Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / OpenTelemetry Collector

In Oracle review

DCA Hardened Telemetry Pipeline for OpenTelemetry Collector — Support & Quick Start

A hardened, CVE-patched virtual machine image running the OpenTelemetry Collector (contrib distribution) — the Cloud Native Computing Foundation project's vendor-neutral agent and gateway for traces, metrics and logs — on Oracle Linux 9.

Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusSubmitted for Oracle certification review
Version0.162.0
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 4317/tcp, 4318/tcp
CategoryCloud management
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@PUBLIC_IP
  2. The OpenTelemetry Collector (contrib distribution) runs as the otelcol-contrib systemd service: OTLP ingest on 4317 (gRPC) and 4318 (HTTP), loopback-bound. Check status:
    sudo systemctl status otelcol-contrib
  3. See data flow without exposing anything: send a test metric, then read it back from the example Prometheus exporter on 127.0.0.1:8889:
    curl -s -H 'Content-Type: application/json' -d '{"resourceMetrics":[{"scopeMetrics":[{"metrics":[{"name":"dca_test_metric","gauge":{"dataPoints":[{"asInt":"1"}]}}]}]}]}' http://127.0.0.1:4318/v1/metrics
    curl -s http://127.0.0.1:8889/metrics | grep dca_test_metric

    The debug exporter also logs a one-line summary of every batch of traces, metrics and logs:

    sudo journalctl -u otelcol-contrib -f

  4. To accept OTLP from other hosts, move 4317 and 4318 to all interfaces (the health check 13133, the collector's own metrics 8888 and the example exporter 8889 stay on 127.0.0.1):
    sudo sed -i 's/^OTEL_LISTEN_HOST=127.0.0.1$/OTEL_LISTEN_HOST=0.0.0.0/' /etc/otelcol-contrib/otelcol.env && sudo systemctl restart otelcol-contrib

    The instance firewall already permits 4317 and 4318; your VCN security list must allow them too. OTLP has NO authentication in this configuration: anyone who can reach 4317 or 4318 can send data. Never expose them to the internet. Allow only your application subnets, or require a token with the bearertokenauth extension (example at the end of /etc/otelcol-contrib/config.yaml) together with TLS.

  5. The configuration is /etc/otelcol-contrib/config.yaml. Replace the debug and example Prometheus exporters with the exporter for your backend (OTLP, Prometheus remote write, Kafka and many more ship in the contrib distribution). Check an edit with sudo /usr/bin/otelcol-contrib validate --config=/etc/otelcol-contrib/config.yaml before sudo systemctl restart otelcol-contrib. The service runs sandboxed as the unprivileged otelcol-contrib user and may write only to /var/lib/otelcol-contrib.
  6. Readiness probe for your monitoring:
    curl http://127.0.0.1:13133/ answers 200 when the collector is ready.

The image is CVE-patched at build time. Apply ongoing OS updates with:

sudo dnf -y update (the collector is the project's official RPM; newer collector releases ship as new image versions).

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

OpenTelemetry™ is a trademark of The Linux Foundation. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the OpenTelemetry project, the CNCF, or The Linux Foundation.