Listing Thumbnail

    Hardened CentOS 9 Minimal (ARM64)

     Info
    Deployed on AWS
    This is a repackaged open source software product wherein additional charges apply for security hardening, optimization, and EC2 baseline validation provided by Hanwei. SELinux is enforcing, SSH is hardened and key-only, auditd is active, and kernel and resource limits are tuned for EC2.

    Overview

    Charges for this image cover the security hardening, optimization, and pre-integration work Hanwei performs on top of the upstream CentOS Stream project. No application software is added. This image provides a minimal, EC2-ready CentOS Stream 9 base that is patched to the build date and configured to a consistent hardening and tuning profile, so instances launch ready for use without a further baseline pass.

    What Hanwei Adds to Upstream CentOS Stream 9

    • 64-bit Arm build: The image targets aarch64 and runs on AWS Graviton instance families.
    • Hardening beyond distribution defaults: SSH is restricted to a modern key-exchange, cipher and MAC allow-list, root login and password authentication are disabled, MaxAuthTries is lowered, auditd ships with an expanded rule set, and kernel network parameters are set for a hardened posture.
    • A uniform tuning baseline: The soft open-file limit is raised from 1024 to 65536 (hard limit 524288), vm.max_map_count is raised from 65530 to 262144, the device receive backlog and TCP SYN backlog are enlarged, socket buffer ceilings are increased, tcp_slow_start_after_idle is disabled, and journald is capped at 500 MB. The profile raises ceilings only and does not alter protocol semantics or application behaviour.
    • AWS operational integration: The Amazon SSM Agent is installed and enabled, and chrony is pointed at the Amazon Time Sync service at 169.254.169.123.
    • Build dependencies preinstalled: gcc, make, pkgconf and openssl-devel are present, so software can be compiled on the instance without adding a toolchain.
    • Pinned patch level and reproducible build: Packages are updated to the build date and the image is produced by a reproducible build that is validated on EC2 before release.

    Access and Security Posture

    • SELinux is in enforcing mode.
    • The default login is the ec2-user account over SSH using key-based authentication.
    • Direct root login over SSH is disabled and password authentication is turned off.
    • No application credentials or SSH keys are baked into the image; host keys are generated on first boot.

    Operational Impact on EC2

    • The image runs on 64-bit Arm (Graviton) instance families.
    • The Amazon SSM Agent allows shell access through Session Manager without opening inbound SSH.
    • Time is synchronized through the Amazon Time Sync service reached at the link-local address.
    • cloud-init handles first-boot initialization: hostname, user data, and the login SSH key.
    • The patch level is fixed at build time, so launches from this version are reproducible.

    Where This Image Fits

    • A general-purpose CentOS Stream 9 base for services, application hosts and build agents.
    • Container and CI hosts, with gcc, make, pkgconf and openssl-devel already present.
    • Fleets managed through cloud-init and AWS Systems Manager.
    • Arm and Graviton deployments seeking price-performance.

    About CentOS Stream 9

    CentOS Stream 9 is the continuously delivered distribution that tracks the next Red Hat Enterprise Linux 9 minor release, providing a current, RHEL-compatible userland and kernel.

    Highlights

    • WHAT IS PACKAGED - A minimal CentOS Stream 9 image for 64-bit Arm (Graviton), patched to the build date, with gcc, make, pkgconf and openssl-devel preinstalled so no build toolchain has to be added.
    • HOW THE BASELINE IS HARDENED AND TUNED - SSH uses a modern algorithm allow-list with key-only login and root login disabled, auditd is active and SELinux is enforcing; the soft open-file limit goes from 1024 to 65536, vm.max_map_count is raised from 65530 to 262144, and socket backlogs and buffers are enlarged without changing protocol behaviour.
    • HOW IT FITS AWS OPERATIONS - The Amazon SSM Agent enables Session Manager access, chrony uses the Amazon Time Sync service, cloud-init handles first-boot setup, and the root filesystem expands to the EBS volume on first boot.

    Details

    Delivery method

    Delivery option
    64-bit (Arm) Amazon Machine Image (AMI)

    Latest version

    Operating system
    CentOs CentOS Stream 9

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Hardened CentOS 9 Minimal (ARM64)

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (222)

     Info
    • ...
    Dimension
    Cost/hour
    t4g.small
    Recommended
    $0.05
    c6g.large
    $0.10
    r7g.medium
    $0.05
    c8g.24xlarge
    $0.05
    c6g.8xlarge
    $1.20
    c6gn.2xlarge
    $0.50
    c6gd.xlarge
    $0.20
    r7gd.medium
    $0.05
    a1.xlarge
    $0.20
    c7gd.12xlarge
    $0.05

    Vendor refund policy

    no refunds

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (Arm) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes
    1. Rebuilt on the latest CentOS Stream 9 for 64-bit Arm and fully patched at build time.
    2. Hanwei security hardening and EC2 resource/network tuning baseline applied.
    3. Amazon SSM Agent and Amazon Time Sync integrated.
    4. Default login user is ec2-user; direct root login and password authentication are disabled.
    5. Root filesystem is XFS.

    Additional details

    Usage instructions

    SSH to the instance and login as 'ec2-user' using the key specified at launch. Additional information may be found at : https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/AccessingInstancesLinux.html 

    Resources

    Support

    Vendor support

    We provide technical support through our work order system. Before creating a support case, we recommend that you browse our knowledge base (https://support.proimage.cloud/ ). If you need manual help, please visit: https://support.proimage.cloud/support , or contact prosupport@hanweie.com  .

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    25
    In High Performance Computing
    Top
    100
    In Testing

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    1 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    64-bit ARM Architecture Support
    Image targets aarch64 architecture and runs on AWS Graviton instance families.
    SSH Hardening Configuration
    SSH restricted to modern key-exchange and cipher allow-list with key-only authentication, root login disabled, and MaxAuthTries lowered.
    SELinux Enforcement
    SELinux operates in enforcing mode for mandatory access control.
    System Resource Tuning
    Soft open-file limit raised from 1024 to 65536, vm.max_map_count increased from 65530 to 262144, device receive backlog and TCP SYN backlog enlarged, and socket buffer ceilings increased.
    AWS Systems Integration
    Amazon SSM Agent installed and enabled for Session Manager access, chrony configured to Amazon Time Sync service, and cloud-init handles first-boot initialization.
    Minimal Package Installation
    Built using CentOS 10 'Minimal Install' package group containing only essential software required for AWS operation, SSH server functionality, and secure user login.
    Automatic Root Partition Expansion
    Root partition and filesystem automatically expand during boot when instance volume exceeds default 8 GiB size, utilizing GPT (GUID Partition Table) partitioning scheme supporting volumes larger than 2 TiB.
    Enhanced Networking Capability
    Enhanced Networking enabled through ENA (Elastic Network Adapter) providing improved network throughput, reduced latency, and optimized network performance.
    Security Hardening
    SELinux enabled for mandatory access controls and all available security updates included at image release date.
    Cloud Initialization Support
    Cloud-init included enabling automated instance initialization tasks including user configuration, SSH key management, networking setup, and launch-time customization.
    Security Hardening Controls
    SELinux enforcing mode, root SSH login disabled, key-only SSH authentication, reduced SSH surface with X11 forwarding disabled, kernel network hardening via sysctl, audit rules loaded in running kernel, PAM-based account lockout via pam_faillock, password quality enforcement via pam_pwquality, default umask of 027, and login banners configured
    Minimal Image Construction
    Built from official Red Hat Enterprise Linux 8.10 Minimal Install package group, 10GB root volume without LVM, UEFI/GPT boot with XFS root filesystem, and rolling updates to newest 8.x releases
    AWS Integration and Drivers
    Elastic Network Adapter (ENA) driver present and verified, NVMe driver support, cloud-init configured for automatic root partition and filesystem expansion, and AWS CLI preinstalled
    Automated Build and Verification Pipeline
    Reproducible fully automated build pipeline from official distribution ISO, automated assertion suite validating all hardening controls on booted instance before publication, and versioned hardening baseline marker at /etc/rinne-labs-hardening
    Repository and Update Management
    Registered with Red Hat Update Infrastructure (RHUI) for security updates without requiring Red Hat subscription, distribution security updates applied at build time, and continued rebuilds with current security patches

    Contract

     Info
    Standard contract

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.