This is a repackaged open source software product wherein additional charges apply for pre-installed Amazon CloudWatch and AWS Systems Manager agents configured to the UniFi controller and MongoDB logs, kernel and PAM tuning for high client counts, a hardened image, and vendor support.
A ready-to-run UniFi Network Application controller built by SolveDevOps with the surrounding services pre-installed and tuned, plus Amazon CloudWatch and AWS Systems Manager agents already configured so your controller is observable and manageable from the moment you launch.
This AMI deploys the UniFi Network Application from the official Ubiquiti repository on Amazon EC2, giving you a centralized interface for deploying access points, monitoring network traffic, and controlling user access across all your sites - without maintaining on-premises hardware.
What Is Included
UniFi Network Application from the official Ubiquiti repository with OpenJDK and MongoDB pre-installed and enabled
Kernel and PAM tuning for busy controllers: fs.file-max and per-user nofile/nproc limits raised to 65,535 via sysctl and pam_limits, supporting large device fleets
Amazon CloudWatch integration: CloudWatch Agent pre-configured to ship /var/log/unifi/server.log, /var/log/unifi/mongod.log, /var/log/mongodb/mongod.log, /var/log/syslog, and /var/log/auth.log to CloudWatch Logs (groups /solvedevops/unifi/*, 30-day retention) and publish CPU, memory, disk, TCP, and process metrics under the SolveDevOps/UniFi namespace
AWS Systems Manager integration: SSM Agent installed and enabled for Session Manager shell access, Run Command, and Patch Manager - without opening SSH ports
Operational quick-start: Message of the day displays the portal URL, log locations, and CloudWatch details on first login
Security Hardening
This AMI is built with security as a priority for network management workloads:
Key-based SSH only - password authentication is disabled
No baked-in credentials - build-time SSH keys are removed and cloud-init instance state is scrubbed before publishing
No embedded AWS credentials - both the CloudWatch Agent and SSM Agent activate automatically using your IAM instance role
You control setup from the start - the UniFi controller is configured on first login at https://:8443
Full root access provided so you can apply your own additional hardening policies
Why Deploy Your UniFi Network Server on AWS
Rapid deployment: The UniFi Network Application, MongoDB 7, and Java 17 are pre-installed and services are enabled. Launch the AMI, attach your IAM role, and access the controller UI - no manual installation or dependency management required.
Scalability: Scale your EC2 instance type up or down to match your network size without investing in additional physical hardware.
Global reach, local speed: Deploy in any AWS Region to minimize latency between your controller and remote sites, ensuring fast and reliable network management for distributed teams.
Built-in observability: Amazon CloudWatch captures UniFi server logs, MongoDB logs, system logs, and host-level metrics automatically, giving you centralized monitoring without additional tooling.
Secure remote management: AWS Systems Manager Session Manager provides shell access without exposing SSH ports to the internet.
Prerequisites and Usage Notes
Attach an IAM instance role with CloudWatchAgentServerPolicy and AmazonSSMManagedInstanceCore policies
Open the following ports in your security group as needed: TCP 8443 (web UI), TCP 8080 (device inform), UDP 3478 (STUN), and UDP 10001 (discovery)
UniFi data and config are stored under /usr/lib/unifi/data; logs are under /var/log/unifi
Hosting your UniFi Network Server on AWS is well suited for businesses experiencing growth, organizations needing robust security for network management, cost-conscious teams replacing on-premises controllers, and companies with a global workforce managing multiple sites remotely.
Get Started Today
Transform how you manage your UniFi network. Click Subscribe now to launch your pre-configured, hardened UniFi Network Server on AWS.
Disclaimer: All product and company names are trademarks or registered trademarks of their respective holders. Their use does not imply any affiliation with or endorsement by them. This is an unofficial image provided by SolveDevOps.
Highlights
Production-ready UniFi Network Application with MongoDB and OpenJDK pre-installed and enabled. Kernel and PAM tuning raises file-descriptor and process limits to 65535, supporting large device fleets without manual sysctl or pam_limits configuration. The controller is accessible on first boot at https://<ip>:8443 with no baked-in credentials - you complete setup on your first login.
Built-in AWS observability and management from first boot. Amazon CloudWatch Agent ships UniFi server logs, MongoDB logs, syslog, and auth logs to CloudWatch Logs with 30-day retention, plus CPU, memory, disk, and TCP metrics under the SolveDevOps/UniFi namespace. AWS Systems Manager Agent enables Session Manager shell access, Run Command, and Patch Manager without opening SSH ports.
Security-hardened image with key-based SSH only, build-time SSH keys removed, and cloud-init instance state scrubbed. No AWS credentials or secrets are baked into the image. Attach an IAM role with CloudWatchAgentServerPolicy and AmazonSSMManagedInstanceCore and both agents activate automatically. Open TCP 8443, 8080, UDP 3478, and UDP 10001 in your security group to get started.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour based on the EC2 instance type you launch. The 22 dimensions are not feature tiers. Each one maps to a different instance size and family, such as general-purpose (t2, t3, t3a, m1, m2, m3), compute-optimized (c4), and memory-optimized (r5, r5a, r5d, r5n, r5dn). Larger instances (medium, large, xlarge, 2xlarge) carry more CPU and memory, so their hourly rate rises accordingly. You pick the instance that fits your workload and pay only for the hours you run it.
Top-of-mind questions for buyers
What exactly am I paying for with each hourly instance rate?
You pay for a pre-built machine image running the UniFi Network Server software on the EC2 instance type you select. The rate covers software use per running hour. Each instance size carries a set amount of CPU and memory, and the hourly charge reflects that resource allocation.
Am I charged the hourly rate when the instance is stopped?
The software charge meters running time only. A fully stopped instance does not accrue the hourly software fee. You may still pay underlying AWS storage costs for the attached volumes and the machine image while the instance is stopped. Running time resumes charges when you start it again.
If I outgrow my instance, how do I move to a size with more resources?
You launch the machine image on a different instance type from the pricing table. Switching to a size with more CPU and memory changes your hourly rate to that instance's rate. The change is manual, not automatic. You pick the instance that matches your current workload and pay its hourly rate while it runs.
solvedevops.com
Helpful?
Vendor refund policy
Cancel Anytime
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Updates to the latest Security Patches for Unifi-Network-Server and Ubuntu 22.04
Additional details
Usage instructions
Quick Start: It has never been this easy to deploy Unifi Server on AWS;
Provision a VM with the right capacity for your needs.
NOTE: Instance takes about 5mins to bootstrap.
SolveDevOps provides vendor support for the UniFi Network Server AMI. For deployment assistance, configuration questions, or troubleshooting, contact us by email at support@solvedevops.com.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This is a repackaged software product wherein additional charges apply for the pre-installed, checksum-verified UniFi OS Server console with its podman runtime, Amazon CloudWatch log/metric shipping and AWS Systems Manager integration, security-hardened image preparation, and CloudSOE vendor support.
Finance-First FinOps consulting for startups, nonprofit and SMBs, replaces manual AWS cost tracking with AI powered cloud financial insights aligned to your existing financial operations.
This is a repackaged software product wherein additional charges apply for the pre-installed and system-tuned UniFi Network controller stack (Java 21, MongoDB 8.0), Amazon CloudWatch log/metric shipping and AWS Systems Manager integration, security-hardened image preparation, and CloudSOE vendor support.
This is a repackaged open source software product wherein additional charges apply for the pre-configured fail2ban SSH and SIP brute-force protection, the Kamailio file log for CloudWatch shipping, Amazon CloudWatch log/metric shipping, AWS Systems Manager integration, security hardening, and vendor support.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.