In Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.
At a glance
| Status | In Oracle certification review |
|---|
| Version | 0.8.1 |
|---|
| Platform | Oracle Linux 9 |
|---|
| Ports open in the host firewall | SSH (22/tcp), 5432/tcp |
|---|
| Category | Databases |
|---|
| Upstream licence | PostgreSQL |
|---|
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
|---|
Quick start
This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.
After launch:
- Connect over SSH as the opc user with the key you supplied at launch:
ssh opc@<public-ip>
- PostgreSQL 18 with the pgvector extension runs as a systemd service bound to localhost only (TCP 5432; peer auth on the local socket, scram-sha-256 over TCP). Check status:
sudo systemctl status postgresql
- The postgres role's password was generated uniquely for this instance at first boot. Read it (root only), and rotate it whenever you like:
sudo cat /root/.pg_default_credentials
sudo -u postgres psql -c "ALTER ROLE postgres WITH PASSWORD 'your-strong-password';"
- Smoke-test from the instance, as the postgres OS user (peer auth, no password; a 'could not change directory' notice is harmless) and over TCP with the generated password:
sudo -u postgres psql -Atc 'SELECT 1'
PGPASSWORD='<password>' psql -h 127.0.0.1 -U postgres -Atc 'SHOW server_version'
- pgvector is installed but enabled in no database until you ask. Create a database for your embeddings, enable the extension in it (once per database) and confirm its version:
sudo -u postgres createdb vectordb
sudo -u postgres psql -d vectordb -c 'CREATE EXTENSION vector;'
sudo -u postgres psql -d vectordb -Atc "SELECT extversion FROM pg_extension WHERE extname = 'vector'"
- Store embeddings (vector(3) here; use your embedding model's dimension) and query the nearest neighbour by L2 distance (<->), which returns 2|[4,5,6]. Then add an HNSW index for fast approximate search as the table grows:
sudo -u postgres psql -d vectordb -c 'CREATE TABLE items (id bigserial PRIMARY KEY, embedding vector(3));'
sudo -u postgres psql -d vectordb -c "INSERT INTO items (embedding) VALUES ('[1,2,3]'), ('[4,5,6]'), ('[7,8,9]');"
sudo -u postgres psql -d vectordb -Atc "SELECT * FROM items ORDER BY embedding <-> '[5,6,7]' LIMIT 1"
sudo -u postgres psql -d vectordb -c 'CREATE INDEX ON items USING hnsw (embedding vector_l2_ops);'
- To reach the server from your application tier, expose it deliberately: listen on all interfaces, allow your application CIDR with SCRAM, restart:
sudo -u postgres psql -c "ALTER SYSTEM SET listen_addresses = '*';"
echo 'host all all <application-cidr> scram-sha-256' | sudo tee -a /var/lib/pgsql/data/pg_hba.conf
sudo systemctl restart postgresql
Port 5432 is already permitted in the host firewall. Restrict it in your VCN security list or NSG to the application tier's CIDR; never expose it to the internet.
- Data lives in /var/lib/pgsql/data (postgresql.conf, pg_hba.conf and postgresql.auto.conf, which holds the ALTER SYSTEM overrides, are in that directory). For anything beyond evaluation, attach a block volume, stop the service, move the directory onto it and mount it at that path before loading data.
The image is CVE-patched at build time. Apply ongoing updates, including PostgreSQL 18 minor releases and pgvector fixes from the Oracle Linux 9 AppStream, with:
sudo dnf -y update
What the image provides
- PostgreSQL 18 (server, client and contrib extensions) and pgvector 0.8.1 (vector, half-precision and sparse types; HNSW and IVFFlat indexes; iterative index scans for filtered search), both installed from the Oracle Linux 9 AppStream module stream postgresql:18, so Oracle carries the security-errata stream for the database and the extension alike — no third-party package repository is added to the image.
- pgvector proven at build time — the extension is created, answers a nearest-neighbour query through an HNSW index, and is dropped again — then shipped enabled in no database: you run CREATE EXTENSION vector; in the databases that need it.
- A data cluster initialised with data checksums for early corruption detection, SCRAM-SHA-256 password encryption, peer authentication on the local socket, and the logging collector enabled.
- An instance-unique password for the postgres role, generated on first boot and readable by root only — never a shared secret baked into the image.
- Safe-by-default network posture: the server listens on localhost until you expose it deliberately with one documented setting and one pg_hba.conf rule. Port 5432 is declared in the host firewall, so that step needs no firewall change.
- Security hardening aligned to the Oracle Cloud Marketplace image standards: SELinux enforcing, host firewall default-deny with only SSH and 5432 permitted, SSH key-only, no account with a usable password, no stray keys, and the image fully patched at build time.
Still stuck?
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.
PostgreSQL and pgvector are open-source software released under the PostgreSQL License. PostgreSQL® is a registered trademark of the PostgreSQL Community Association of Canada, used here only to identify the software this image runs. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the PostgreSQL Community Association of Canada, the PostgreSQL Global Development Group, or the pgvector project.