Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / Uptime Kuma

In Oracle review

DCA Hardened Uptime Monitoring for Uptime Kuma — Support & Quick Start

A hardened, CVE-patched virtual machine image running Uptime Kuma 2.5 — the open-source, self-hosted monitoring tool for websites, APIs, servers and network services — on Oracle Linux 9.

Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusSubmitted for Oracle certification review
Version2.5.5
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 3001/tcp
CategoryCloud management
Upstream licenceMIT
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@PUBLIC_IP
  2. On first boot the image generates an instance-unique TLS certificate and creates the Uptime Kuma administrator before the service ever listens, so the web setup page that hands a new instance to its first visitor is never served. Check both units:
    sudo systemctl status uptime-kuma-firstboot uptime-kuma
  3. Read the administrator password generated uniquely for this instance (root only):
    sudo cat /root/.uptime-kuma_default_credentials

    Smoke-test the server over TLS:

    sudo curl -s --cacert /etc/uptime-kuma/tls/cert.pem https://127.0.0.1:3001/api/entry-page

  4. Uptime Kuma listens on 127.0.0.1:3001 (HTTPS) as shipped. Open it from your workstation through an SSH tunnel:
    ssh -L 3001:127.0.0.1:3001 opc@PUBLIC_IP
    then browse to https://localhost:3001 and sign in as admin. Change the password in Settings -> Security, where you can also turn on two-factor authentication.
  5. To serve your team directly instead of through the tunnel, rebind and restart, then browse to https://PRIVATE_IP:3001
    sudo sed -i 's/^UPTIME_KUMA_HOST=127.0.0.1$/UPTIME_KUMA_HOST=0.0.0.0/' /etc/uptime-kuma/uptime-kuma.env && sudo systemctl restart uptime-kuma

    Browsers verify the server with /etc/uptime-kuma/tls/cert.pem (its SAN lists the instance's private IPs), or install a CA-issued pair at /etc/uptime-kuma/tls/cert.pem and key.pem (key readable by group uptime-kuma).

  6. Port 3001 is already permitted in the host firewall. Restrict it in your VCN security list to your users' CIDR; never expose it to the internet. Monitors send requests from this instance into your network, so share the administrator account only with people you trust.
  7. Monitors, settings and the SQLite database live in /var/lib/uptime-kuma; for anything beyond evaluation place it on a block volume. Prometheus metrics are served at /metrics (HTTP basic authentication as admin, or an API key once you create one). The update check that contacts the project's version server is off (Settings -> About).

The image is CVE-patched at build time. Apply ongoing operating system updates with:

sudo dnf -y update

Uptime Kuma itself is installed from hash-verified upstream release files and is refreshed by launching a newer image version of this listing.

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.