet, and configure client_encryption_options with your own certificate before traffic crosses a subnet boundary. The inter-node (7000/7001) and JMX (7199) ports remain blocked by the host firewall even after this change. To add nodes, set listen_address and seeds on every node, keep cluster_name identical, and open 7000/tcp in firewalld to cluster members only.

  6. Data lives in /var/lib/cassandra (data, commitlog, hints, saved_caches). For anything beyond evaluation, attach a block volume: stop the service, copy the directory to the volume preserving ownership (rsync -a), mount it at /var/lib/cassandra, and start the service. The first-boot marker /var/lib/cassandra/.initialized travels with the data; starting from an empty directory re-runs the rotation at the next reboot and rewrites /root/.cassandra_default_credentials.
  7. Rotate the superuser password at any time:
    cqlsh -u dcaadmin 127.0.0.1 -e "ALTER ROLE dcaadmin WITH PASSWORD = 'NEW_PASSWORD'"
    then update /root/.cassandra_default_credentials. Create least-privilege roles for applications with CREATE ROLE and GRANT.
  8. The Java heap is auto-sized by cassandra-env.sh (half of RAM, capped at 31744 MB with the G1 collector this image uses): 8 GB on a 16 GB shape. To pin it, set -Xms and -Xmx together in /etc/cassandra/conf/jvm-server.options and restart the service.

The image is CVE-patched at build time. Apply ongoing updates, including Cassandra 5.0.x fixes from the Apache repository, with:

sudo dnf -y update && sudo systemctl restart cassandra

Your cassandra.yaml edits survive package updates (new defaults arrive as .rpmnew files beside them).

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

Apache®, Apache Cassandra® and Cassandra® are registered trademarks or trademarks of The Apache Software Foundation. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by The Apache Software Foundation.