Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / pgvector

In Oracle review

DCA Hardened Vector Database with pgvector — Support & Quick Start

A hardened, CVE-patched image running PostgreSQL® 18 with the pgvector extension on Oracle Linux 9.

In Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusIn Oracle certification review
Version0.8.1
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 5432/tcp
CategoryDatabases
Upstream licencePostgreSQL
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@<public-ip>
  2. PostgreSQL 18 with the pgvector extension runs as a systemd service bound to localhost only (TCP 5432; peer auth on the local socket, scram-sha-256 over TCP). Check status:
    sudo systemctl status postgresql
  3. The postgres role's password was generated uniquely for this instance at first boot. Read it (root only), and rotate it whenever you like:
    sudo cat /root/.pg_default_credentials
    sudo -u postgres psql -c "ALTER ROLE postgres WITH PASSWORD 'your-strong-password';"
  4. Smoke-test from the instance, as the postgres OS user (peer auth, no password; a 'could not change directory' notice is harmless) and over TCP with the generated password:
    sudo -u postgres psql -Atc 'SELECT 1'
    PGPASSWORD='<password>' psql -h 127.0.0.1 -U postgres -Atc 'SHOW server_version'
  5. pgvector is installed but enabled in no database until you ask. Create a database for your embeddings, enable the extension in it (once per database) and confirm its version:
    sudo -u postgres createdb vectordb
    sudo -u postgres psql -d vectordb -c 'CREATE EXTENSION vector;'
    sudo -u postgres psql -d vectordb -Atc "SELECT extversion FROM pg_extension WHERE extname = 'vector'"
  6. Store embeddings (vector(3) here; use your embedding model's dimension) and query the nearest neighbour by L2 distance (<->), which returns 2|[4,5,6]. Then add an HNSW index for fast approximate search as the table grows:
    sudo -u postgres psql -d vectordb -c 'CREATE TABLE items (id bigserial PRIMARY KEY, embedding vector(3));'
    sudo -u postgres psql -d vectordb -c "INSERT INTO items (embedding) VALUES ('[1,2,3]'), ('[4,5,6]'), ('[7,8,9]');"
    sudo -u postgres psql -d vectordb -Atc "SELECT * FROM items ORDER BY embedding <-> '[5,6,7]' LIMIT 1"
    sudo -u postgres psql -d vectordb -c 'CREATE INDEX ON items USING hnsw (embedding vector_l2_ops);'
  7. To reach the server from your application tier, expose it deliberately: listen on all interfaces, allow your application CIDR with SCRAM, restart:
    sudo -u postgres psql -c "ALTER SYSTEM SET listen_addresses = '*';"
    echo 'host all all <application-cidr> scram-sha-256' | sudo tee -a /var/lib/pgsql/data/pg_hba.conf
    sudo systemctl restart postgresql

    Port 5432 is already permitted in the host firewall. Restrict it in your VCN security list or NSG to the application tier's CIDR; never expose it to the internet.

  8. Data lives in /var/lib/pgsql/data (postgresql.conf, pg_hba.conf and postgresql.auto.conf, which holds the ALTER SYSTEM overrides, are in that directory). For anything beyond evaluation, attach a block volume, stop the service, move the directory onto it and mount it at that path before loading data.

The image is CVE-patched at build time. Apply ongoing updates, including PostgreSQL 18 minor releases and pgvector fixes from the Oracle Linux 9 AppStream, with:

sudo dnf -y update

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

PostgreSQL and pgvector are open-source software released under the PostgreSQL License. PostgreSQL® is a registered trademark of the PostgreSQL Community Association of Canada, used here only to identify the software this image runs. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the PostgreSQL Community Association of Canada, the PostgreSQL Global Development Group, or the pgvector project.