Listing Thumbnail

    Bastion Config - Passwordless PostgreSQL with mTLS

     Info
    Sold by: Fromkos 
    Deployed on AWS
    Free Trial
    Passwordless PostgreSQL in your own AWS account: applications connect with client certificates, so your code holds no database password to leak. Bastion Config is the certificate authority and mTLS control plane for PostgreSQL on EC2 - sealed at rest, every approval audited, with continuous WAL archiving and point-in-time recovery into your S3 bucket.

    Overview

    Open image

    Bastion Config removes database passwords from your applications. It runs entirely in your AWS account as one CloudFormation stack - an EC2 instance behind an Application Load Balancer, a retained data volume and a backup bucket - and acts as the certificate authority and mTLS control plane for the PostgreSQL hosts you attach to it. An application redeems a one-time credential once and then connects with a client certificate (one year by default, configurable). There is no password to put in a config file, a CI variable or a chat message, and revoking a certificate blocks new connections within minutes. A lightweight sidecar writes three PEM files, so any language and any PostgreSQL driver works with no SDK; Java changes one line of a JDBC URL.

    Security is built into the workflow, not bolted on. Every key is generated inside your VPC; the vendor holds no key, password or access to your installation. The installation starts sealed and opens only when a custodian unlocks it with a registered YubiKey or passphrase; private keys and Bastion's own backups are encrypted under a master key the disk never holds. Three administrator roles split the work, and every trust decision - enrolling a database host, granting an application access, changing the schema - is audited with a name and a reason. There is no remote superuser: schema changes are Liquibase changelogs uploaded in the console and run as a schema-owner role only Bastion can act as, so the changelog is a complete change history.

    Operations are covered from day one. The agent beside PostgreSQL archives WAL continuously and takes scheduled base backups into your own S3 bucket; point-in-time recovery is a form in the console, not a runbook. Database server certificates rotate with an overlap and a reload, not a restart, and upgrades are a stack parameter change that keeps your data volume, certificate authority and attached databases. No SSH; first sign-in well under an hour. One price on every supported instance size, billed through your AWS account, with a 30-day free trial.

    Highlights

    • Passwordless PostgreSQL with mTLS: applications connect with client certificates instead of passwords, so no database password can leak, and revoking a certificate blocks new connections within minutes. Any language, any PostgreSQL driver, no SDK.
    • Nothing to steal from the vendor: every key is generated inside your VPC, and the installation is sealed until a custodian unlocks it with a registered YubiKey or passphrase. Every trust decision is audited with a name and a reason.
    • Backups you own, restore you control: continuous WAL archiving and scheduled base backups into your S3 bucket, with point-in-time recovery driven from the console - no DBA runbook, no database password.

    Details

    Sold by

    Delivery method

    Delivery option
    Bastion Config - CloudFormation stack in your VPC

    Latest version

    Operating system
    Ubuntu 24.04

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free for 30 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.

    Bastion Config - Passwordless PostgreSQL with mTLS

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (4)

     Info
    Dimension
    Cost/hour
    t3.small
    $0.32
    t3.medium
    $0.32
    t3.large
    $0.32
    m6i.large
    $0.32

    AI Insights

     Info

    Dimensions summary

    You pay by the hour for the EC2 instance size that runs the software. The four options are instance types: t3.small, t3.medium, t3.large, and m6i.large. They differ by compute and memory capacity, so you pick the size that fits your workload. Billing is usage-based, charged per hour the instance runs. You set the instance type when you launch the CloudFormation stack, with t3.small as the default. This Marketplace charge is billed by AWS alongside the underlying infrastructure your stack uses.

    Top-of-mind questions for buyers

    Each option runs one EC2 instance behind an Application Load Balancer, plus a retained data volume (20 GB default) and a backup bucket. The four choices differ only in compute and memory. You set the type as a launch parameter, with t3.small as the default.
    Cancelling the subscription does not terminate a running instance. The hourly software charge meters the time the instance runs. To stop software charges, you remove the stack and its resources yourself. The retained data volume and backup bucket stay until you delete them.
    You also pay AWS for the underlying infrastructure: the EC2 instance, data volume, load balancer, and related services. Separate costs include a NAT gateway prerequisite, a backup bucket that grows with retention, and one EC2 instance per attached PostgreSQL database you run. These bill alongside the software charge.
    fromkos.com+2
    Helpful?

    Vendor refund policy

    Hourly usage is billed as used and is not refundable; the 30-day free trial lets you evaluate first. Annual subscriptions canceled within 30 days of purchase are refunded in full; after that, refunds are pro rata for unused full months. To request a refund, email bastion-config@fromkos.com  with your AWS account ID and agreement ID; approved refunds are processed through AWS Marketplace.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Bastion Config - CloudFormation stack in your VPC

    Deploys Bastion Config into an existing VPC in your account: the instance runs in a private subnet behind an Application Load Balancer that accepts HTTPS only from the CIDR you choose. The stack creates the ACM certificate and Route 53 records, one least-privilege IAM role, CloudWatch log groups, a data volume retained across instance replacement and stack deletion, and a versioned S3 bucket for PostgreSQL WAL archives and base backups. Requires a VPC with two private and two public subnets and a public Route 53 hosted zone.

    CloudFormation Template (CFT)

    AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."

    Version release notes

    First release on AWS Marketplace. Passwordless PostgreSQL with mTLS: certificate authority and control plane, one-command PostgreSQL attach, client certificates delivered once to each application (one year by default, configurable) and revocable at any time, continuous WAL archiving and point-in-time recovery into your S3 bucket, and an installation sealed until a custodian unlocks it with a YubiKey or passphrase. Supported instance types: t3.small, t3.medium, t3.large, m6i.large.

    Additional details

    Usage instructions

    Full guide: https://fromkos.com/docs/deployment  (every resource, role and key: https://fromkos.com/docs/aws-resources )

    BEFORE YOU LAUNCH (in the target Region)

    1. A VPC with two private subnets (outbound internet via NAT) and two public subnets, each pair in different AZs.
    2. A public Route 53 hosted zone that already answers for your domain (e.g. example.com for bastion.example.com). The stack creates the record and validates the ACM certificate through it.
    3. The CIDR allowed to reach the console (AllowedCidr). No default, on purpose.
    4. Two hardware security keys (YubiKey 5 / FIDO2) or a passphrase: setup starts with an unlock ceremony.
    5. Session Manager access to the instance. No SSH key or SSH port is used.

    PARAMETERS: leave ImageId and AppImage as they are. DataVolumeGb 20 is enough. The first name in PostgresDbUsers becomes the database owner.

    FIRST SIGN-IN

    1. Wait for CREATE_COMPLETE; first boot can take up to 30 minutes.
    2. Run the command from the FirstRunSecrets output: aws ssm start-session --region <region> --target <instance-id> sudo head -n 20 /opt/bastion/configs/setup_token /opt/bastion/configs/admin_pwd setup_token claims the installation and is valid 30 minutes. If it lapsed: sudo systemctl restart bastion, wait 20 s, read it again. admin_pwd is the first password for user admin; you change it at first login.
    3. Open the ConsoleUrl output. Bastion starts sealed: complete the setup ceremony with your keys, then sign in as admin.
    4. Attach PostgreSQL: the console's attach panel prints one command that downloads the attach Terraform for this exact release and reads the stack's outputs.

    IAM: the stack creates ONE role (InstanceRole), assumed only by this instance:

    • AmazonSSMManagedInstanceCore: Session Manager access, instead of SSH.
    • bastion-parameters: read/write only /bastion/pki/* and this stack's /bastion/app/image (PKI exchange with the PostgreSQL agents; image pin).
    • bastion-attach-own-volume: ec2:DescribeVolumes, and ec2:AttachVolume only on this stack's tagged volume and instance.
    • bastion-logs: write only to /bastion/* log groups. No other role, user or access key. The role cannot read your S3 buckets or call KMS, IAM or Marketplace APIs.

    KEYS: the template creates no KMS key; volumes use the account's default aws/ebs key. The CA private key lives wrapped on the EBS data volume, usable only after unlock. Unlock shares are held only by your operators. First-run secrets are 0600 files on the instance. AWS and the seller hold none of these.

    NETWORK: only the load balancer is reachable, HTTPS 443 from AllowedCidr. The load balancer reaches the instance on 8443 (console) and 8444 (certificate delivery). Attached PostgreSQL hosts reach it on 8000 and 1111, admitted by membership of BastionClientSecurityGroup.

    INTERNET (outbound HTTPS via NAT): the instance downloads the Bastion container image from Docker Hub (bastionsecurity/bastion-app, pinned by digest) and Ubuntu packages; the attach command downloads the Terraform bundle from the seller's public S3 bucket (SHA-256 checked). Nothing connects to the seller at runtime.

    UNRECOVERABLE BY DESIGN: the EBS data volume (identity, CA, control-plane database) and the unlock shares. The volume and the backup bucket are RETAINED when you delete the stack. Back both up before production.

    UPDATES: update the stack with the newer template. That writes the new release to SSM but does not restart the running app: restart it in a Session Manager session with sudo systemctl restart bastion. It comes back sealed; unlock it as at setup. The data volume survives even an instance replacement. Re-run the attach step on each PostgreSQL host afterwards.

    REMOVAL: delete the stack, then decide separately about the retained volume and bucket (irreversible). Unsubscribing does not terminate running instances.

    SUPPORT: bastion-config@fromkos.com , Monday-Thursday, US Pacific Time. Include your AWS account ID and stack name.

    Support

    Vendor support

    Email: bastion-config@fromkos.com  Documentation: https://fromkos.com/docs/overview  Support page: https://fromkos.com/docs/support 

    Support is by email, in English, Monday to Thursday during US Pacific Time working hours. Include your AWS account ID and the CloudFormation stack name so we can identify your subscription.

    Target first response: 5 business days (Monday-Thursday). This is a response target, not an uptime, incident-response, or fix-time guarantee. There is no SLA and no 24/7 coverage.

    Covered:

    • Launching and configuring the product with the supplied CloudFormation template, on the instance types it offers.
    • The sealed setup and unlock ceremony, domain and administrator setup, certificate issuance, and attaching a PostgreSQL database.
    • Backup, restore, and point-in-time recovery using the documented procedures.
    • Bug reports against the current version, with logs, versions, and steps to reproduce.
    • Subscription and entitlement questions.

    Not covered:

    • Operating your installation, production incident response, or guaranteed fix times.
    • Custom topologies, custom integrations or code changes.
    • Your AWS account, networking, IAM, or charges billed by AWS.
    • Review of unredacted secrets. Never send private keys, unlock shares, or secret values.

    Two things nobody can recover for you: the data volume the stack creates (it holds the installation's identity, certificate authority, and control-plane database, and deliberately survives instance replacement) and the unlock shares handed out during setup. By design, we can't reconstruct either. Back both up before production.

    Refunds are handled through AWS Marketplace under the refund policy on this listing.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.