Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / MLflow

In Oracle review

DCA Hardened ML Lifecycle Platform for MLflow — Support & Quick Start

A hardened, CVE-patched virtual machine image running MLflow™ 3.17 — the open-source platform for the machine learning lifecycle: experiment tracking and a model registry — on Oracle Linux 9.

Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusSubmitted for Oracle certification review
Version3.17.0
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 8443/tcp
CategoryMachine_Learning
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@PUBLIC_IP
  2. On first boot the image creates the PostgreSQL metadata databases, the MLflow administrator and an instance-unique TLS certificate, then starts MLflow behind nginx; allow a minute or two. Check all four units:
    sudo systemctl status mlflow-firstboot mlflow nginx postgresql
  3. Read the administrator password generated uniquely for this instance (root only), then smoke-test the server through the TLS proxy with it; sign-in is required for everything except /health:
    sudo cat /root/.mlflow_default_credentials
    curl -s --cacert /etc/nginx/mlflow/ca.crt -u admin:YOUR_PASSWORD https://localhost:8443/version
  4. MLflow listens on 127.0.0.1:8443 (HTTPS) as shipped. Open it from your workstation through an SSH tunnel, browse to https://localhost:8443 and sign in as admin, then change the password under Account, Change password:
    ssh -L 8443:127.0.0.1:8443 opc@PUBLIC_IP
  5. Log runs from an MLflow 3.17 client through the tunnel. Copy this instance's CA certificate first (scp opc@PUBLIC_IP:/etc/nginx/mlflow/ca.crt .), then:
    export MLFLOW_TRACKING_URI=https://localhost:8443 MLFLOW_TRACKING_USERNAME=admin MLFLOW_TRACKING_PASSWORD=YOUR_PASSWORD MLFLOW_TRACKING_SERVER_CERT_PATH=ca.crt
    python -c 'import mlflow; mlflow.set_experiment("demo"); mlflow.start_run(); mlflow.log_metric("accuracy", 0.97); mlflow.end_run()'
  6. To serve your team directly, expose the proxy (never MLflow's own port 5000) and restart nginx; clients then use https://PRIVATE_IP:8443, and the certificate names the private IPs and host names:
    sudo sed -i 's/listen 127.0.0.1:8443 ssl;/listen 8443 ssl;/' /etc/nginx/conf.d/mlflow.conf && sudo systemctl restart nginx

    For a DNS name or a load balancer, add it to MLFLOW_SERVER_ALLOWED_HOSTS and MLFLOW_SERVER_CORS_ALLOWED_ORIGINS in /etc/mlflow/instance.env, then:

    sudo systemctl restart mlflow

  7. Port 8443 is already permitted in the host firewall; 5000 and PostgreSQL stay closed. Restrict 8443 in your VCN security list to your users' CIDR; never expose it to the internet. Only the admin can create users (Admin page or the users API), and every user can read all experiments (default_permission in /etc/mlflow/basic_auth.ini). Rotate or recover the admin password (it prompts twice):
    sudo /usr/local/sbin/mlflow-admin-password
  8. Runs, the model registry and users live in PostgreSQL (/var/lib/pgsql/data), artifacts in /var/lib/mlflow/artifacts and this instance's keys in /etc/mlflow/instance.env: back them up together, and for anything beyond evaluation put them on a block volume. Telemetry is off (MLFLOW_DISABLE_TELEMETRY, DO_NOT_TRACK). Back up the databases:
    sudo -u postgres pg_dumpall -f /var/lib/pgsql/mlflow-backup.sql

The image is CVE-patched at build time. Apply ongoing operating system, PostgreSQL and nginx updates with:

sudo dnf -y update

MLflow and its Python libraries are pinned in /opt/mlflow/venv and are not changed by dnf; new MLflow releases ship as new versions of this image.

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

MLflow™ is a trademark of LF Projects, LLC, used here only to identify the software this image runs. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the MLflow project, LF Projects, LLC, or the Linux Foundation.