Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / OpenSearch

In Oracle review

DCA Hardened Search and Analytics Engine for OpenSearch — Support & Quick Start

A hardened, CVE-patched virtual machine image running OpenSearch® — the Apache-2.0 licensed search and analytics engine stewarded by the OpenSearch Project under the Linux Foundation — on Oracle Linux 9.

In Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusIn Oracle certification review
Version3.8.0
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 9200/tcp
CategoryDatabases
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@<public-ip>
  2. OpenSearch runs as a systemd service bound to loopback (REST 9200 over HTTPS, transport 9300). The first start also initialises the security index, so allow a minute or two. Check status:
    sudo systemctl status opensearch
  3. The admin password and the TLS certificates were generated uniquely for this instance at first boot. Read the credentials (root only):
    sudo cat /root/.opensearch_default_credentials
  4. Smoke-test from the instance (the instance's own CA is at /etc/opensearch/certs/root-ca.pem):
    curl --cacert /etc/opensearch/certs/root-ca.pem -u admin:'<password>' https://localhost:9200
    curl --cacert /etc/opensearch/certs/root-ca.pem -u admin:'<password>' https://localhost:9200/_cluster/health
  5. To reach the node from your application tier, expose the REST layer deliberately — add to /etc/opensearch/opensearch.yml:
    http.host: 0.0.0.0
    then: sudo systemctl restart opensearch

    Port 9200 is already permitted in the host firewall. Restrict it in your VCN security list to the application tier's CIDR; never expose it to the internet. The transport port (9300) and the Performance Analyzer port (9600) remain blocked by the host firewall even after this change. Clients must trust root-ca.pem, or replace certs/node.pem and certs/node-key.pem with a certificate issued by your own CA whose SAN carries the node's private DNS name, and update plugins.security.nodes_dn to match.

  6. Data lives in /var/lib/opensearch; logs in /var/log/opensearch. For anything beyond evaluation, attach a block volume, mount it at /var/lib/opensearch before loading data, and raise the heap in /etc/opensearch/jvm.options (-Xms/-Xmx, default 1g) to half of the instance's memory.
  7. Rotate the admin password at any time with the Security plugin's Account API (the admin user is deliberately not marked reserved, so it can change its own password with basic auth); this keeps every other user intact:
    curl --cacert /etc/opensearch/certs/root-ca.pem -u admin:'<password>' -X PUT https://localhost:9200/_plugins/_security/api/account -H 'Content-Type: application/json' -d '{"current_password":"<password>","password":"<new-password>"}'

    The new password must be strong (the plugin scores it; a long random string passes). Create additional users with the Security REST API (PUT _plugins/_security/api/internalusers/<name>) rather than sharing admin. If the admin password is lost, the credentials file holds a recovery recipe that uses securityadmin.sh with the instance's admin certificate. Note that securityadmin.sh -f replaces the ENTIRE internal-user set with the file you give it: retrieve the current users first (securityadmin.sh -r) and edit that copy, and never upload the image's /etc/opensearch/opensearch-security/internal_users.yml over a node on which other users exist.

  8. Three optional features are removed at build because their upstream builds embed libraries with unpatched vulnerabilities: Security Analytics, Notifications and Skills. The node's own libraries and every other bundled plugin are patched instead. To add one back, accepting those libraries, install it from Maven Central and restart OpenSearch:
    sudo env OPENSEARCH_PATH_CONF=/etc/opensearch /usr/share/opensearch/bin/opensearch-plugin install org.opensearch.plugin:opensearch-security-analytics:$(rpm -q --qf '%{VERSION}' opensearch).0

    (Notifications: install opensearch-notifications-core, then notifications; Skills: opensearch-skills.) Updating to a newer OpenSearch release with dnf reinstalls all three from that release.

The image is CVE-patched at build time. Apply ongoing updates, including OpenSearch 3.x releases from the enabled upstream repository, with:

sudo dnf -y update

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

OpenSearch® is a registered trademark of LF Projects, LLC. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the OpenSearch Project or LF Projects, LLC.