Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.
At a glance
| Status | Submitted for Oracle certification review |
|---|
| Version | 1.36.5-k3s1 |
|---|
| Platform | Oracle Linux 9 |
|---|
| Ports open in the host firewall | SSH (22/tcp), 6443/tcp, 80/tcp, 443/tcp |
|---|
| Category | Cloud management |
|---|
| Upstream licence | Apache-2.0 |
|---|
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
|---|
Quick start
This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.
After launch:
- Connect over SSH as the opc user with the key you supplied at launch:
ssh opc@PUBLIC_IP
- K3s runs as the systemd service k3s. On first boot, k3s-firstboot starts it for the first time and K3s generates this instance's own cluster CA, join token and admin kubeconfig (allow about 3 minutes). Check status:
sudo systemctl status k3s-firstboot k3s
sudo k3s kubectl get nodes
- The admin kubeconfig /etc/rancher/k3s/k3s.yaml is root-only (0600), so run kubectl through sudo. This instance's API endpoint, CA fingerprint and join-token path:
sudo cat /root/.k3s_default_credentials
sudo k3s kubectl get pods -A
- Deploy a test app from the preloaded busybox image and publish it through the bundled Traefik ingress on port 80:
sudo k3s kubectl create deployment hello --image=rancher/mirrored-library-busybox:1.37.0 --port=8080 -- sh -c 'echo hello from K3s > /tmp/index.html && exec httpd -f -p 8080 -h /tmp'
sudo k3s kubectl expose deployment hello --port=80 --target-port=8080 && sudo k3s kubectl create ingress hello --rule='/*=hello:80'
curl -s http://127.0.0.1/
- To run kubectl from another host in your VCN, allow TCP 6443 from that host's CIDR in your VCN security list (6443/tcp is already permitted in the host firewall), then copy this kubeconfig, rewritten to the instance's private IP, to that host:
(umask 077 && sudo sed 's/127.0.0.1/PRIVATE_IP/' /etc/rancher/k3s/k3s.yaml > ~/k3s.yaml)
Or, without opening 6443 at all, tunnel from your workstation:
ssh -L 6443:127.0.0.1:6443 opc@PUBLIC_IP and use the kubeconfig unchanged.
- Never expose 6443 to the internet. Traefik's ports 80/443 and any NodePort or LoadBalancer service are published through NAT rules that the host firewall does not filter, so your VCN security list is what restricts them: open 80/443 only to the clients that need them.
- Cluster state lives in /var/lib/rancher/k3s (Secrets encrypted at rest; API audit log in /var/lib/rancher/k3s/server/logs). Configuration is /etc/rancher/k3s/config.yaml; add settings as drop-ins in /etc/rancher/k3s/config.yaml.d. Your VCN must not overlap the pod and service networks 10.42.0.0/16 and 10.43.0.0/16. Recommended sizing: at least 2 OCPU (4 vCPU) and 16 GB memory.
The image is CVE-patched at build time. Apply ongoing OS updates with:
sudo dnf -y update
K3s itself is a single binary (/usr/bin/k3s), not a package; K3s fixes ship as new image versions.
What the image provides
- K3s 1.36.5 (Kubernetes 1.36.5, the K3s stable channel), installed from the project's official release with its SHA-256 checksums verified at build time. The system container images ship preloaded, so the first boot pulls nothing from an image registry.
- An instance-unique cluster. Nothing cluster-specific is baked into the image: the cluster certificate authority, join token, node identity, Secrets encryption key and admin kubeconfig are generated by K3s on the instance's own first boot.
- Hardened Kubernetes defaults: Secrets encrypted at rest; anonymous access refused by the API server and the kubelet; API audit logging at metadata level; protect-kernel-defaults; an admin kubeconfig readable by root only; SELinux enforcing with the official K3s SELinux policy, so workloads run confined; and the Traefik update check and usage reporting switched off.
- Security hardening aligned to the Oracle Cloud Marketplace image standards: host firewall default-deny with only SSH, the Kubernetes API (6443) and ingress HTTP/HTTPS (80, 443) permitted — services you publish through NodePort or LoadBalancer are governed by your VCN security list — no account with a usable password, no stray keys, and the image fully patched at build time.
Still stuck?
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.
K3s™ is a trademark of The Linux Foundation, and Kubernetes® is a registered trademark of The Linux Foundation. Traefik is a trademark of Traefik Labs. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the K3s project, SUSE, Traefik Labs, the Cloud Native Computing Foundation, or The Linux Foundation.