Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / Temporal

Live

DCA Hardened Workflow Engine for Temporal — Support & Quick Start

A hardened, CVE-patched virtual machine image running a self-hosted Temporal service — the open-source durable-execution and workflow-orchestration engine — on Oracle Linux 9.

At a glance

StatusLive on Oracle Cloud Marketplace
Version1.31.2
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 7233/tcp
CategoryApplication development
Upstream licenceMIT
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@PUBLIC_IP
  2. On first boot the image initializes PostgreSQL, installs the Temporal schema and generates an instance-unique database password; this can take a minute. Check both services:
    sudo systemctl status postgresql temporal
  3. The frontend serves gRPC on 127.0.0.1:7233 and the HTTP API on 127.0.0.1:7243 — loopback only until step 6. Smoke-test from the instance (the reply reports the server version):
    curl -s http://127.0.0.1:7243/api/v1/system-info

    From a workstation with the Temporal CLI, tunnel instead of exposing:

    ssh -L 7233:127.0.0.1:7233 opc@PUBLIC_IP
    temporal operator cluster health --address 127.0.0.1:7233
  4. The PostgreSQL role 'temporal' password was generated uniquely for this instance at first boot. Read it (root only) and verify it against the running database:
    sudo cat /root/.temporal_default_credentials
    PGPASSWORD='YOUR_PASSWORD' psql -h 127.0.0.1 -U temporal -d temporal -tAc 'SELECT 1'

    PostgreSQL (5432) is loopback-only and rejects an empty password; it is Temporal's persistence store, not a customer-facing endpoint.

  5. No namespace exists yet. Create the default namespace the SDKs expect (3-day retention shown), then confirm it:
    curl -s -X POST http://127.0.0.1:7243/api/v1/namespaces -H 'Content-Type: application/json' -d '{"namespace":"default","workflowExecutionRetentionPeriod":"259200s"}'
    curl -s http://127.0.0.1:7243/api/v1/namespaces/default
  6. To reach the frontend from your application tier, expose it deliberately — it has no authentication by default. Bind it to all interfaces and restart:
    sudo sed -i 's/^BIND_ON_IP=.*/BIND_ON_IP=0.0.0.0/' /etc/temporal/env
    sudo systemctl restart temporal

    Port 7233 is already permitted in the host firewall. Restrict it in your VCN security list to the application tier's CIDR and front it with mTLS or an authorizing proxy; never expose it to the internet.

    The HTTP API (7243), history (7234), matching (7235), worker (7239), membership (6933, 6934, 6935, 6939) and PostgreSQL (5432) ports stay blocked by the host firewall after this change.

  7. Data lives in /var/lib/pgsql/data (PostgreSQL, the persistence store) and /var/lib/temporal. For anything beyond evaluation, attach a block volume for PostgreSQL. Recommended sizing: at least 2 OCPU (4 vCPU) and 16 GB memory.

The image is CVE-patched at build time. Apply ongoing updates with:

sudo dnf -y update

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

Temporal is a registered trademark of Temporal Technologies Inc. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by Temporal Technologies Inc.