SonarQube installation on Redhat Linux

Are you still finding code quality issues only after deployment?

Modern DevOps and DevSecOps teams shift quality and security checks earlier in the software delivery lifecycle. SonarQube helps teams identify bugs, code smells, security vulnerabilities, and technical debt before applications reach production.

In this tutorial, we will install SonarQube 10 on Rocky Linux 8/CentOS 8 using PostgreSQL and Java 17, and prepare it for integration with modern CI/CD pipelines such as Jenkins, GitLab CI, GitHub Actions, and Azure DevOps.

Code smell tool SonarQube installation on linux
SonarQube installation on Vagrant box Linux


As of my last update in August 2023, SonarQube 10 already released. However, I can provide you with general steps to install SonarQube on CentOS/Rocky 8. Please note that the steps might need adjustments based on the specific versions you are using.

What we'll learn in this post?

By the end of this article, you will be able to:

  • Install SonarQube 10 on Rocky Linux 8 or CentOS 8
  • Configure PostgreSQL as the backend database
  • Configure Java 17 runtime
  • Tune Linux kernel parameters for SonarQube
  • Create a dedicated SonarQube service account
  • Start and manage SonarQube services
  • Access the SonarQube web dashboard
  • Troubleshoot common installation issues
  • Understand how SonarQube fits into a DevSecOps pipeline
Prerequisites:

For this demonstration, we will create a Rocky Linux/CentOS 8 virtual machine using Vagrant.

Recommended System Requirements

ComponentMinimumRecommended
CPU1 vCPU4 vCPU
Memory4 GB8 GB
Disk20 GB50 GB
JavaOpenJDK 17OpenJDK 17
DatabasePostgreSQLPostgreSQL

Ensure you have the following prerequisites installed on your CentOS 8 server:

Step 1: Create Vagrant box using Rocky(previously used Centos 8) Linux

Create a Vagrant CentOS/8 box for SonarQube installation:

 
Vagrant.configure(2) do |config|
  config.vm.box = "centos/8"
  config.vm.boot_timeout=600
  config.vm.define "sonarqube" do |sonarqube|
    sonarqube.vm.network "private_network", ip: "192.168.33.150"
    sonarqube.vm.hostname = "sonarqube.devopshunter.com"
    sonarqube.vm.provider "virtualbox" do |vb|
        vb.cpus = "4"
        vb.memory = "4096"
    end
  end
end
Bring up the box using `vagrant up`. 

Step 2: Update repo configuration

Since it is CentOS 8 requires this step. In the PuTTY / SSH terminal do run the following repo changes steps.
 
sudo cd /etc/yum.repos.d/
sudo sed -i 's/^mirrorlist/#mirrorlist/g' /etc/yum.repos.d/CentOS-*
sudo sed -i 's|#baseurl=http://mirror.centos.org|baseurl=http://vault.centos.org|g' /etc/yum.repos.d/CentOS-*
dnf update -y # update the repo      

Step 3: Create a dedicated SonarQube user

A dedicated user 'sonar' can be used for operations taken care by this user.

 
 sudo useradd sonar \
-c "SonarQube user" \
-d /opt/sonarqube \
-s /bin/bash;
sudo passwd sonar 

Enter New, confirm password.  

Benefits of this dedicate user:

  • Better security
  • Easier auditing
  • Principle of least privilege

Step 4: Configure Linux Kernel parameters

To tune increasse the vm_max_map_count kernal, file descriptor and limits add permanently use the following steps:
sudo vi /etc/sysctl.conf 
#Enter the following lines at end
vm.max_map_count=262144
fs.file-max-65536
 
sudo  vi /etc/security/limits.conf 
# Add the following lines a the end of the file:
sonar - nofile 65536
sonar - noproc 4096
After changes above `reboot` system.




Software requirements

Java JDK 17 (SonarQube Latest version typically requires Java 17) this may vary as per current Java version availability.

PostgreSQL database

Step 5: Java Installation

If you don't have Java 11 installed, you can do so with the following commands:
sudo yum install java-17-openjdk  -y
java -version
# If multiple version exists then you can map right Java with this:
sudo update-alternatives --config java 

Step 6: Install PostgreSQL:

SonarQube requires a database to store its data. You can use PostgreSQL as the database backend. Install it using the following commands:
 
sudo dnf install postgresql-server postgresql-contrib
sudo postgresql-setup --initdb
sudo systemctl start postgresql
sudo systemctl enable postgresql
sudo systemctl status postgresql # Check it is active

This may create 'postgres' user, you can set passwd for it by
su - postgres 
psql 

Step 7: Create a PostgreSQL Database for SonarQube

Create a PostgreSQL database and user for SonarQube. Replace sonarqube_db, sonarqube_user, and your_password with your desired values.
sudo -u postgres psql
CREATE DATABASE sonarqube_db;
CREATE USER sonarqube_user WITH ENCRYPTED PASSWORD 'your_password';
ALTER USER sonarqube_user WITH SUPERUSER;
ALTER DATABASE sonarqube_db OWNER TO sonarqube_user;
\q
You can check the postgres running on which port :
netstat -tulpn |grep postgres 

Step 8: Download and Install SonarQube

Download the SonarQube distribution and install it on your system:
sudo yum install wget unzip -y
wget https://binaries.sonarsource.com/Distribution/sonarqube/sonarqube-<version>.zip

 unzip sonarqube-<version>.zip
For example: 
sudo wget https://binaries.sonarsource.com/Distribution/sonarqube/sonarqube-10.1.0.73491.zip
sudo unzip sonarqube-10.1.0.73491.zip -d /opt/
sudo mv /opt/sonarqube-10.1.0.73491 /opt/sonarqube

Step 9: Configure SonarQube

Edit the SonarQube configuration file to set up the database connection and listen on the appropriate IP address:

sudo vi /opt/sonarqube/conf/sonar.properties

Update the following properties with your PostgreSQL database information:
 
sonar.jdbc.url=jdbc:postgresql://localhost/sonarqube_db
sonar.jdbc.username=sonarqube_user
sonar.jdbc.password=your_password
Start SonarQube:
Start the SonarQube service:
/opt/sonarqube/bin/linux-x86-64/sonar.sh start
/opt/sonarqube/bin/linux-x86-64/sonar.sh status
To check the sonarqube logs navigate to the /opt/sonarqube/logs/ and the file sonar.log 
Troubleshoot point:

Step 10: Configure SonarQube Service User 

Modify sonar.sh script to handle service user related configuration

sudo vi /opt/sonarqube/bin/linux-x86-64/sonar.sh

You can find 
RUN_AS_USER= 
set that line as
RUN_AS_USER=sonar

Troubleshooting Guide

SonarQube Does Not Start

Check:

tail -f /opt/sonarqube/logs/sonar.log

Elasticsearch Bootstrap Errors

Verify:

sysctl vm.max_map_count

Expected:

262144
    

Database Connection Failure

Verify:

psql -h localhost \
-U sonarqube_user \
-d sonarqube_db

Port Already In Use

Check:

ss -tulpn | grep 9000

Access SonarQube:

Open a web browser and access SonarQube using the URL http://your_server_ip:9000. The default credentials are 'admin' for both the username and password. You will be prompted to change the password during the first login.

Finally we have reached the end of this topic, successfully installed and configured SonarQube on CentOS/8 or any RHEL flavors. 

Remember to check the official SonarQube documentation for any specific instructions related to SonarQube 10 or any updates beyond my knowledge cutoff date.

Modern DevSecOps Benefits of SonarQube

Shift Security Left : 

Detect vulnerabilities before deployment.

Quality Gates

Prevent low-quality code from reaching production.

Technical Debt Visibility

Track maintainability improvements over time.

CI/CD Integration

Automate code analysis during every build.

Developer Productivity

Provide instant feedback directly within pipelines.

Real-World Use Cases

  • Java application quality analysis
  • Python code scanning
  • Kubernetes manifest validation
  • Infrastructure-as-Code quality checks
  • Pull Request quality gates
  • Enterprise secure SDLC implementation

Conclusion

SonarQube has become a critical component of modern DevSecOps practices by helping organizations continuously monitor code quality, security vulnerabilities, and technical debt.

By following this guide, you have successfully installed SonarQube 10 on Rocky Linux 8/CentOS 8 using PostgreSQL and Java 17. The next step is integrating SonarQube into your CI/CD pipeline so that every code change is automatically analyzed before reaching production.

Dear Reader Question for you

How are you currently using SonarQube in your organization—Jenkins pipelines, GitHub Actions, GitLab CI/CD, Azure DevOps, or standalone code reviews?

Share your experience in the comments and help other DevOps engineers learn from real-world implementations.

Comments

Popular Articles

DevOps Weapons

Ansible URI Module Tutorial: Real-World Application Health Checks, REST API Validation and DevOps Automation

Ansible Jinja2 Templates: A Complete Guide with Examples