> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-2.-deploy-your-virtual-machine-on-oci.md).

# Task 2. Deploy your virtual machine on OCI

Currently, only Oracle Public Cloud is supported (not Government Cloud).

If you set your Cortex XSOAR environment as a standalone (single node), you cannot add nodes to it and switch to a cluster. If you deploy three nodes, you can later add nodes and expand the cluster. For more information, see [Manage nodes in a cluster](/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/optimize-performance-and-robustness-from-the-textual-ui.md#manage-nodes-in-a-cluster).

{% hint style="warning" %}
To implement built-in High Availability, deploy a cluster with three nodes (VMs), with each VM on a different hypervisor. This ensures that if one hypervisor fails, the other VMs continue to operate.

You then need to:

* Establish trust between all nodes in the cluster (Task 6).
* Set the Cluster FQDN to the reverse proxy/ingress controller IP address (Task 7). The reverse proxy/ingress controller serves as a single entry point to distribute traffic across the nodes in the cluster.

To configure backup and restore in your tenant, see [Back up data](/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/back-up-data.md).
{% endhint %}

1. In OCI, upload the OVA image file to a private bucket.

   Make sure the bucket is private and secure.
2. Import the image from the bucket into the OCI environment.

   ![Import the image](https://docs-cortex.paloaltonetworks.com/api/khub/maps/_pgJmah_jOQZMdDuGbjUsg/resources/W~IThD1ZK8xw3Q2ep1CA4Q-_pgJmah_jOQZMdDuGbjUsg/content?v=304897cf634308ac\&Ft-Calling-App=ft/turnkey-portal)
3. Disable CPU logging and performance (DRS). For more information, see Oracle [Define or Edit Server Pool Policies](https://docs.oracle.com/cd/E50245_01/E50250/html/vmusg-svrpool-policy-configure.html).

   ![opp-drs-disable.png](https://docs-cortex.paloaltonetworks.com/api/khub/maps/_pgJmah_jOQZMdDuGbjUsg/resources/JHet~Qfv9beSxK8JsNJ2Dw-_pgJmah_jOQZMdDuGbjUsg/content?v=abff66f4acca0fcf\&Ft-Calling-App=ft/turnkey-portal)
4. Create the instance.

   ![opp-oci-create-an-instance.png](https://docs-cortex.paloaltonetworks.com/api/khub/maps/_pgJmah_jOQZMdDuGbjUsg/resources/tE8gF2M_n~33bE4s5X1wAQ-_pgJmah_jOQZMdDuGbjUsg/content?v=8663ac98b3cb762f\&Ft-Calling-App=ft/turnkey-portal)
5. Create a block volume.

   The block volume size depends on the scale you want to use. For example, 1024 GB (1TB) corresponds to the hardware requirements for a small scale deployment with a 256 GB boot disk plus an additional separate 775 GB data disk.

   <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p>Every virtual machine includes a 256 GB OS disk. Add a separate data disk for each application instance.</p><p>Ensure the disks meet the <a href="/spaces/7HkFeeCibkdZoGaTJCzm/pages/f3Vt1vz8EtvmLv3kK8rf">System requirements</a>.</p><p>All virtual machines in a cluster must have the same storage size.</p></div>

   ![opp-oci-create-block-volume.png](https://docs-cortex.paloaltonetworks.com/api/khub/maps/_pgJmah_jOQZMdDuGbjUsg/resources/viO1KwhzL1SnH6Jjdy8scg-_pgJmah_jOQZMdDuGbjUsg/content?v=b9d03dc7948e762e\&Ft-Calling-App=ft/turnkey-portal)
6. Attach the block volume to the running instance.

   The attachment type needs to be Paravirtualized (and not iSCSI).

   ![opp-oci-attach-block-volume.png](https://docs-cortex.paloaltonetworks.com/api/khub/maps/_pgJmah_jOQZMdDuGbjUsg/resources/8c_fk9uNANRULEYaI2ikSA-_pgJmah_jOQZMdDuGbjUsg/content?v=c103990452434709\&Ft-Calling-App=ft/turnkey-portal)
7. Repeat these steps for each VM in a cluster.
8. For first-time login, open an external terminal and use the `ssh admin<server ip address>` command to SSH log in. The default username and password is `admin`.

   ![opp-oci-cloud-shell.png](https://docs-cortex.paloaltonetworks.com/api/khub/maps/_pgJmah_jOQZMdDuGbjUsg/resources/0WDz06eAHdc~7e1f~Ydbgg-_pgJmah_jOQZMdDuGbjUsg/content?v=c7ebdd435a3f56c7\&Ft-Calling-App=ft/turnkey-portal)

   Give the admin a new password as follows.

   <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p>Save the SSH password securely. If you lose this password, you cannot recover or change it, and to use SSH you will need to redeploy the cluster.</p></div>

   The password must be at least eight characters long and contain at least:

   * One lower case letter
   * One upper case letter
   * One number, or one of the following special characters: !@#%

   If this is not a first-time login, you can log in from the web console or from a terminal using the `ssh admin@<server ip address>` command to SSH log in.

   The textual UI menu opens with all the configuration and installation options.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><ul><li>To start using the textual UI, click anywhere on the screen.</li><li>To navigate between the menu items, use the up and down arrow keys. To select a menu item, press the Enter key.</li><li>To navigate between fields within a menu item, use the Tab key. To save settings, tab to the Save button and press the Enter key.</li><li>To go back to the menu from a specific menu item field, press the esc key.</li></ul></div>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-2.-deploy-your-virtual-machine-on-oci.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
