Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.
At a glance
| Status | Submitted for Oracle certification review |
|---|
| Version | 5.0.8 |
|---|
| Platform | Oracle Linux 9 |
|---|
| Ports open in the host firewall | SSH (22/tcp), 1880/tcp |
|---|
| Category | Application development |
|---|
| Upstream licence | Apache-2.0 |
|---|
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
|---|
Quick start
This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.
After launch:
- Connect over SSH as the opc user with the key you supplied at launch:
ssh opc@PUBLIC_IP
- On first boot the image creates the editor administrator, a credential-encryption key and an instance-unique TLS certificate before Node-RED ever listens, so the editor is never reachable without sign-in. Check both units:
sudo systemctl status node-red-firstboot node-red
- Read the administrator password generated uniquely for this instance (root only):
sudo cat /root/.node-red_default_credentials
Smoke-test the server over TLS (it answers with the sign-in prompt):
sudo curl -s --cacert /etc/node-red/tls/cert.pem https://127.0.0.1:1880/auth/login
- Node-RED serves HTTPS only, on 127.0.0.1:1880 as shipped. Open the editor from your workstation through an SSH tunnel:
ssh -L 1880:127.0.0.1:1880 opc@PUBLIC_IP
then browse to https://localhost:1880 and sign in as admin. Change the password (12 to 72 characters) with: sudo /usr/local/sbin/node-red-passwd
- To serve your team directly instead of through the tunnel, rebind and restart, then browse to https://PRIVATE_IP:1880
sudo sed -i 's/^NODE_RED_LISTEN_ADDRESS=127.0.0.1$/NODE_RED_LISTEN_ADDRESS=0.0.0.0/' /etc/node-red/node-red.env && sudo systemctl restart node-red
Browsers verify the server with /etc/node-red/tls/cert.pem (its SAN lists the instance's private IPs), or install a CA-issued pair at /etc/node-red/tls/cert.pem and key.pem (key readable by group node-red).
- Port 1880 is already permitted in the host firewall. Restrict it in your VCN security list to your users' CIDR; never expose it to the internet. Function and Exec nodes run code on this instance, so share the editor only with people you trust. Endpoints your flows publish with HTTP In nodes are served on 1880 without editor sign-in; protect them with httpNodeAuth in /etc/node-red/settings.js. Sign-ins, failed sign-ins and deploys are logged:
sudo journalctl -u node-red
- Flows, their encrypted credentials and installed palette nodes live in /var/lib/node-red; for anything beyond evaluation place it on a block volume. The key that decrypts those credentials is /etc/node-red/credential-secret, so back up both together. Telemetry to the Node-RED project is off; installing palette nodes needs outbound HTTPS to the npm registry.
The image is CVE-patched at build time. Apply ongoing operating system updates with:
sudo dnf -y update
Node-RED itself is installed from hash-verified upstream release files and is refreshed by launching a newer image version of this listing.
What the image provides
- Node-RED release 5.0.8 installed from the project's release files, verified by SHA-256 at build time, with every dependency installed from the project's own lock file (integrity-checked, npm registry signatures verified, no install-time scripts), on Node.js 24 LTS from Oracle Linux 9 AppStream, running as a dedicated unprivileged systemd service with a read-only view of the operating system: only its data directory is writable.
- No open editor: a stock Node-RED installation serves its editor without a password, and anyone who reaches it can run code on the server. Here the editor and admin API require sign-in from the first boot: the administrator password is generated uniquely for this instance, surfaced to the operator over SSH and stored only as a bcrypt hash, and Node-RED refuses to start rather than run without it. Repeated failed sign-ins are throttled, sign-ins and deploys are written to an audit log, and one documented command changes a password and signs that account's sessions out.
- Credentials stored in your flows are encrypted with an instance-unique key generated at first boot and kept outside the data directory.
- Encryption in transit: the editor, the admin API and your flows' HTTP endpoints are served only over HTTPS with an instance-unique certificate generated at first boot.
- Privacy by default: usage telemetry and update checks to the Node-RED project are turned off.
- Safe-by-default network posture: Node-RED listens on loopback until you expose it with one documented command; security hardening aligned to the Oracle Cloud Marketplace image standards — SELinux enforcing, host firewall default-deny with only SSH and 1880 permitted, no account with a usable password, and the image fully patched at build time.
Still stuck?
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.
Node-RED® and Node.js® are registered trademarks of the OpenJS Foundation. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the OpenJS Foundation or the Node-RED project.