Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / Milvus

In Oracle review

DCA Hardened Vector Database for Milvus — Support & Quick Start

A hardened, CVE-patched virtual machine image running Milvus™ 2.6 — the open-source vector database for similarity search and retrieval-augmented generation (RAG), a Linux Foundation AI & Data project — on Oracle Linux 9.

Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusSubmitted for Oracle certification review
Version2.6.25
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 19530/tcp, 19540/tcp
CategoryDatabases
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@<public-ip>
  2. On first boot the image generates the root password and an instance-unique TLS certificate, then Milvus initializes (allow two to three minutes). Check both units and the health endpoint:
    sudo systemctl status milvus-firstboot milvus
    curl -s http://127.0.0.1:9091/healthz
  3. Read the root password generated uniquely for this instance (root only):
    sudo cat /root/.milvus_default_credentials
  4. Smoke-test the REST API over TLS (gRPC clients such as pymilvus use port 19530 with the same certificate and token "root:<password>"):
    curl -s --cacert /etc/milvus/tls/server.pem https://127.0.0.1:19540/v2/vectordb/collections/list -H "Authorization: Bearer root:<password>" -d '{}'
  5. Create an account for your application, then rotate the root password (same --cacert and root Authorization header as step 4, POST to https://127.0.0.1:19540):
    /v2/vectordb/users/create          -d '{"userName":"appuser","password":"<strong-password>"}'
    /v2/vectordb/users/grant_role      -d '{"userName":"appuser","roleName":"admin"}'
    /v2/vectordb/users/update_password -d '{"userName":"root","password":"<current>","newPassword":"<new>"}'
  6. Ports 19530 (gRPC) and 19540 (REST) are published on 127.0.0.1 only as shipped. To accept connections from your application tier, publish them on all interfaces and restart:
    sudo sed -i -e 's/^PublishPort=127.0.0.1:19530:19530$/PublishPort=19530:19530/' -e 's/^PublishPort=127.0.0.1:19540:19540$/PublishPort=19540:19540/' /etc/containers/systemd/milvus.container && sudo systemctl daemon-reload && sudo systemctl restart milvus

    Clients verify the server with /etc/milvus/tls/server.pem (its SAN lists the instance's private IPs), or install a CA-issued pair at /etc/milvus/tls/server.pem and server.key.

  7. Restrict 19530 and 19540 in your VCN security list to your application tier's CIDR; never expose them to the internet. The management port 9091 (health and metrics only) stays on loopback.
  8. Data (vectors, indexes and the embedded etcd metadata) lives in /var/lib/milvus. For anything beyond evaluation place it on a block volume; to back up, sudo systemctl stop milvus, copy /var/lib/milvus, then sudo systemctl start milvus.

The image is CVE-patched at build time. Apply ongoing operating system and Podman updates with:

sudo dnf -y update

Milvus itself runs from a container image pinned at build time and is refreshed by launching a newer image version of this listing.

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

Milvus™ is a trademark of LF Projects, LLC. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the Milvus project, LF AI & Data, The Linux Foundation, or Zilliz.