Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / etcd

In Oracle review

DCA Hardened Key-Value Store for etcd — Support & Quick Start

A hardened, CVE-patched virtual machine image running etcd — the Cloud Native Computing Foundation's distributed, strongly-consistent key-value store — on Oracle Linux 9.

In Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusIn Oracle certification review
Version3.7.0
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 2379/tcp
CategoryDatabases
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@<public-ip>
  2. etcd runs as a systemd service bound to loopback only: client API https://127.0.0.1:2379 (TLS) and peer http://127.0.0.1:2380. Authentication is DISABLED out of the box (upstream default), which is why nothing listens off-box. Check status:
    sudo systemctl status etcd
  3. There is no generated password. The TLS certificate and key are unique to this instance, minted at first boot into /etc/etcd/tls (server.crt, server.key; owned by the etcd user, so use sudo). Smoke-test from the instance:
    sudo /usr/local/bin/etcdctl --endpoints=https://127.0.0.1:2379 --cacert=/etc/etcd/tls/server.crt endpoint health
    sudo /usr/local/bin/etcdctl --endpoints=https://127.0.0.1:2379 --cacert=/etc/etcd/tls/server.crt put hello world
    sudo /usr/local/bin/etcdctl --endpoints=https://127.0.0.1:2379 --cacert=/etc/etcd/tls/server.crt get hello --print-value-only
    sudo curl -s --cacert /etc/etcd/tls/server.crt https://127.0.0.1:2379/version
  4. Before exposing etcd beyond the instance, enable authentication. You are prompted for the root password; from then on add --user root to every etcdctl command:
    sudo /usr/local/bin/etcdctl --endpoints=https://127.0.0.1:2379 --cacert=/etc/etcd/tls/server.crt user add root
    sudo /usr/local/bin/etcdctl --endpoints=https://127.0.0.1:2379 --cacert=/etc/etcd/tls/server.crt user grant-role root root
    sudo /usr/local/bin/etcdctl --endpoints=https://127.0.0.1:2379 --cacert=/etc/etcd/tls/server.crt auth enable
  5. Then expose the client API deliberately: bind it to all interfaces, advertise this instance's DNS name (the certificate is valid for that name and for 127.0.0.1), and restart:
    sudo sed -i 's#^listen-client-urls:.*#listen-client-urls: https://0.0.0.0:2379#' /etc/etcd/etcd.conf.yml
    sudo sed -i "s#^advertise-client-urls:.*#advertise-client-urls: https://$(hostname -f):2379#" /etc/etcd/etcd.conf.yml
    sudo systemctl restart etcd

    Port 2379 is already permitted in the host firewall. Restrict it in your VCN security list to the application tier's CIDR; never expose etcd to the internet. The peer port (2380) stays on loopback and blocked by the host firewall.

  6. Clients connect to https://<instance-fqdn>:2379 with --user root and a copy of /etc/etcd/tls/server.crt as --cacert. Data lives in /var/lib/etcd (etcd user, mode 0700). etcd is sensitive to disk latency: for anything beyond evaluation, attach a block volume with consistent performance and point data-dir in /etc/etcd/etcd.conf.yml at it before loading data. Recommended sizing: at least 2 OCPU (4 vCPU) and 16 GB memory.

The image is CVE-patched at build time. Apply ongoing OS updates with:

sudo dnf -y update

etcd itself is a static binary in /usr/local/bin (not a package); etcd fixes ship as new image versions.

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

etcd is a registered trademark of The Linux Foundation. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the etcd project, the CNCF, or The Linux Foundation.