Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.
At a glance
| Status | Submitted for Oracle certification review |
|---|
| Version | 1.39.3 |
|---|
| Platform | Oracle Linux 9 |
|---|
| Ports open in the host firewall | SSH (22/tcp), 10000/tcp |
|---|
| Category | Networking |
|---|
| Upstream licence | Apache-2.0 |
|---|
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
|---|
Quick start
This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.
After launch:
- Connect over SSH as the opc user with the key you supplied at launch:
ssh opc@PUBLIC_IP
No credentials file is created: the proxy has no login, and its admin interface stays on 127.0.0.1:9901.
- Envoy runs as a systemd service with one HTTP listener on port 10000, bound to 127.0.0.1 as shipped and answering with a placeholder. Check it:
sudo systemctl status envoy
curl http://127.0.0.1:10000/
- To accept traffic from other hosts, bind the listener to all interfaces (the admin interface stays on 127.0.0.1):
sudo sed -i 's/^ENVOY_LISTEN_ADDRESS=127.0.0.1$/ENVOY_LISTEN_ADDRESS=0.0.0.0/' /etc/envoy/envoy.env && sudo systemctl restart envoy
The instance firewall already permits 10000/tcp; your VCN security list must allow it too. Then browse to http://PUBLIC_IP:10000
- To proxy to your application on 127.0.0.1:8080 (the predefined cluster local_app), switch the route, then apply it with step 5:
sudo sed -i 's/^\( *\)direct_response: .*/\1route: { cluster: local_app }/' /etc/envoy/envoy.yaml
For an application on another host, replace 127.0.0.1 in the local_app cluster with UPSTREAM_HOST (an IP address; a DNS name needs type: STRICT_DNS).
- After any edit of /etc/envoy/envoy.yaml, validate it, then restart — a failed check leaves the running proxy untouched:
sudo /usr/local/sbin/envoy-bootstrap check && sudo systemctl restart envoy
At every start, ENVOY_LISTEN_ADDRESS from /etc/envoy/envoy.env is filled into the file and Envoy runs the result, /run/envoy/envoy.yaml.
- Never expose the admin interface (port 9901, no authentication). Use it on the instance, e.g. curl http://127.0.0.1:9901/ready, or through a tunnel:
ssh -L 9901:127.0.0.1:9901 opc@PUBLIC_IP
Access logs:
sudo journalctl -u envoy
- Configuration reference: https://www.envoyproxy.io/docs/envoy/latest/
The image is CVE-patched at build time. Apply ongoing updates with:
sudo dnf -y update
What the image provides
- Envoy 1.39.3, the project's official release binary, verified at build time against its pinned SHA-256 digest and against the release checksums signed by the Envoy maintainers, running as a dedicated unprivileged service.
- A working configuration out of the box: one HTTP listener on port 10000 that answers with a placeholder, bound to loopback until you expose it with one documented command, plus a predefined upstream cluster, so proxying to your application is a one-line change followed by a built-in validate-then-restart step.
- Edge-proxy defaults taken from Envoy's own best-practices guide: client addresses taken from the connection, path normalization, requests carrying underscore headers rejected, idle and request timeouts, bounded per-connection buffers, and a global downstream connection limit.
- The admin interface bound to 127.0.0.1 only, never exposed. No statistics sinks, tracing or dynamic-configuration endpoints are configured, so the proxy opens no outbound connection except to the upstreams you route to.
- Least privilege: the service holds no Linux capabilities at all, inside a locked-down systemd sandbox (NoNewPrivileges, a read-only operating system via ProtectSystem=strict, ProtectHome, PrivateTmp, PrivateDevices, protected kernel tunables, modules and logs, and restricted address families).
- Security hardening aligned to the Oracle Cloud Marketplace image standards: SELinux enforcing, host firewall default-deny with only SSH and port 10000 permitted, no account with a usable password, no stray keys, and the image fully patched at build time.
Still stuck?
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.
Envoy is a registered trademark of The Linux Foundation. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the Envoy project, the Cloud Native Computing Foundation, or The Linux Foundation.