Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.
At a glance
| Status | Submitted for Oracle certification review |
|---|
| Version | 15.0.9 |
|---|
| Platform | Oracle Linux 9 |
|---|
| Ports open in the host firewall | SSH (22/tcp), 3000/tcp |
|---|
| Category | Developer tools |
|---|
| Upstream licence | GPL-3.0-or-later |
|---|
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
|---|
Quick start
This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.
After launch:
- Connect over SSH as the opc user with the key you supplied at launch:
ssh opc@PUBLIC_IP
- Forgejo runs as a systemd service on 127.0.0.1:3000 over HTTPS. On first boot it creates the administrator account, a TLS certificate and secrets unique to this instance; check status:
sudo systemctl status forgejo
- Read the generated administrator credentials (root only):
sudo cat /root/.forgejo_default_credentials
You will be required to change the password at first login.
- Reach the web UI safely by tunnelling over SSH:
ssh -L 3000:127.0.0.1:3000 opc@PUBLIC_IP
then open https://localhost:3000 and sign in as dcaadmin. The certificate is self-signed and unique to this instance; to trust it, print it and save it on your workstation as forgejo-cert.pem: sudo cat /etc/forgejo/tls/cert.pem
- To serve your team directly, rebind Forgejo to all interfaces and set the address your users reach (replace PRIVATE_IP with the instance's private IP address), then restart:
sudo sed -i -e 's/^HTTP_ADDR = 127.0.0.1$/HTTP_ADDR = 0.0.0.0/' -e 's#^ROOT_URL = https://localhost:3000/$#ROOT_URL = https://PRIVATE_IP:3000/#' /etc/forgejo/app.ini && sudo systemctl restart forgejo
Port 3000/tcp is already permitted in the host firewall. Restrict TCP 3000 in your VCN security list to your users' CIDR; never expose Forgejo directly to the internet.
- Clone and push over HTTPS; Git over SSH is disabled (DISABLE_SSH = true in /etc/forgejo/app.ini). On each client, with the certificate saved as forgejo-cert.pem:
git -c http.sslCAInfo=forgejo-cert.pem clone https://PRIVATE_IP:3000/OWNER/REPO.git
To use a CA-issued certificate instead, replace /etc/forgejo/tls/cert.pem and key.pem (key owned by root:git, mode 0640) and restart Forgejo.
- Self-registration is disabled; create accounts under Site administration. Repositories and the SQLite database live in /var/lib/forgejo; configuration in /etc/forgejo/app.ini. The update checker that contacts the project's release server is off. Recommended sizing: at least 2 OCPU (4 vCPU) and 16 GB memory, scaling with repository count and CI usage.
The image is CVE-patched at build time. Apply ongoing operating system updates with:
sudo dnf -y update
Forgejo itself is installed from the project's signed release binary and is refreshed by launching a newer image version of this listing. Its licence and matching source code ship in the image; see /usr/local/share/doc/forgejo/SOURCE.txt
What the image provides
- Forgejo 15.0.9 from the project's long-term-support line, installed from the official release binary after its OpenPGP signature is verified against the Forgejo release key and its SHA-256 digest is checked at build time, running as a dedicated unprivileged service with filesystem sandboxing.
- Fully self-contained: the built-in SQLite backend means no external database to provision. Launch one instance and you have a working Git server.
- Instance-unique security on first boot: a random administrator password that must be changed at first sign-in, plus unique signing secrets, an OAuth2 signing key and a TLS certificate, all generated the first time the instance starts. Nothing secret is baked into the image, and self-registration is disabled.
- Encryption in transit: the web interface, the API and Git traffic are served only over HTTPS.
- Safe-by-default network posture: Forgejo listens on loopback until you expose it with one documented command. Git over SSH is off (clone and push over HTTPS), so the service account has no login shell and no SSH keys.
- Privacy by default: the update checker that contacts the project's release server is turned off, and avatars and web assets are served locally.
- Security hardening aligned to the Oracle Cloud Marketplace image standards: SELinux enforcing, host firewall default-deny with only SSH and the Forgejo port permitted, no account with a usable password, no stray keys, and the image fully patched at build time.
- Licence compliance built in: Forgejo is free software under the GNU General Public License v3.0 or later. Its licence text and the matching upstream source code ship inside the image.
Still stuck?
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.
Forgejo is developed by the Forgejo community, and the project's domains are held by Codeberg e.V.; the name is used here only to identify the software this image runs. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the Forgejo project or Codeberg e.V. Learn more about Forgejo at https://forgejo.org. Git is a trademark of Software Freedom Conservancy.