In Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.
At a glance
| Status | In Oracle certification review |
|---|
| Version | 6.1.0 |
|---|
| Platform | Oracle Linux 9 |
|---|
| Ports open in the host firewall | SSH (22/tcp), 8088/tcp |
|---|
| Category | Business applications |
|---|
| Upstream licence | Apache-2.0 |
|---|
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
|---|
Quick start
This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.
After launch:
- Connect over SSH as the opc user with the key you supplied at launch:
ssh opc@<public-ip>
- Superset runs as the superset systemd service (gunicorn web server) bound to loopback on port 8088; its metadata lives in a local PostgreSQL 16 database that is reachable only over a Unix socket. On first boot, superset-firstboot.service minted this instance's secret keys, built the metadata database and created your administrator, which takes three to five minutes. Check all three:
sudo systemctl status superset-firstboot superset postgresql
If first boot failed, read sudo journalctl -u superset-firstboot, fix the cause and reboot: it runs again on every boot until it completes, and superset starts only after it has.
- The administrator dcaadmin and its password were generated uniquely for this instance at first boot. Read them (root only):
sudo cat /root/.superset_default_credentials
- Smoke-test from the instance: the health check, then a login through Superset's REST API with the generated password, which answers with an access token:
curl -fsS http://127.0.0.1:8088/health
curl -fsS -X POST http://127.0.0.1:8088/api/v1/security/login -H 'Content-Type: application/json' -d '{"username":"dcaadmin","password":"<password>","provider":"db"}'
- Open the web UI through an SSH tunnel from your workstation (no exposure needed), browse to http://localhost:8088 and sign in as dcaadmin. PostgreSQL data sources work out of the box; add connections under Settings > Database Connections.
ssh -L 8088:127.0.0.1:8088 opc@<public-ip>
- To serve users on your network, expose it deliberately: bind the web server to all interfaces, then restart it.
sudo sed -i 's/^SUPERSET_BIND=.*/SUPERSET_BIND=0.0.0.0:8088/' /etc/superset/superset.env
sudo systemctl restart superset
Port 8088 is already permitted in the host firewall. Restrict it in your VCN security list to your users' CIDR, never expose it to the internet, and terminate TLS in front of it (for example on an OCI load balancer).
- Rotate the administrator password at any time (you are prompted twice, so it never appears on the command line), then update /root/.superset_default_credentials. Give each person a named account under Settings > List Users instead of sharing dcaadmin:
sudo /usr/local/sbin/superset-cli fab reset-password --username dcaadmin
- Superset's state is the PostgreSQL database superset (data in /var/lib/pgsql/data) plus the keys in /etc/superset. Back them up together, because the secret key encrypts the database passwords Superset stores:
sudo -u postgres pg_dump -Fc -f /var/lib/pgsql/superset.dump superset
The image is CVE-patched at build time. Apply ongoing Oracle Linux, Python 3.12 and PostgreSQL updates with:
sudo dnf -y update
Superset and its Python libraries are pinned in /opt/superset/venv and are not changed by dnf; new Superset releases ship as new versions of this image.
What the image provides
- Apache Superset 6.1.0, the current stable release, installed from the official release on PyPI together with exactly the dependency set the Superset project tested for that release. Every one of the roughly 160 Python packages is pinned and verified against a SHA-256 hash recorded in the build, and the finished environment is checked against that lock, so nothing is resolved or substituted on build day. It runs in an isolated virtual environment on Python 3.12 from the Oracle Linux 9 AppStream repository, served by the gunicorn web server as a dedicated unprivileged system user with a locked-down systemd profile (read-only system and code, no capabilities, private temporary files and devices).
- A local PostgreSQL 16 metadata database from the Oracle Linux 9 AppStream repository, reached only over a Unix socket with operating-system (peer) authentication: the database listens on no network port and has no password to leak. The PostgreSQL driver is included, so PostgreSQL data sources work out of the box.
- Instance-unique secrets, generated on first boot and never baked into the image: the Flask secret key that signs sessions and API tokens and encrypts the database passwords Superset stores, the two token-signing secrets Superset otherwise ships with published defaults, and the administrator's password, readable by root only. The metadata schema and the administrator account are created on first boot, and no example data is loaded.
- Safe-by-default network posture: Superset listens on loopback until you expose it deliberately with one documented setting, and you can use it immediately through an SSH tunnel. The web port (8088) is declared in the host firewall; everything else stays behind the firewall's default-deny.
- Security hardening aligned to the Oracle Cloud Marketplace image standards: SELinux enforcing, host firewall default-deny with only SSH and 8088 permitted, SSH key-only, no account with a usable password, no stray keys, and the image fully patched at build time.
Still stuck?
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.
Apache Superset is open-source software released under the Apache License 2.0. Apache®, Apache Superset™, Superset™ and the Superset logo are either registered trademarks or trademarks of the Apache Software Foundation, used here only to identify the software this image runs. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the Apache Software Foundation.