Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / Meilisearch

In Oracle review

DCA Hardened Search Engine for Meilisearch — Support & Quick Start

A hardened, CVE-patched virtual machine image running Meilisearch™ Community Edition 1.54 — the open-source, typo-tolerant search engine for site search, in-app search and search-as-you-type experiences — on Oracle Linux 9.

Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusSubmitted for Oracle certification review
Version1.54.3
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 7700/tcp
CategoryDatabases
Upstream licenceMIT
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@PUBLIC_IP
  2. On first boot the image generates the master key, an instance-unique TLS certificate and the default admin and search API keys, then starts Meilisearch Community Edition. Check both units:
    sudo systemctl status meilisearch-firstboot meilisearch
  3. Read the keys generated uniquely for this instance (root only):
    sudo cat /root/.meilisearch_default_credentials

    Use ADMIN_KEY for indexes, documents and settings, SEARCH_KEY in front ends (it can only search), and MASTER_KEY only to manage API keys through /keys.

  4. Add a document with ADMIN_KEY (indexing is asynchronous and returns a task), then search it with SEARCH_KEY:
    curl -s --cacert /etc/meilisearch/tls/cert.pem -X POST https://127.0.0.1:7700/indexes/movies/documents -H "Authorization: Bearer ADMIN_KEY" -H "Content-Type: application/json" --data-binary '[{"id":1,"title":"Carol"}]'
    curl -s --cacert /etc/meilisearch/tls/cert.pem -X POST https://127.0.0.1:7700/indexes/movies/search -H "Authorization: Bearer SEARCH_KEY" -H "Content-Type: application/json" --data-binary '{"q":"carol"}'
  5. The API listens on 127.0.0.1:7700, TLS only, as shipped. To accept connections from your application tier, rebind and restart:
    sudo sed -i 's/^MEILI_HTTP_ADDR=127.0.0.1:7700$/MEILI_HTTP_ADDR=0.0.0.0:7700/' /etc/meilisearch/meilisearch.env && sudo systemctl restart meilisearch

    Clients then use https://PRIVATE_IP:7700 and verify it with /etc/meilisearch/tls/cert.pem (its SAN lists the instance's private IPs), or install a CA-issued pair at /etc/meilisearch/tls/cert.pem and key.pem and restart.

  6. Port 7700 is already permitted in the host firewall. Restrict it in your VCN security list to your application tier's CIDR; never expose it to the internet.
  7. Indexes, dumps and snapshots live in /var/lib/meilisearch; for anything beyond evaluation place it on a block volume. Back up with a dump (written to /var/lib/meilisearch/dumps):
    curl -s --cacert /etc/meilisearch/tls/cert.pem -X POST https://127.0.0.1:7700/dumps -H "Authorization: Bearer ADMIN_KEY"

    Anonymous telemetry to Meilisearch is disabled (MEILI_NO_ANALYTICS=true in /etc/meilisearch/meilisearch.env).

The image is CVE-patched at build time. Apply ongoing operating system updates with:

sudo dnf -y update

Meilisearch itself is built from the upstream Community Edition release source and is refreshed by launching a newer image version of this listing.

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

Meilisearch™ is a trademark of Meili SAS. This image is an independent hardened distribution of Meilisearch Community Edition (MIT) and is not affiliated with, endorsed by, or sponsored by Meili SAS.