Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / K3s

In Oracle review

DCA Hardened Container Orchestration Platform for K3s — Support & Quick Start

A hardened, CVE-patched virtual machine image running K3s™ — the lightweight Kubernetes® distribution and Cloud Native Computing Foundation sandbox project — as a ready-to-use single-node cluster on Oracle Linux 9.

Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusSubmitted for Oracle certification review
Version1.36.5-k3s1
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 6443/tcp, 80/tcp, 443/tcp
CategoryCloud management
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@PUBLIC_IP
  2. K3s runs as the systemd service k3s. On first boot, k3s-firstboot starts it for the first time and K3s generates this instance's own cluster CA, join token and admin kubeconfig (allow about 3 minutes). Check status:
    sudo systemctl status k3s-firstboot k3s
    sudo k3s kubectl get nodes
  3. The admin kubeconfig /etc/rancher/k3s/k3s.yaml is root-only (0600), so run kubectl through sudo. This instance's API endpoint, CA fingerprint and join-token path:
    sudo cat /root/.k3s_default_credentials
    sudo k3s kubectl get pods -A
  4. Deploy a test app from the preloaded busybox image and publish it through the bundled Traefik ingress on port 80:
    sudo k3s kubectl create deployment hello --image=rancher/mirrored-library-busybox:1.37.0 --port=8080 -- sh -c 'echo hello from K3s > /tmp/index.html && exec httpd -f -p 8080 -h /tmp'
    sudo k3s kubectl expose deployment hello --port=80 --target-port=8080 && sudo k3s kubectl create ingress hello --rule='/*=hello:80'
    curl -s http://127.0.0.1/
  5. To run kubectl from another host in your VCN, allow TCP 6443 from that host's CIDR in your VCN security list (6443/tcp is already permitted in the host firewall), then copy this kubeconfig, rewritten to the instance's private IP, to that host:

    (umask 077 && sudo sed 's/127.0.0.1/PRIVATE_IP/' /etc/rancher/k3s/k3s.yaml > ~/k3s.yaml)

    Or, without opening 6443 at all, tunnel from your workstation:

    ssh -L 6443:127.0.0.1:6443 opc@PUBLIC_IP and use the kubeconfig unchanged.

  6. Never expose 6443 to the internet. Traefik's ports 80/443 and any NodePort or LoadBalancer service are published through NAT rules that the host firewall does not filter, so your VCN security list is what restricts them: open 80/443 only to the clients that need them.
  7. Cluster state lives in /var/lib/rancher/k3s (Secrets encrypted at rest; API audit log in /var/lib/rancher/k3s/server/logs). Configuration is /etc/rancher/k3s/config.yaml; add settings as drop-ins in /etc/rancher/k3s/config.yaml.d. Your VCN must not overlap the pod and service networks 10.42.0.0/16 and 10.43.0.0/16. Recommended sizing: at least 2 OCPU (4 vCPU) and 16 GB memory.

The image is CVE-patched at build time. Apply ongoing OS updates with:

sudo dnf -y update

K3s itself is a single binary (/usr/bin/k3s), not a package; K3s fixes ship as new image versions.

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

K3s™ is a trademark of The Linux Foundation, and Kubernetes® is a registered trademark of The Linux Foundation. Traefik is a trademark of Traefik Labs. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the K3s project, SUSE, Traefik Labs, the Cloud Native Computing Foundation, or The Linux Foundation.