Home / Support / Oracle Cloud Marketplace / OpenSearch
In Oracle reviewA hardened, CVE-patched virtual machine image running OpenSearch® — the Apache-2.0 licensed search and analytics engine stewarded by the OpenSearch Project under the Linux Foundation — on Oracle Linux 9.
| Status | In Oracle certification review |
|---|---|
| Version | 3.8.0 |
| Platform | Oracle Linux 9 |
| Ports open in the host firewall | SSH (22/tcp), 9200/tcp |
| Category | Databases |
| Upstream licence | Apache-2.0 |
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.
After launch:
ssh opc@<public-ip>sudo systemctl status opensearchsudo cat /root/.opensearch_default_credentialscurl --cacert /etc/opensearch/certs/root-ca.pem -u admin:'<password>' https://localhost:9200
curl --cacert /etc/opensearch/certs/root-ca.pem -u admin:'<password>' https://localhost:9200/_cluster/healthhttp.host: 0.0.0.0
then: sudo systemctl restart opensearchPort 9200 is already permitted in the host firewall. Restrict it in your VCN security list to the application tier's CIDR; never expose it to the internet. The transport port (9300) and the Performance Analyzer port (9600) remain blocked by the host firewall even after this change. Clients must trust root-ca.pem, or replace certs/node.pem and certs/node-key.pem with a certificate issued by your own CA whose SAN carries the node's private DNS name, and update plugins.security.nodes_dn to match.
curl --cacert /etc/opensearch/certs/root-ca.pem -u admin:'<password>' -X PUT https://localhost:9200/_plugins/_security/api/account -H 'Content-Type: application/json' -d '{"current_password":"<password>","password":"<new-password>"}'The new password must be strong (the plugin scores it; a long random string passes). Create additional users with the Security REST API (PUT _plugins/_security/api/internalusers/<name>) rather than sharing admin. If the admin password is lost, the credentials file holds a recovery recipe that uses securityadmin.sh with the instance's admin certificate. Note that securityadmin.sh -f replaces the ENTIRE internal-user set with the file you give it: retrieve the current users first (securityadmin.sh -r) and edit that copy, and never upload the image's /etc/opensearch/opensearch-security/internal_users.yml over a node on which other users exist.
sudo env OPENSEARCH_PATH_CONF=/etc/opensearch /usr/share/opensearch/bin/opensearch-plugin install org.opensearch.plugin:opensearch-security-analytics:$(rpm -q --qf '%{VERSION}' opensearch).0(Notifications: install opensearch-notifications-core, then notifications; Skills: opensearch-skills.) Updating to a newer OpenSearch release with dnf reinstalls all three from that release.
The image is CVE-patched at build time. Apply ongoing updates, including OpenSearch 3.x releases from the enabled upstream repository, with:
sudo dnf -y update
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.
OpenSearch® is a registered trademark of LF Projects, LLC. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the OpenSearch Project or LF Projects, LLC.