Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / NATS

Live

DCA Hardened Messaging Server for NATS — Support & Quick Start

A hardened, CVE-patched virtual machine image running NATS — the Cloud Native Computing Foundation's high-performance messaging system — on Oracle Linux 9.

At a glance

StatusLive on Oracle Cloud Marketplace
Version2.14.3
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 4222/tcp
CategoryApplication development
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@<public-ip>
  2. NATS runs as a systemd service, as the unprivileged nats user, with JetStream enabled. It ships without authentication, so both listeners are loopback-only: client 127.0.0.1:4222, monitoring 127.0.0.1:8222. Check status:
    sudo systemctl status nats
  3. Smoke-test from the instance over the monitoring endpoint — healthz answers {"status":"ok"}; varz reports the running version, connections and JetStream state (the image ships the server only; install the nats CLI on your client hosts):
    curl -s http://127.0.0.1:8222/healthz
    curl -s http://127.0.0.1:8222/varz
    /usr/local/bin/nats-server --version
  4. Browse the monitoring pages from your workstation through an SSH tunnel rather than opening 8222:
    ssh -L 8222:127.0.0.1:8222 opc@<public-ip>
    then open http://localhost:8222/varz
  5. To reach NATS from your application tier, require credentials first, then bind to all interfaces. In /etc/nats/nats-server.conf change host: "127.0.0.1" to host: "0.0.0.0" and append (NKeys and JWT are also supported):
    authorization { user: "app", password: "<strong-password>" }
    then: sudo systemctl restart nats (a reload cannot change the listen address; later credential changes apply with sudo systemctl reload nats)

    Port 4222 is already permitted in the host firewall. Restrict it in your VCN security list to the application tier's CIDR; never expose it to the internet, and never expose an unauthenticated NATS server. Monitoring (8222) stays on loopback and blocked by the host firewall.

  6. JetStream data lives in /var/lib/nats/jetstream (max_memory_store 256MB, max_file_store 10GB; adjust in the config). Recommended sizing: at least 2 OCPU (4 vCPU) and 16 GB memory; scale with message throughput and stream retention. For anything beyond evaluation, attach a block volume and point store_dir at it before creating streams.

The image is CVE-patched at build time. Apply ongoing updates with:

sudo dnf -y update

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

NATS is a trademark of The Linux Foundation. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the NATS project, the CNCF, or The Linux Foundation.