Ubuntu Pro EKS is an Ubuntu AWS Machine Image, optimized for EKS with 10 years of security maintenance, covering not only the OS but also its 3rd party open source repositories. Clusters built from this AMI can also benefit from using this extended security maintenance in an unlimited number of containers running on the cluster. This allows teams to consume freely open source software while meeting internal security, governance and compliance requirements.
Ubuntu Pro EKS remains fully-compatible with Ubuntu EKS 22.04 LTS, adding additional security, enabled by default, as well as compliance and management tools in a form suitable for small to large-scale Linux operations.
Why developers and devops choose Ubuntu Pro for AWS:
Upgrade your in-container experience by adding access to security updates for 30,000+ packages including Apache Kafka, NGINX, MongoDB, Redis and PostgreSQL
Security hardening and audit tools (CIS) to establish a security baseline across your systems
FIPS 140-2 certified modules
Kernel Livepatch: kernel patches delivered immediately, without the need to reboot your nodes
Optimized performance: optimized kernel, with improved boot speed, outstanding runtime performance and advanced device support
10-year security maintenance: Ubuntu Pro 22.04 LTS provides security maintenance until April 2032
Production ready: Ubuntu is the leading Linux in the public cloud with > 50% of Linux workloads
Developer friendly: Ubuntu is the #1 Linux for developers offering the latest library and tools to innovate with the latest technologies and security coverage.
Non-stop security: Canonical publishes images periodically, ensuring security is built-in from the moment an instance launches
Consistent experience across platforms: from edge to multi-cloud, Ubuntu provides the same experience regardless of the platform. It will ensure consistency of your CI/CD pipelines and management mechanisms.
These images are based on the official Ubuntu Minimal LTS, including the custom Ubuntu-aws optimized kernel with Ubuntu Pro kernel livepatch and ESM enabled. They have been built specifically for the EKS service, therefore are not intended as general OS images.
To deploy Ubuntu worker nodes on EKS, you can use eksctl, EC2 Launch templates on the EKS web console, Cloudformation templates and other mechanisms.
For guidance on adding Ubuntu Pro security patches to your container build processes for containers that will run on a cluster made from this AMI, please contact us.
Highlights
Secure your in-container experience with Canonical's security coverage for more than 23,000 open source packages.
Run workloads without disruption with Ubuntu Pro's Kernel Livepatch.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for Ubuntu Pro 22.04 LTS running on your EKS worker nodes. Each dimension maps to one specific EC2 instance type, from small general-purpose nodes to large memory-, compute-, storage-, and GPU-focused machines. The hourly rate scales with the instance you choose, so pricing follows the size and capability of the node. You are billed only for the hours each node runs, with no upfront commitment. This subscription adds security maintenance, hardening, and compliance tooling on top of the base operating system across whichever instance types you deploy.
Top-of-mind questions for buyers
What counts as one billable unit for this Ubuntu Pro subscription?
Each EC2 instance type you run as an EKS worker node counts as one billable unit. You pick a dimension matching the instance you deploy. The hourly software rate meters running time for that node, alongside the standard AWS compute charges for the instance itself.
Am I charged when an EKS worker node is stopped or scaled down?
The software rate meters running hours only. When a node is stopped or removed by autoscaling, it stops accruing Ubuntu Pro hourly charges. Underlying AWS storage or reserved capacity fees may still apply separately, but the software licence bills active running time.
What does the Ubuntu Pro subscription add on top of the base operating system?
You get extended security maintenance, kernel updates applied without reboot, hardening and audit tooling for common compliance profiles, and access to a wider trusted open source package repository. Coverage runs up to 10 years for the OS and packages, with longer add-on options.
cloud.ubuntu.com
Helpful?
Vendor refund policy
No refunds will be issued for usage of this product.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Automated version update for new release
Additional details
Usage instructions
For Ubuntu Cloud Guest it is suggested to manually configure your Security Group/Firewall settings. The 1-Click Security Group opens only port 22 so that you can access your instance via ssh using login 'ubuntu'. If you chose the 1-Click Security Group, you may change it later to enable applications using the AWS Console or API.
Ubuntu Pro with Support provides a supported and secure foundation for modern applications by adding 24x7 technical support for your Ubuntu Pro workloads on AWS. Learn more at
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Security updates for 30,000+ open source packages including Apache Kafka, NGINX, MongoDB, Redis and PostgreSQL with 10-year maintenance window until April 2032
Kernel Live Patching
Kernel patches delivered and applied without requiring node reboot
FIPS 140-2 Certification
FIPS 140-2 certified modules with FedRAMP compliance and FIPS mode availability
Security Hardening and Compliance Tools
CIS security hardening and audit tools to establish security baseline across systems
Optimized Kernel Performance
Custom Ubuntu-aws optimized kernel with improved boot speed, runtime performance and advanced device support
Operating System Hardening
Amazon Linux 2 configured with STIG Benchmark High standard for enhanced security posture
Security Standards Compliance
Implementation of Defense Information System Agency (DISA) Security Technical Implementation Guides (STIGs) for system hardening
EMR Compatibility
Tested and compatible with Amazon Elastic MapReduce (EMR) for distributed computing workloads
Continuous Security Updates
Access to continuous security updates available through new versions of the image
Multi-Application Support
Suitable for deployment across various applications beyond EMR environments
Security Hardening Standard Compliance
Container image hardened according to CIS Benchmark Level 1 profile with consensus-based security configuration guidance
Regulatory Compliance Support
Alignment with PCI DSS, FedRAMP, DoD Cloud Computing SRG, FISMA, and select NIST publications requirements
Pre-configured Security Controls
Hardened account and local policies, firewall configuration, and computer-based and user-based administrative templates pre-applied
Conformance Assessment and Reporting
Includes CIS-CAT Pro assessment reports, package inventory files, and exception documentation for benchmark compliance verification
Regular Security Maintenance
Monthly patching aligned with software vendor updates to maintain alignment with latest security standards
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.