At a glance
| Status | Live on Oracle Cloud Marketplace |
|---|
| Version | 2.3.2 |
|---|
| Platform | Oracle Linux 9 |
|---|
| Ports open in the host firewall | SSH (22/tcp), 8080/tcp |
|---|
| Category | Business applications |
|---|
| Upstream licence | Apache-2.0 |
|---|
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
|---|
Quick start
This is the listing's usage information, verbatim.
After launch:
- Connect over SSH as the opc user with the key you supplied at launch:
ssh opc@<public-ip>
- Miniflux runs as a systemd service on port 8080 (loopback-bound), with PostgreSQL on the same instance. First boot created an instance-unique admin account:
sudo cat /root/.miniflux_default_credentials
- Verify the services:
sudo systemctl status miniflux postgresql
- Quickest look from your workstation — an SSH tunnel, no exposure at all:
ssh -L 8080:127.0.0.1:8080 opc@<public-ip>
then browse http://localhost:8080 and sign in.
- To serve users directly, edit /etc/miniflux.conf and change LISTEN_ADDR to 0.0.0.0:8080, then:
sudo systemctl restart miniflux
(Your VCN security list must also allow TCP 8080 — the instance firewall already does.) For public use, put it behind HTTPS: set BASE_URL in /etc/miniflux.conf and front it with a TLS-terminating proxy.
- Import your feeds under Settings > Import (OPML). Add users under Settings > Users. Full configuration reference: https://miniflux.app/docs/configuration.html
- All data lives in PostgreSQL under /var/lib/pgsql. Back up with:
sudo -u postgres pg_dump miniflux > backup.sql
The image is CVE-patched at build time. Apply ongoing updates with:
sudo dnf -y update
What the image provides
- Miniflux 2.3.2, installed from the project's official signed release with its SHA-256 checksum verified at build time, running as a dedicated unprivileged service.
- PostgreSQL 16 from the Oracle Linux AppStream (Oracle carries its errata stream), reachable only over the local unix socket with peer authentication — no database password exists at all, and nothing listens beyond the instance.
- Zero-touch first boot: database migrations are applied at build time by the exact binary that ships, and an instance-unique administrator account is generated on first boot — no shared secret is baked into the image. Credentials are written to /root/.miniflux_default_credentials.
- The web UI bound to loopback by default; you expose port 8080 deliberately. A locked-down systemd sandbox (NoNewPrivileges, ProtectSystem, ProtectHome, PrivateTmp) on every service.
- Security hardening aligned to the Oracle Cloud Marketplace image standards: SELinux enforcing, host firewall default-deny with only SSH and 8080 permitted, no account with a usable password, no stray keys, and the image fully patched at build time.
Still stuck?
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.