Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.
At a glance
| Status | Submitted for Oracle certification review |
|---|
| Version | 11.8.8 |
|---|
| Platform | Oracle Linux 9 |
|---|
| Ports open in the host firewall | SSH (22/tcp), 3306/tcp |
|---|
| Category | Databases |
|---|
| Upstream licence | GPL-2.0 |
|---|
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
|---|
Quick start
This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.
After launch:
- Connect over SSH as the opc user with the key you supplied at launch:
ssh opc@<public-ip>
- On first boot MariaDB initializes its data directory on this instance and applies the secure-installation end state (no anonymous accounts, no test database, no remotely usable root). Check both units:
sudo systemctl status mariadb mariadb-firstboot
- There is no password anywhere on this image: local root signs in over the unix socket. Open a client with:
sudo mariadb
Check the server:
sudo mariadb -e "SELECT VERSION();"
- Create a database and an account for your application at the sudo mariadb prompt (choose your own strong password; typing it at the prompt keeps it out of your shell history):
CREATE DATABASE appdb;
CREATE USER 'appuser'@'%' IDENTIFIED BY '<strong-password>';
GRANT ALL PRIVILEGES ON appdb.* TO 'appuser'@'%';
- TCP is bound to 127.0.0.1 as shipped. To accept connections from your application tier, rebind and restart:
sudo sed -i 's/^bind-address = 127.0.0.1$/bind-address = 0.0.0.0/' /etc/my.cnf.d/zz-dca-hardening.cnf && sudo systemctl restart mariadb
Every TCP client must use TLS (require_secure_transport = ON); MariaDB 11.8 clients do so by default:
mariadb -h <server-ip> -u appuser -p appdb
- Port 3306 is already permitted in the host firewall. Restrict it in your VCN security list to your application tier's CIDR only; never expose 3306 to the internet. The server presents a self-signed certificate generated at each start; to install a CA-issued pair, set ssl_cert and ssl_key in /etc/my.cnf.d/zz-dca-hardening.cnf and restart mariadb.
- Data lives in /var/lib/mysql. For anything beyond evaluation, place it on a block volume and back up with:
sudo mariadb-dump --all-databases --single-transaction > backup.sql
The image is CVE-patched at build time. MariaDB 11.8 comes from the Oracle Linux 9 AppStream repository, so it receives Oracle's security errata together with the operating system:
sudo dnf -y update
What the image provides
- MariaDB Server 11.8 from the Oracle Linux 9 AppStream repository, so the database receives Oracle's security errata through dnf update together with the operating system — no third-party package repository is added to the image.
- No shared or default credentials: the data directory is initialized on your instance at first boot, local root signs in over the unix socket (sudo mariadb), and the first-boot unit applies the end state of mariadb-secure-installation — no anonymous accounts, no test database, no remotely usable root.
- Safe-by-default network posture: TCP is bound to loopback until you rebind it with one documented command, and once exposed every TCP client must use TLS (require_secure_transport); MariaDB generates its self-signed certificate at each start, so no private key exists in the image. LOAD DATA LOCAL is disabled.
- Security hardening aligned to the Oracle Cloud Marketplace image standards: SELinux enforcing, host firewall default-deny with only SSH and 3306 permitted, no account with a usable password, no stray keys, and the image fully patched at build time.
Still stuck?
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.
The MariaDB® mark is a trademark of MariaDB Corporation Ab. The mariadb.org, MariaDB Foundation and MariaDB Server marks are exclusively licensed to the MariaDB Foundation. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by MariaDB Corporation Ab or the MariaDB Foundation.