Launch a production-ready SonarQube server on AWS in minutes. Pre-configured with PostgreSQL, Docker Compose, and CI/CD scanner examples for fast code quality and security analysis.
Launch a Self-Hosted SonarQube Server on AWS in Minutes
SonarQube Code Quality and Code Security Server by Code Creator gives your team a ready-to-launch SonarQube Community Build environment on AWS. Analyze source code across multiple languages, identify code quality issues, track technical debt, review security hotspots, and integrate automated code analysis directly into your development workflows - all without building the server environment from scratch.
Why Teams Choose This AMI
In an era where AI-generated code is becoming commonplace, development teams need stronger guardrails for every line of code - whether written by humans or produced by AI assistants. This preconfigured SonarQube environment helps your team begin reviewing code quality, maintainability, security hotspots, and technical debt sooner, reducing the time from purchase to first scan.
How It Works
This AMI is built on Ubuntu 26.04 and uses Docker Compose to orchestrate SonarQube and PostgreSQL 16 containers. On first boot, the automation detects your instance's public IP address, starts the full SonarQube stack, generates a landing page with first-login instructions, and prepares the environment for immediate use. The entire process runs without manual intervention.
Real-World Scenario: Gate Pull Requests With Quality Thresholds
Imagine a development team that wants to enforce code quality standards before any pull request is merged. After launching this AMI, the team connects their GitHub Actions workflow to the SonarQube server using the included starter configuration. Every pull request now triggers an automated scan that checks for bugs, vulnerabilities, code smells, and maintainability issues. If the code fails the quality gate, the merge is blocked until the issues are resolved. This workflow applies equally to GitLab CI and Jenkins pipelines using the provided starter examples.
Built-In Starter Configurations for CI/CD Integration
The AMI includes SonarScanner starter examples so your team can connect projects and pipelines quickly:
Docker-based scanning - Run SonarScanner in a container for flexible, isolated analysis
Maven and Gradle - Integrate scanning into Java build workflows with minimal configuration
GitHub Actions - Add automated code quality gates to your GitHub pull request workflow
GitLab CI - Embed SonarQube analysis into your GitLab pipeline stages
Jenkins - Connect your Jenkins jobs to the SonarQube server for continuous inspection
What You Get on Launch
Public IP landing page - A browser-accessible page with your server status and first-login instructions
First-login guidance - Clear steps for the ubuntu user to access and configure SonarQube
Helper commands - Operational tooling to manage and monitor your SonarQube stack
SonarScanner starter examples - Pre-built configurations for six CI/CD integration paths
Automated first-boot deployment - Public IP detection, stack startup, and landing page generation without manual steps
Designed For
Software development teams looking to add static code analysis to their workflow
DevOps and platform engineers who want a self-hosted SonarQube instance without manual Docker and database setup
Security-focused developers who need to review security hotspots and vulnerabilities in their codebase
Consultants who need to stand up a code audit environment quickly for client engagements
Small organizations that want enterprise-grade code quality tooling on their own infrastructure
Important: Community Build Edition
This AMI deploys the SonarQube Community Build edition. SonarQube Community Build is the open-source foundation of the SonarQube platform. Buyers familiar with SonarQube's commercial editions should note that features such as branch analysis, SAML authentication, and portfolio management are not included in the Community Build. The Community Build supports analysis of the main branch and provides the core rule set for detecting bugs, vulnerabilities, and code smells.
Architecture Overview
The deployment runs as a Docker Compose stack on a single EC2 instance:
Host OS - Ubuntu 26.04 with Docker and Docker Compose
SonarQube container - Serves the web interface and runs code analysis
First-boot automation - Detects public IP, starts services, and generates the landing page
Get Started
A free trial is available so you can evaluate the full environment before committing. Launch the AMI, visit the public IP landing page in your browser, and follow the first-login instructions to begin scanning your first project.
Highlights
Automated first boot deployment - Launch the AMI and the automation handles PostgreSQL setup, Docker Compose orchestration, public IP detection, and SonarQube server startup. Skip the manual work of configuring a self-hosted code analysis stack from scratch. The included landing page displays first login instructions so your team can begin scanning code without reading lengthy setup documentation.
Pre-built CI/CD scanner examples for common workflows - Includes ready-to-use SonarScanner configurations for Docker, Maven, Gradle, GitHub Actions, GitLab CI, and Jenkins. Instead of writing pipeline integration from scratch, your developers can adapt the provided examples to start analyzing code quality, security hotspots, and technical debt in their existing CI/CD pipelines.
Self-hosted code quality and security analysis without vendor lock-in - Run SonarQube Community Build on your own AWS infrastructure with full control over your data and configuration. Detect maintainability, reliability, and vulnerability issues across 30+ programming languages with over 6,000 built-in analysis rules. Helper commands are included for common operational tasks.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 5 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
SonarQube™ : Code Quality and Code Security Server by Code Creator
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour based on the EC2 instance type you run this self-hosted code analysis server on. Each dimension maps to a specific AWS instance size, from small options like t2.nano and t2.micro up to large compute, memory, and storage instances such as c5ad.16xlarge, r4.16xlarge, and m5n.metal. Pricing scales with the compute power you choose — larger instances cost more per hour. You select the instance that fits your workload and team size. Billing is usage-based, so you only pay for the hours you run.
Top-of-mind questions for buyers
What does one hourly unit cover, and what am I actually paying for?
Each hourly unit maps to one running EC2 instance of the type you select. The rate covers the software license for that instance size, billed per hour it runs. If you run several instances, each accrues its own hourly charge. Underlying AWS infrastructure fees are billed separately by AWS.
Am I charged when my instance is stopped or paused?
Software charges apply only while an instance runs. A fully stopped instance stops accruing the hourly software fee. Stopped instances may still incur AWS storage costs for attached volumes, but those are separate AWS charges, not the software license metered by the hour.
How do I pick the right instance type for my team and codebase?
This self-hosted code analysis server supports 40+ languages and scans code in your CI/CD pipeline. Larger codebases and more concurrent analyses need more compute and memory. Choose a smaller instance for light workloads and a larger compute or memory instance for heavy scanning. You can change instance types as needs shift.
docs.sonarsource.com
Helpful?
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
For support inquiries related to this AMI, contact Code Creator by email at info@codecreator.com
For SonarQube application documentation, including configuration guides, plugin references, and language-specific analysis rules, visit the official SonarQube documentation at
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Analyzes source code to identify code quality issues, maintainability concerns, and technical debt tracking across development projects.
Security Vulnerability Detection
Reviews and identifies security hotspots within source code to help teams address potential vulnerabilities and security risks.
CI/CD Integration
Provides preconfigured SonarScanner examples for Docker, Maven, Gradle, GitHub Actions, GitLab CI, and Jenkins to enable automated code analysis in development workflows.
Infrastructure Stack
Built on Ubuntu 26.04 with Docker Compose orchestration, PostgreSQL 16 database, and automated first boot provisioning with public IP detection and configuration.
Multi-Scanner Support
Includes starter SonarScanner configurations for multiple scanning environments including Docker-based scanning, Maven, Gradle, and various CI/CD platforms to accelerate project integration.
Code Quality Analysis
Detects maintainability, reliability, and vulnerability issues across codebases with support for over 30 programming languages and more than 6,000 rules including taint analysis for security.
DevOps Platform Integration
Integrates with DevOps platforms including GitHub, Bitbucket, Azure DevOps, and GitLab for CI/CD pipeline quality gate enforcement.
Cloud Observability
Amazon CloudWatch integration ships SonarQube logs (sonar.log, web.log, ce.log, es.log, access.log), PostgreSQL server logs, and system logs to CloudWatch Logs with CPU, memory, disk, TCP connection, and process metrics published under the SolveDevOps/SonarQube namespace.
Infrastructure Management
AWS Systems Manager integration includes SSM Agent for Session Manager shell access, Run Command, Patch Manager, and Inventory capabilities.
Security Hardening
Key-only SSH authentication, disabled root login, no SSH keys or AWS credentials baked into the image, and per-instance password generation.
Automated Code Analysis
Detects bugs, code smells, and security vulnerabilities in application code through automated analysis.
CI/CD Pipeline Integration
Integrates with modern development workflows and CI/CD pipelines for continuous code inspection across branches and pull requests.
Multi-Linux Distribution Support
Preconfigured and supported on Ubuntu, Debian, Amazon Linux, Rocky Linux, AlmaLinux, Oracle Linux, Fedora, and Red Hat Enterprise Linux.
Pre-configured Environment
Comes preinstalled and configured on Amazon Machine Image with SonarQube service running immediately upon EC2 instance launch.
Quality Gate Enforcement
Enables enforcement of coding standards and quality gates before code merges to maintain application security and reliability standards.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.