Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / Qdrant

In Oracle review

DCA Hardened Vector Search Engine for Qdrant — Support & Quick Start

A hardened, CVE-patched virtual machine image running Qdrant™ 1.19 — the open-source vector search engine for similarity search, recommendations and retrieval-augmented generation (RAG) — on Oracle Linux 9.

Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusSubmitted for Oracle certification review
Version1.19.2
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 6333/tcp, 6334/tcp
CategoryDatabases
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@<public-ip>
  2. On first boot the image generates the API key and an instance-unique TLS certificate, then starts Qdrant. Check both units:
    sudo systemctl status qdrant-firstboot qdrant
  3. Read the API key generated uniquely for this instance (root only):
    sudo cat /root/.qdrant_default_credentials
  4. Smoke-test the REST API over TLS (every request needs the api-key header; gRPC on 6334 uses the same key and certificate):
    curl -s --cacert /etc/qdrant/tls/cert.pem https://127.0.0.1:6333/collections -H "api-key: <api-key>"
  5. Back up a collection with a snapshot (written under /var/lib/qdrant/snapshots):
    curl -s --cacert /etc/qdrant/tls/cert.pem -X POST https://127.0.0.1:6333/collections/<collection>/snapshots -H "api-key: <api-key>"

    Rotate the API key by editing QDRANT__SERVICE__API_KEY in /etc/qdrant/qdrant.env, then:

    sudo systemctl restart qdrant

  6. REST (6333) and gRPC (6334) listen on 127.0.0.1 as shipped. To accept connections from your application tier, rebind and restart:
    sudo sed -i 's/^  host: 127.0.0.1$/  host: 0.0.0.0/' /etc/qdrant/config.yaml && sudo systemctl restart qdrant

    Clients verify the server with /etc/qdrant/tls/cert.pem (its SAN lists the instance's private IPs), or install a CA-issued pair at /etc/qdrant/tls/cert.pem and key.pem (Qdrant reloads it hourly).

  7. Ports 6333 and 6334 are already permitted in the host firewall. Restrict them in your VCN security list to your application tier's CIDR; never expose them to the internet.
  8. Collections and snapshots live in /var/lib/qdrant. For anything beyond evaluation place it on a block volume. Anonymous usage telemetry to Qdrant's servers is disabled (telemetry_disabled in /etc/qdrant/config.yaml).

The image is CVE-patched at build time. Apply ongoing operating system updates with:

sudo dnf -y update

Qdrant itself is installed from the upstream release and is refreshed by launching a newer image version of this listing.

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

Qdrant™ is a trademark of Qdrant Solutions GmbH. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by Qdrant Solutions GmbH.