Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / Envoy

In Oracle review

DCA Hardened Edge and Service Proxy for Envoy — Support & Quick Start

A hardened, CVE-patched virtual machine image running the Envoy proxy — the Cloud Native Computing Foundation's graduated, high-performance edge and service proxy — on Oracle Linux 9.

Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusSubmitted for Oracle certification review
Version1.39.3
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 10000/tcp
CategoryNetworking
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@PUBLIC_IP

    No credentials file is created: the proxy has no login, and its admin interface stays on 127.0.0.1:9901.

  2. Envoy runs as a systemd service with one HTTP listener on port 10000, bound to 127.0.0.1 as shipped and answering with a placeholder. Check it:
    sudo systemctl status envoy
    curl http://127.0.0.1:10000/
  3. To accept traffic from other hosts, bind the listener to all interfaces (the admin interface stays on 127.0.0.1):
    sudo sed -i 's/^ENVOY_LISTEN_ADDRESS=127.0.0.1$/ENVOY_LISTEN_ADDRESS=0.0.0.0/' /etc/envoy/envoy.env && sudo systemctl restart envoy

    The instance firewall already permits 10000/tcp; your VCN security list must allow it too. Then browse to http://PUBLIC_IP:10000

  4. To proxy to your application on 127.0.0.1:8080 (the predefined cluster local_app), switch the route, then apply it with step 5:
    sudo sed -i 's/^\( *\)direct_response: .*/\1route: { cluster: local_app }/' /etc/envoy/envoy.yaml

    For an application on another host, replace 127.0.0.1 in the local_app cluster with UPSTREAM_HOST (an IP address; a DNS name needs type: STRICT_DNS).

  5. After any edit of /etc/envoy/envoy.yaml, validate it, then restart — a failed check leaves the running proxy untouched:
    sudo /usr/local/sbin/envoy-bootstrap check && sudo systemctl restart envoy

    At every start, ENVOY_LISTEN_ADDRESS from /etc/envoy/envoy.env is filled into the file and Envoy runs the result, /run/envoy/envoy.yaml.

  6. Never expose the admin interface (port 9901, no authentication). Use it on the instance, e.g. curl http://127.0.0.1:9901/ready, or through a tunnel:
    ssh -L 9901:127.0.0.1:9901 opc@PUBLIC_IP

    Access logs:

    sudo journalctl -u envoy

  7. Configuration reference: https://www.envoyproxy.io/docs/envoy/latest/

The image is CVE-patched at build time. Apply ongoing updates with:

sudo dnf -y update

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

Envoy is a registered trademark of The Linux Foundation. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the Envoy project, the Cloud Native Computing Foundation, or The Linux Foundation.