Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / VictoriaMetrics

Live

DCA Hardened Metrics Database for VictoriaMetrics — Support & Quick Start

A hardened, CVE-patched virtual machine image running VictoriaMetrics — a fast, cost-efficient, Prometheus-compatible time-series database — on Oracle Linux 9.

At a glance

StatusLive on Oracle Cloud Marketplace
Version1.147.0
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 8428/tcp
CategoryCloud management
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@<public-ip>
  2. VictoriaMetrics runs as a systemd service under the unprivileged user victoriametrics, bound to loopback only (HTTP 127.0.0.1:8428). It ships with NO authentication, so nothing is reachable from outside the instance until step 5. Check status:
    sudo systemctl status victoriametrics
  3. Smoke-test from the instance: health, the running version, then write one sample and read it back (allow a second or two for the write to become searchable):
    curl -s http://127.0.0.1:8428/health
    curl -s http://127.0.0.1:8428/metrics | grep vm_app_version
    curl -s -d 'smoke_test 42' http://127.0.0.1:8428/api/v1/import/prometheus
    curl -s 'http://127.0.0.1:8428/api/v1/export?match=smoke_test'
  4. Use the web UI and query API from your workstation without exposing anything: tunnel over SSH, then open http://localhost:8428/vmui in your browser:
    ssh -L 8428:127.0.0.1:8428 opc@<public-ip>
  5. To let other hosts write and query (Prometheus remote_write url: http://<private-ip>:8428/api/v1/write), bind to all interfaces AND turn on HTTP basic auth in one edit of the service's ExecStart flags — pick a password of letters and digits only — then reload:
    sudo sed -i 's|-httpListenAddr=127.0.0.1:8428|-httpListenAddr=0.0.0.0:8428 -httpAuth.username=admin -httpAuth.password=<password>|' /etc/systemd/system/victoriametrics.service
    sudo systemctl daemon-reload && sudo systemctl restart victoriametrics

    Every endpoint now requires the credentials (curl -u admin:<password> ..., basic_auth in the remote_write block, and basic_auth in any scrape job for /metrics); only /health stays open, for load-balancer probes. Port 8428 is already permitted in the host firewall.

    Restrict 8428 in your VCN security list to your collectors' and Grafana's CIDR; never expose 8428 to the internet.

  6. Only 8428 is open. The Graphite (2003), OpenTSDB (4242) and InfluxDB line-protocol (8089) listeners are disabled in this image (no -graphiteListenAddr, -opentsdbListenAddr or -influxListenAddr flag) and those ports stay blocked by the host firewall.
  7. Data lives in /var/lib/victoria-metrics with 12 months of retention (-retentionPeriod=12 in the same unit file; add an h, d, w or y suffix for other units). For anything beyond evaluation, stop the service, mount a block volume at that path owned by victoriametrics, and start it again; in-memory data is flushed to disk on every clean stop.

The image is CVE-patched at build time. Apply ongoing updates with:

sudo dnf -y update

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

VictoriaMetrics is a trademark of VictoriaMetrics, Inc. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by VictoriaMetrics, Inc.