Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / Prometheus

Live

DCA Hardened Monitoring for Prometheus — Support & Quick Start

A hardened, CVE-patched virtual machine image running Prometheus — the Cloud Native Computing Foundation's open-source monitoring and time-series database — on Oracle Linux 9.

At a glance

StatusLive on Oracle Cloud Marketplace
Version3.13.0
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 9090/tcp
CategoryCloud management
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@<public-ip>
  2. Prometheus runs as a systemd service, as the unprivileged prometheus user, bound to 127.0.0.1:9090. Check status:
    sudo systemctl status prometheus
  3. Smoke-test from the instance — readiness, the running version, and the built-in self-scrape (job "prometheus", up = 1):
    curl -s http://127.0.0.1:9090/-/ready
    curl -s http://127.0.0.1:9090/api/v1/status/buildinfo
    curl -s 'http://127.0.0.1:9090/api/v1/query?query=up'
  4. Reach the UI safely by tunnelling over SSH (this image runs Prometheus without authentication):
    ssh -L 9090:127.0.0.1:9090 opc@<public-ip>
    then open http://localhost:9090 in your browser.
  5. Add scrape targets in /etc/prometheus/prometheus.yml, validate, then reload the configuration in place (SIGHUP — no restart, no scrape gap):
    /usr/local/bin/promtool check config /etc/prometheus/prometheus.yml
    sudo systemctl kill -s HUP prometheus
  6. To expose Prometheus beyond the instance:
    sudo mkdir -p /etc/systemd/system/prometheus.service.d, then create /etc/systemd/system/prometheus.service.d/listen.conf containing:
    [Service]
    ExecStart=
    ExecStart=/usr/local/bin/prometheus --config.file=/etc/prometheus/prometheus.yml --storage.tsdb.path=/var/lib/prometheus --web.listen-address=0.0.0.0:9090
    then: sudo systemctl daemon-reload && sudo systemctl restart prometheus
  7. Port 9090 is already permitted in the host firewall. Restrict it in your VCN security list to your clients' CIDR. Never expose 9090 to the internet: Prometheus runs unauthenticated here, so for anything wider than a private subnet put an authenticating reverse proxy (NGINX with TLS and basic-auth or OIDC) in front and open only the proxy's port. The lifecycle (/-/reload, /-/quit) and admin TSDB APIs are disabled.
  8. Data lives in /var/lib/prometheus; the time-series database grows with retention and cardinality. Recommended sizing: at least 2 OCPU (4 vCPU) and 16 GB memory. For anything beyond evaluation, attach a block volume and mount it there before adding scrape targets.

The image is CVE-patched at build time. Apply ongoing updates with:

sudo dnf -y update

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

Prometheus is a registered trademark of The Linux Foundation. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the Prometheus project, the CNCF, or The Linux Foundation.