Overview
Squid Proxy is a production-ready forward proxy and caching proxy image designed for egress control, content filtering, and bandwidth savings on AWS, with logging and monitoring already wired to native AWS services.
What Is Included
- Curated proxy configuration - A working, commented squid.conf applied at build time with custom access-log format and sensible ACLs, so the proxy is usable immediately. The stock config is preserved at /etc/squid/squid.conf.bak for reference.
- Production tuning - System and root file-descriptor limits raised to 65,535 for high concurrent connection counts, plus scheduled nightly log rotation.
- Amazon CloudWatch integration - CloudWatch Agent pre-configured to ship /var/log/squid/access.log, /var/log/squid/cache.log, /var/log/syslog, and /var/log/auth.log to CloudWatch Logs (per-instance streams, 30-day retention). Publishes CPU, memory, disk, TCP connection-state, and process metrics under the SolveDevOps/Squid namespace, tagged with instance ID, instance type, and Auto Scaling group.
- AWS Systems Manager integration - SSM Agent installed and enabled for Session Manager shell access without opening SSH, plus Patch Manager and Run Command support.
- CIS security hardening - Password SSH authentication disabled, root remote login disabled, X11 forwarding off, no baked-in keys, passwords, or shell history. Build-time credentials and cloud-init state scrubbed.
- Operational quick-start - Login banner with config path, log locations, and monitoring instructions.
- Vendor support - Email support from Solve DevOps for the image and its configuration.
Use Case: Centralized Egress Proxy for Microservices
Deploy Squid as a centralized egress proxy within your Amazon VPC to control and monitor outbound traffic from backend microservices. Route traffic from private subnets through the proxy to enforce domain-based ACLs, cache repeated API calls to external services, and gain full
Highlights
- Ready-to-run Squid forward proxy with a curated, documented squid.conf, file-descriptor limits raised to 65,535 for high concurrent connections, sensible ACLs pre-configured, and nightly log rotation. CIS-hardened image with SSH restricted to key-only authentication, root login disabled, X11 forwarding off, and no stored credentials or shell history. Deploy and proxy traffic on port 3128 immediately without manual configuration.
- Observability built in: CloudWatch Agent pre-configured to ship Squid access logs, cache logs, syslog, and auth logs to CloudWatch Logs with 30-day retention. Publishes CPU, memory, disk, TCP connection-state, and process metrics under the SolveDevOps/Squid namespace tagged by instance ID, instance type, and Auto Scaling group. Attach an IAM role with CloudWatchAgentServerPolicy and monitoring activates automatically.
- AWS Systems Manager Agent enabled for Session Manager shell access without opening SSH ports, plus Patch Manager and Run Command support. Attach AmazonSSMManagedInstanceCore policy to your instance role for immediate access. Email support from Solve DevOps covers image configuration, proxy tuning, and troubleshooting to help you get to production faster.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Cost/hour |
|---|---|
t3.small Recommended | $0.027 |
t3.micro | $0.027 |
t2.micro | $0.027 |
t3a.xlarge | $0.027 |
t3a.large | $0.027 |
r5ad.4xlarge | $0.027 |
r5.12xlarge | $0.027 |
r5.xlarge | $0.027 |
r5d.large | $0.027 |
r6i.4xlarge | $0.027 |
Vendor refund policy
Cancel Anytime
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Updates to the latest Security Patches for Squid and Ubuntu 26.04
Additional details
Usage instructions
Getting Started:
- Provision a VM with a suitable capacity for your needs.
- Access EC2 instance over SSH username: ubuntu password: EC2instance ID More advanced use cases can be found here: https://solvedevops.com/blog/getting-started-with-squid-proxy-server-in-the-cloud/
Support and Suggestions: support@solvedevops.com
Resources
Vendor resources
Support
Vendor support
Support from Solve DevOps
Solve DevOps provides email support for this Squid Proxy AMI covering image configuration, proxy tuning, ACL customization, CloudWatch integration, and troubleshooting.
Support Channel: Email support@solvedevops.com
For self-service guidance, visit the getting started blog at https://solvedevops.com/blog/getting-started-with-squid-proxy-server-in-the-cloud/ or contact us at
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products


