Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / Ollama

In Oracle review

DCA Hardened Private LLM Server for Ollama — Support & Quick Start

A hardened, CVE-patched virtual machine image running Ollama — the MIT-licensed runtime for open-weight large language models — as a private, authenticated LLM server on Oracle Linux 9.

In Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusIn Oracle certification review
Version0.34.4
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 8443/tcp
CategoryApplication development
Upstream licenceMIT
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@<public-ip>
  2. Ollama runs as a systemd service on loopback only (127.0.0.1:11434). It has no authentication of its own, so it is never exposed: nginx fronts it on port 8443 with TLS and an API key, both generated uniquely for this instance at first boot, and the proxy also listens on loopback until step 5. No model ships in the image. Check both services:
    sudo systemctl status ollama nginx
  3. Pull a model and run it on the instance. smollm2:135m (271 MB, Apache-2.0) answers in seconds on 2 OCPUs; other models from ollama.com/library run the same way under their own licences, sized to the instance's memory:
    ollama pull smollm2:135m
    ollama run smollm2:135m "Why is the sky blue? Answer in one sentence."
  4. Read the API key (root only), then call the OpenAI-compatible API through the proxy, trusting this instance's own certificate authority:
    sudo cat /root/.ollama_default_credentials
    curl --cacert /etc/nginx/ollama-proxy/ca.crt -H 'Authorization: Bearer <api-key>' -H 'Content-Type: application/json' https://localhost:8443/v1/chat/completions -d '{"model":"smollm2:135m","messages":[{"role":"user","content":"Say hello."}]}'

    From your workstation (with a copy of ca.crt), the same https://localhost:8443 works through an SSH tunnel without exposing anything:

    ssh -L 8443:127.0.0.1:8443 opc@<public-ip>

  5. To reach the API from your application tier, expose the proxy (never Ollama itself) and restart nginx:
    sudo sed -i 's/listen 127.0.0.1:8443 ssl;/listen 8443 ssl;/' /etc/nginx/conf.d/ollama-proxy.conf && sudo systemctl restart nginx

    Port 8443 is already permitted in the host firewall; 11434 stays blocked. Restrict 8443 in your VCN security list to the application tier's CIDR; never expose it to the internet. Clients use https://<private-ip>:8443/v1 as the OpenAI base URL, or https://<private-ip>:8443 for Ollama's own API (for example /api/embed with an embedding model such as all-minilm), send the key as a Bearer token, and trust /etc/nginx/ollama-proxy/ca.crt (the certificate names localhost, the instance's hostname and its primary private IP). To use your own certificate instead, replace server.crt and server.key in that directory and restart nginx.

  6. The API key grants the whole Ollama API, including pulling and deleting models. Rotate it at any time; the old key stops working at once and the new one is written to the credentials file:
    sudo /usr/local/sbin/ollama-rotate-api-key
  7. Models live in /var/lib/ollama/models; free space with ollama rm <model>. For anything beyond evaluation, attach a block volume, stop the service (sudo systemctl stop ollama), mount the volume at /var/lib/ollama, run sudo chown -R ollama:ollama /var/lib/ollama && sudo restorecon -R /var/lib/ollama, then start it again. Ollama's cloud features (remote inference and web search) are disabled with OLLAMA_NO_CLOUD=1, so prompts never leave the instance; pulls from the Ollama model registry still work.

The image is CVE-patched at build time. Apply ongoing operating-system and nginx updates with:

sudo dnf -y update. Ollama itself is updated by launching a newer image version; keeping models on a block volume (step 7) carries them across.

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

Ollama is a trademark of Ollama, Inc. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by Ollama, Inc. Models you download are provided by third parties under their own licence terms.