Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.
At a glance
| Status | Submitted for Oracle certification review |
|---|
| Version | 1.12.5 |
|---|
| Platform | Oracle Linux 9 |
|---|
| Ports open in the host firewall | SSH (22/tcp), 7860/tcp |
|---|
| Category | Application development |
|---|
| Upstream licence | MIT |
|---|
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
|---|
Quick start
This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.
After launch:
- Connect over SSH as the opc user with the key you supplied at launch:
ssh opc@<public-ip>
- On first boot the image generates the administrator password, the session secret and an instance-unique TLS certificate, then starts Langflow (the first start takes a few minutes). Check both units:
sudo systemctl status langflow-firstboot langflow
- Read the administrator password generated uniquely for this instance (root only):
sudo cat /root/.langflow_default_credentials
Smoke-test the server over TLS:
curl -s --cacert /etc/langflow/tls/cert.pem https://127.0.0.1:7860/health
- Langflow listens on 127.0.0.1:7860 (HTTPS) as shipped. Open it from your workstation through an SSH tunnel:
ssh -L 7860:127.0.0.1:7860 opc@<public-ip>
then browse to https://localhost:7860 and sign in as admin. Sign-in is required: auto-login and public sign-up are off.
- Change the administrator password after first sign-in in Settings -> General -> Password. The bootstrap value LANGFLOW_SUPERUSER_PASSWORD in /etc/langflow/langflow.env only creates the admin on the first start and is ignored once the admin exists; keep the line, Langflow will not start without it.
- To serve your team directly instead of through the tunnel, rebind and restart:
sudo sed -i 's/^LANGFLOW_HOST=127.0.0.1$/LANGFLOW_HOST=0.0.0.0/' /etc/langflow/langflow.env && sudo systemctl restart langflow
Browsers verify the server with /etc/langflow/tls/cert.pem (its SAN lists the instance's private IPs), or install a CA-issued pair at /etc/langflow/tls/cert.pem and key.pem.
- Port 7860 is already permitted in the host firewall. Restrict it in your VCN security list to your users' CIDR; never expose it to the internet. Flows can run code and call external APIs, so add only users you trust.
- Flows, credentials you store in Langflow, and the SQLite database live in /var/lib/langflow. For anything beyond evaluation place it on a block volume. Anonymous usage telemetry is disabled (LANGFLOW_DO_NOT_TRACK and DO_NOT_TRACK in /etc/langflow/langflow.env).
The image is CVE-patched at build time. Apply ongoing operating system updates with:
sudo dnf -y update
Langflow itself is installed from hash-pinned upstream packages and is refreshed by launching a newer image version of this listing.
What the image provides
- Langflow 1.12.5 installed from the upstream release's own lock file: every one of several hundred Python packages is pinned by SHA-256 and verified at build time, the release commit is checked, and the result runs as a dedicated unprivileged systemd service.
- Sign-in required: auto-login, public sign-up and the superuser command line are disabled; the administrator password and session secret are generated uniquely for this instance at first boot and surfaced to the operator over SSH — never a shared default credential.
- Encryption in transit: the web UI and API are served only over HTTPS with an instance-unique certificate generated at first boot.
- Privacy by default: anonymous usage telemetry is disabled.
- Safe-by-default network posture: Langflow listens on loopback until you expose it with one documented command; security hardening aligned to the Oracle Cloud Marketplace image standards — SELinux enforcing, host firewall default-deny with only SSH and 7860 permitted, no account with a usable password, and the image fully patched at build time.
Still stuck?
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.
Langflow™ is a trademark of its respective owner, used here only to identify the software this image runs. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the Langflow project or its owners.