This product has charges associated with it for hardening, security configuration, and support.
Ollama + Open WebUI is a complete private AI stack - run Llama, Mistral, Gemma, and 100+ LLMs locally with a ChatGPT-like interface. No OpenAI subscription, no data leaving your VPC. Authentication enabled, Nginx TLS proxy, Ollama API localhost-only, and CIS Level 1 hardened Ubuntu 24.04 LTS base. Built and maintained by Lynxroute.
Models are not pre-loaded - pull via Web UI or CLI after launch. For GPU inference use g4dn.xlarge or g5.xlarge.
Ollama is MIT-licensed; Open WebUI uses a source-available license (see Long Description for details).
This is a repackaged software product wherein additional charges apply for hardening, security configuration, and support.
WHAT IS OLLAMA + OPEN WEBUI
Ollama is a Go-based runtime for running large language models locally - it pulls quantized GGUF weights from the public Ollama library and exposes a streaming REST API for inference with optional GPU acceleration via NVIDIA CUDA. Open WebUI is a self-hosted ChatGPT-style web interface (FastAPI + Svelte) that connects to the local Ollama API and lets your team chat with models, manage conversations, upload documents for RAG, run web search, and configure prompt templates. The bundle supports CPU and GPU instance types (g4dn.xlarge, g5.xlarge), embedded SQLite for chat history and user accounts, and Llama, Mistral, Gemma, Phi, Qwen, DeepSeek-R1 and 100+ models pulled on demand. Together they form a complete private AI stack with no external service dependencies.
LICENSING NOTE
Ollama is MIT-licensed. Open WebUI is distributed under the source-available Open WebUI License (not an OSI-approved open-source license). The license permits self-hosted use without restriction; deployments with more than 50 end users in any 30-day window that also modify Open WebUI branding (name, logo) require a commercial Enterprise License from Open WebUI Inc. This AMI ships Open WebUI with the original branding preserved - the 50-user clause does not apply unless the operator rebrands.
WHAT THIS AMI ADDS
Security hardening:
Authentication enabled by default
Nginx reverse proxy with TLS - Open WebUI proxied on port 443
Ollama API (port 11434) bound to localhost only
UFW firewall - ports 22, 80, 443 only
fail2ban, AppArmor
OS hardening (CIS Level 1):
CIS Ubuntu 24.04 LTS Level 1 benchmark applied via ansible-lockdown
CIS Conformance Report at /etc/lynxroute/cis-report.html
CIS Tailored Profile at /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
Highlights
Private ChatGPT: run Llama, Mistral, Gemma and 100+ LLMs locally - no OpenAI subscription, no data leaving your VPC, authentication enabled by default. Built by Lynxroute.
CIS Level 1 hardened Ubuntu 24.04 LTS: auditd, fail2ban, AppArmor, SSH key-only, IMDSv2 enforced. CVE-scanned before every release. SBOM (CycloneDX) and CIS Conformance Report included.
GPU-ready: works with g4dn.xlarge (NVIDIA T4) and g5.xlarge (A10G) for fast inference - pull any model from ollama.com/library via Web UI or CLI.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 5 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
Ollama & Open WebUI - Hardened Private LLM Runtime
You pay by the hour based on the EC2 instance type you run. All six options deliver the same hardened LLM runtime image; they differ only in the underlying compute. Two GPU instances, g4dn.xlarge and g5.xlarge, suit models that need graphics acceleration. Two general-purpose instances, m6i.xlarge and m6i.2xlarge, offer more memory and CPU. Two burstable instances, t3.medium and t3.large, fit lighter workloads. Hourly rates scale with the size and capability of each instance. You add AWS infrastructure charges separately. Choose the instance that matches your workload and budget.
Top-of-mind questions for buyers
What do I actually receive when I launch one of these hourly instances?
You get a security-hardened Ubuntu 24.04 LTS image running the private LLM runtime. Each image ships with CIS Level 1 hardening, CVE scanning, a bundled software bill of materials, a conformance report, firewall, and unique credentials generated at first boot. The runtime is the same across all instance types.
Am I charged when I stop or power off the instance?
Software charges meter running instance-hours. A fully stopped instance stops accruing hourly software charges. Stopped instances may still incur separate AWS storage fees for attached volumes. Those AWS infrastructure charges are billed by AWS, not included in the hourly software rate.
How does my total bill combine the software charge and AWS costs?
Your invoice combines two parts. The hourly software rate covers the hardened runtime image for the instance type you choose. AWS bills its own compute, storage, and data transfer charges separately. Both accrue per hour the instance runs and appear on the same AWS Marketplace invoice.
lynxroute.com
Helpful?
Vendor refund policy
We do not offer refunds for this product. AWS infrastructure charges (EC2, EBS, data transfer) are billed separately by AWS and are not refundable by us. If you experience technical issues with the AMI, please contact us at https://lynxroute.com before requesting a refund.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Ollama 0.32.3 + Open WebUI 0.9.6
Ollama upgraded to 0.32.3 (from 0.32.1) - fixes stalled model downloads, adds GPU/model support, and includes upstream bugfixes (0.32.2 was withdrawn upstream). Open WebUI remains at 0.9.6; the client API surface is unchanged.
Certbot pre-installed - enable a trusted HTTPS certificate with one command: sudo certbot --nginx -d yourdomain.com
Rebuilt on the latest CIS Level 1 hardened Ubuntu 24.04 LTS base
Additional details
Usage instructions
Launch instance (t3.large for CPU inference, g4dn.xlarge for GPU inference)
Open Security Group - allow TCP 443 and TCP 80 from your IP
Open https://<PUBLIC_IP> - accept the self-signed certificate warning
Log in and pull a model: Settings - Models - search and pull (e.g. llama3.2)
Credentials are saved to /root/ollama-credentials.txt at first boot.
Models are NOT pre-loaded - pull via Web UI or CLI after launch.
For GPU inference, use g4dn.xlarge (NVIDIA T4) or g5.xlarge (A10G).
Replace the self-signed TLS certificate with a CA-signed certificate for production use.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for support. Ollama is a cutting-edge AI tool that empowers users to set up and run large language models, such as Llama 2 and 3, directly on their local machines. This innovative solution caters to a wide range of users, from experienced AI professionals to enthusiasts, enabling them to explore natural language processing without depending on cloud-based services.
This is a repackaged software product wherein additional charges apply for seller maintenance.
Deploy a powerful, self-hosted AI server supporting multiple LLMs (including Deepseek) via Open WebUI and Ollama. Streamline AI inference, customization, and local model management in a scalable AWS environment.
Deploy Open WebUI instantly with a preconfigured AMI for self hosted AI chat, LLM interaction, and collaborative AI workflows. This platform provides a modern web interface for large language models with secure access, customizable deployment, and scalable infrastructure for teams and developers.
This product has charges associated with it for seller support. This image comes with a prebuilt Ubuntu 26.04 AMI for private local LLM experimentation on EC2 with Ollama, Open WebUI, and a small preloaded validation model.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.