Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / MariaDB

In Oracle review

DCA Hardened Relational Database for MariaDB — Support & Quick Start

A hardened, CVE-patched virtual machine image running MariaDB® Server 11.8 — the open-source relational database, from its 11.8 long-term-support series — on Oracle Linux 9.

Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusSubmitted for Oracle certification review
Version11.8.8
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 3306/tcp
CategoryDatabases
Upstream licenceGPL-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@<public-ip>
  2. On first boot MariaDB initializes its data directory on this instance and applies the secure-installation end state (no anonymous accounts, no test database, no remotely usable root). Check both units:
    sudo systemctl status mariadb mariadb-firstboot
  3. There is no password anywhere on this image: local root signs in over the unix socket. Open a client with:
    sudo mariadb

    Check the server:

    sudo mariadb -e "SELECT VERSION();"

  4. Create a database and an account for your application at the sudo mariadb prompt (choose your own strong password; typing it at the prompt keeps it out of your shell history):
    CREATE DATABASE appdb;
    CREATE USER 'appuser'@'%' IDENTIFIED BY '<strong-password>';
    GRANT ALL PRIVILEGES ON appdb.* TO 'appuser'@'%';
  5. TCP is bound to 127.0.0.1 as shipped. To accept connections from your application tier, rebind and restart:
    sudo sed -i 's/^bind-address = 127.0.0.1$/bind-address = 0.0.0.0/' /etc/my.cnf.d/zz-dca-hardening.cnf && sudo systemctl restart mariadb

    Every TCP client must use TLS (require_secure_transport = ON); MariaDB 11.8 clients do so by default:

    mariadb -h <server-ip> -u appuser -p appdb

  6. Port 3306 is already permitted in the host firewall. Restrict it in your VCN security list to your application tier's CIDR only; never expose 3306 to the internet. The server presents a self-signed certificate generated at each start; to install a CA-issued pair, set ssl_cert and ssl_key in /etc/my.cnf.d/zz-dca-hardening.cnf and restart mariadb.
  7. Data lives in /var/lib/mysql. For anything beyond evaluation, place it on a block volume and back up with:
    sudo mariadb-dump --all-databases --single-transaction > backup.sql

The image is CVE-patched at build time. MariaDB 11.8 comes from the Oracle Linux 9 AppStream repository, so it receives Oracle's security errata together with the operating system:

sudo dnf -y update

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

The MariaDB® mark is a trademark of MariaDB Corporation Ab. The mariadb.org, MariaDB Foundation and MariaDB Server marks are exclusively licensed to the MariaDB Foundation. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by MariaDB Corporation Ab or the MariaDB Foundation.