Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.
At a glance
| Status | Submitted for Oracle certification review |
|---|
| Version | 10.0.1 |
|---|
| Platform | Oracle Linux 9 |
|---|
| Ports open in the host firewall | SSH (22/tcp), 9000/tcp, 8812/tcp |
|---|
| Category | Databases |
|---|
| Upstream licence | Apache-2.0 |
|---|
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
|---|
Quick start
This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.
After launch:
- Connect over SSH as the opc user with the key you supplied at launch:
ssh opc@PUBLIC_IP
- On first boot the image generates one instance-unique password for the admin user of the web console, REST API and PostgreSQL wire protocol, proves it on both protocols, then starts QuestDB. Check both units:
sudo systemctl status questdb-firstboot questdb
- Read the password (root only):
sudo cat /root/.questdb_default_credentials
Smoke-test from the instance (the health check needs no password):
curl -s http://127.0.0.1:9003/status
curl -s -u admin:'YOUR_PASSWORD' -G http://127.0.0.1:9000/exec --data-urlencode 'query=SELECT build()'
- QuestDB listens on 127.0.0.1 only: 9000 for the web console, REST API and ILP or QWP clients over HTTP, 8812 for the PostgreSQL wire protocol. Open the web console through an SSH tunnel, then browse to http://localhost:9000 and sign in as admin:
ssh -L 9000:127.0.0.1:9000 opc@PUBLIC_IP
- To serve your application tier directly, rebind both listeners and restart:
sudo sed -i -e 's/^http.net.bind.to=127.0.0.1:9000$/http.net.bind.to=0.0.0.0:9000/' -e 's/^pg.net.bind.to=127.0.0.1:8812$/pg.net.bind.to=0.0.0.0:8812/' /etc/questdb/server.conf && sudo systemctl restart questdb
Then connect any PostgreSQL client (psql -h PRIVATE_IP -p 8812 -U admin -d qdb) or an ILP client with http::addr=PRIVATE_IP:9000;username=admin;password=YOUR_PASSWORD; (QWP clients use the same user and password).
- Ports 9000 and 8812 are already permitted in the host firewall. Open source QuestDB has no TLS, so restrict them in your VCN security list to your application tier's CIDR and never expose them to the internet. ILP over TCP (9009) is disabled because it accepts unauthenticated writes by default.
- Data lives in /var/lib/questdb; for anything beyond evaluation place it on a block volume. Settings are in /etc/questdb/server.conf (read it with sudo); to rotate the password, change http.password and pg.password there, then run sudo systemctl restart questdb. Usage telemetry is off (telemetry.enabled=false).
The image is CVE-patched at build time. Apply ongoing operating system and Java updates with:
sudo dnf -y update
QuestDB itself is installed from the checksum-verified upstream release and is refreshed by launching a newer image version of this listing.
What the image provides
- QuestDB open source 10.0.1 (Apache License 2.0) from the project's official release archive, with the archive's SHA-256 checksum, the release commit and the native libraries verified at build time — the open source edition only, with no QuestDB Enterprise components. It runs on OpenJDK 25 from Oracle Linux 9 AppStream, so Java security fixes arrive with dnf update, as a dedicated unprivileged systemd service with a read-only view of the operating system: it can write only to its data directory and a private temporary directory.
- No default credentials: stock QuestDB answers the PostgreSQL wire protocol with a published default login and serves its web console and REST API without authentication. Here one instance-unique password for the admin user protects both. It is generated at first boot and proven on both protocols, with the default login proven refused, before it is surfaced to the operator over SSH; the server is configured to refuse to start until that password exists.
- Safe-by-default network posture: the web console, REST API and PostgreSQL wire protocol listen on loopback until you expose them with one documented command, and the line-protocol TCP and UDP receivers, which accept unauthenticated writes by default, are disabled.
- Privacy by default: QuestDB's usage telemetry and product analytics are turned off.
- Security hardening aligned to the Oracle Cloud Marketplace image standards: SELinux enforcing, host firewall default-deny with only SSH, 9000 and 8812 permitted, no account with a usable password, and the image fully patched at build time.
Still stuck?
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.
QuestDB is a trademark of QuestDB Technology Inc. This image is an independent hardened distribution of QuestDB open source (Apache License 2.0) and is not affiliated with, endorsed by, or sponsored by QuestDB Technology Inc.