Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.
At a glance
| Status | Submitted for Oracle certification review |
|---|
| Version | 2.5.5 |
|---|
| Platform | Oracle Linux 9 |
|---|
| Ports open in the host firewall | SSH (22/tcp), 3001/tcp |
|---|
| Category | Cloud management |
|---|
| Upstream licence | MIT |
|---|
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
|---|
Quick start
This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.
After launch:
- Connect over SSH as the opc user with the key you supplied at launch:
ssh opc@PUBLIC_IP
- On first boot the image generates an instance-unique TLS certificate and creates the Uptime Kuma administrator before the service ever listens, so the web setup page that hands a new instance to its first visitor is never served. Check both units:
sudo systemctl status uptime-kuma-firstboot uptime-kuma
- Read the administrator password generated uniquely for this instance (root only):
sudo cat /root/.uptime-kuma_default_credentials
Smoke-test the server over TLS:
sudo curl -s --cacert /etc/uptime-kuma/tls/cert.pem https://127.0.0.1:3001/api/entry-page
- Uptime Kuma listens on 127.0.0.1:3001 (HTTPS) as shipped. Open it from your workstation through an SSH tunnel:
ssh -L 3001:127.0.0.1:3001 opc@PUBLIC_IP
then browse to https://localhost:3001 and sign in as admin. Change the password in Settings -> Security, where you can also turn on two-factor authentication.
- To serve your team directly instead of through the tunnel, rebind and restart, then browse to https://PRIVATE_IP:3001
sudo sed -i 's/^UPTIME_KUMA_HOST=127.0.0.1$/UPTIME_KUMA_HOST=0.0.0.0/' /etc/uptime-kuma/uptime-kuma.env && sudo systemctl restart uptime-kuma
Browsers verify the server with /etc/uptime-kuma/tls/cert.pem (its SAN lists the instance's private IPs), or install a CA-issued pair at /etc/uptime-kuma/tls/cert.pem and key.pem (key readable by group uptime-kuma).
- Port 3001 is already permitted in the host firewall. Restrict it in your VCN security list to your users' CIDR; never expose it to the internet. Monitors send requests from this instance into your network, so share the administrator account only with people you trust.
- Monitors, settings and the SQLite database live in /var/lib/uptime-kuma; for anything beyond evaluation place it on a block volume. Prometheus metrics are served at /metrics (HTTP basic authentication as admin, or an API key once you create one). The update check that contacts the project's version server is off (Settings -> About).
The image is CVE-patched at build time. Apply ongoing operating system updates with:
sudo dnf -y update
Uptime Kuma itself is installed from hash-verified upstream release files and is refreshed by launching a newer image version of this listing.
What the image provides
- Uptime Kuma 2.5.5 installed from the upstream release files, each verified by SHA-256 at build time, with every server-side package installed from the release's own lock file (integrity-checked, no install-time scripts), running as a dedicated unprivileged systemd service with filesystem hardening.
- No setup-page takeover: a stock Uptime Kuma instance belongs to whoever opens its setup page first. Here the administrator is created at first boot, before the service ever listens, with a password generated uniquely for this instance and surfaced to the operator over SSH — never a shared default credential.
- Encryption in transit: the web interface, status pages and metrics endpoint are served only over HTTPS with an instance-unique certificate generated at first boot.
- Privacy by default: the update check that contacts the project's version server is turned off.
- Safe-by-default network posture: Uptime Kuma listens on loopback until you expose it with one documented command; security hardening aligned to the Oracle Cloud Marketplace image standards — SELinux enforcing, host firewall default-deny with only SSH and 3001 permitted, no account with a usable password, and the image fully patched at build time.
Still stuck?
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.