At a glance
| Status | Live on Oracle Cloud Marketplace |
|---|
| Version | 1.14.6 |
|---|
| Platform | Oracle Linux 9 |
|---|
| Ports open in the host firewall | SSH (22/tcp), 53/tcp, 53/udp |
|---|
| Category | Networking |
|---|
| Upstream licence | Apache-2.0 |
|---|
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
|---|
Quick start
This is the listing's usage information, verbatim.
After launch:
- Connect over SSH as the opc user with the key you supplied at launch:
ssh opc@<public-ip>
- CoreDNS runs as a systemd service, as the unprivileged coredns user (holding only CAP_NET_BIND_SERVICE), serving DNS on port 53 (TCP and UDP) on all interfaces as a caching forwarding resolver. Its health (8080) and readiness (8181) endpoints answer on 127.0.0.1 only. Check status:
sudo systemctl status coredns
- Smoke-test from the instance (dig ships in bind-utils:
sudo dnf -y install bind-utils if it is not present):
curl -s http://127.0.0.1:8080/health
curl -s http://127.0.0.1:8181/ready
dig @127.0.0.1 example.com
From a client your security list permits:
dig @<public-ip> example.com
- To serve your own zones, put a zone file (with its SOA and NS records) in /etc/coredns and add a server block to /etc/coredns/Corefile, for example:
example.internal:53 {
file /etc/coredns/db.example.internal
}
The reload plugin applies the change automatically within about 45 seconds (sudo journalctl -u coredns shows "Reloading complete"); to apply it immediately:
sudo systemctl restart coredns
- Port 53 (TCP and UDP) is already permitted in the host firewall and is the only port reachable from outside the instance; 8080 and 8181 stay on loopback and blocked. Restrict 53 in your VCN security list to your clients' CIDR. Never expose an open resolver to the internet: it will be abused for amplification attacks.
- Configuration and zone files live in /etc/coredns (the Corefile plus your zone files); the service's working directory is /var/lib/coredns. Upstream forwarders come from /etc/resolv.conf (the VCN resolver). Recommended sizing: at least 2 OCPU (4 vCPU) and 16 GB memory; scale OCPU with query volume.
The image is CVE-patched at build time. Apply ongoing OS updates with:
sudo dnf -y update
CoreDNS itself is a static binary in /usr/local/bin (not a package); CoreDNS fixes ship as new image versions.
What the image provides
- CoreDNS 1.14.6, installed from the project's official signed release with its SHA-256 checksum verified at build time, running as a dedicated unprivileged service.
- A working forwarding resolver out of the box, with caching, load-balancing, and health/readiness endpoints. Edit the Corefile to serve authoritative zones or add plugins.
- Least privilege for a network service: because DNS uses the privileged port 53, the service is granted only CAP_NET_BIND_SERVICE and nothing else, with a locked-down systemd sandbox (NoNewPrivileges, ProtectSystem, ProtectHome, PrivateTmp). The health and readiness endpoints are bound to loopback so port 53 is the only externally reachable port.
- Security hardening aligned to the Oracle Cloud Marketplace image standards: SELinux enforcing, host firewall default-deny with only SSH and DNS permitted, no account with a usable password, no stray keys, and the image fully patched at build time.
Still stuck?
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.
CoreDNS is a trademark of The Linux Foundation. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the CoreDNS project, the CNCF, or The Linux Foundation.