This is a repackaged open source software product wherein additional charges apply for security hardening, optimization, and EC2 baseline validation provided by Hanwei. SELinux is enforcing, SSH is hardened and key-only, auditd is active, and kernel and resource limits are tuned for EC2. The root volume is LVM-managed for flexible resizing.
Charges for this image cover the security hardening, optimization, and pre-integration work Hanwei performs on top of the upstream CentOS Stream project. No application software is added. This image provides a minimal, EC2-ready CentOS Stream 9 base that is patched to the build date and configured to a consistent hardening and tuning profile, so instances launch ready for use without a further baseline pass.
What Hanwei Adds to Upstream CentOS Stream 9
LVM root volume: The root filesystem is on LVM, so the volume can be extended online after the EBS volume is grown.
Hardening beyond distribution defaults: SSH is restricted to a modern key-exchange, cipher and MAC allow-list, root login and password authentication are disabled, MaxAuthTries is lowered, auditd ships with an expanded rule set, and kernel network parameters are set for a hardened posture.
A uniform tuning baseline: The soft open-file limit is raised from 1024 to 65536 (hard limit 524288), vm.max_map_count is raised from 65530 to 262144, the device receive backlog and TCP SYN backlog are enlarged, socket buffer ceilings are increased, tcp_slow_start_after_idle is disabled, and journald is capped at 500 MB. The profile raises ceilings only and does not alter protocol semantics or application behaviour.
AWS operational integration: The Amazon SSM Agent is installed and enabled, and chrony is pointed at the Amazon Time Sync service at 169.254.169.123.
Build dependencies preinstalled: gcc, make, pkgconf and openssl-devel are present, so software can be compiled on the instance without adding a toolchain.
Pinned patch level and reproducible build: Packages are updated to the build date and the image is produced by a reproducible build that is validated on EC2 before release.
Access and Security Posture
SELinux is in enforcing mode.
The default login is the ec2-user account over SSH using key-based authentication.
Direct root login over SSH is disabled and password authentication is turned off.
No application credentials or SSH keys are baked into the image; host keys are generated on first boot.
Operational Impact on EC2
The root volume is LVM-managed and can be extended online after the EBS volume is grown.
The Amazon SSM Agent allows shell access through Session Manager without opening inbound SSH.
Time is synchronized through the Amazon Time Sync service reached at the link-local address.
cloud-init handles first-boot initialization: hostname, user data, and the login SSH key.
The patch level is fixed at build time, so launches from this version are reproducible.
Where This Image Fits
A general-purpose CentOS Stream 9 base for services, application hosts and build agents.
Container and CI hosts, with gcc, make, pkgconf and openssl-devel already present.
Fleets managed through cloud-init and AWS Systems Manager.
Workloads that need flexible root-volume sizing through LVM.
About CentOS Stream 9
CentOS Stream 9 is the continuously delivered distribution that tracks the next Red Hat Enterprise Linux 9 minor release, providing a current, RHEL-compatible userland and kernel.
Highlights
WHAT IS PACKAGED - A minimal CentOS Stream 9 image for x86-64 on an LVM root volume, patched to the build date, with gcc, make, pkgconf and openssl-devel preinstalled so no build toolchain has to be added.
HOW THE BASELINE IS HARDENED AND TUNED - SSH uses a modern algorithm allow-list with key-only login and root login disabled, auditd is active and SELinux is enforcing; the soft open-file limit goes from 1024 to 65536, vm.max_map_count is raised from 65530 to 262144, and socket backlogs and buffers are enlarged without changing protocol behaviour.
HOW IT FITS AWS OPERATIONS - The Amazon SSM Agent enables Session Manager access, chrony uses the Amazon Time Sync service, cloud-init handles first-boot setup, and the LVM root volume can be extended online.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for this hardened CentOS Stream 9 image, billed only while your instance runs. Each dimension maps to one Amazon EC2 instance type, so your rate follows the instance you choose. Options span general-purpose, compute-optimized, memory-optimized, storage-optimized, accelerated-computing, and high-performance-computing families, plus bare-metal and high-memory sizes. Larger instances with more CPU, memory, or GPU resources carry higher hourly rates. Pick the instance that fits your workload; there are no tiers or upfront commitments. The software runs on many cloud platforms, but these hourly rates apply to EC2 deployment.
Top-of-mind questions for buyers
What do I get for the hourly rate on each instance dimension?
Each rate covers the hardened CentOS Stream 9 Minimal image with LVM running on one Amazon EC2 instance of that type. You pay the software rate plus the underlying EC2 charge for the CPU, memory, storage, and any GPU that instance provides.
Am I charged when my instance is stopped or powered off?
Hourly software charges accrue only while the instance runs. A stopped or powered-off instance stops accruing the software rate. Attached storage may still incur separate AWS storage fees, but the software meters running hours only.
How does my bill change if I move to a larger instance size?
Your rate follows the instance you launch. Switching to a size with more CPU, memory, or GPU raises the hourly software charge. There are no tiers or upfront commitments, so the change applies immediately when you run the new instance type.
www.proimage.cloud
Helpful?
Vendor refund policy
no refunds
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Rebuilt on the latest CentOS Stream 9 and fully patched at build time.
Hanwei security hardening and EC2 resource/network tuning baseline applied.
Amazon SSM Agent and Amazon Time Sync integrated.
Default login user is ec2-user; direct root login and password authentication are disabled.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This is a repackaged open source software product wherein additional charges apply for baseline security hardening, kernel performance tuning, weekly automated patch integrations, versatile storage support (Standard & LVM), and pre-integrated AWS cloud utilities.
This is a repackaged open source software product wherein additional charges apply for baseline security hardening, kernel performance tuning, weekly automated patch integrations, versatile storage support (Standard & LVM), and pre-integrated AWS cloud utilities.
This is a repackaged open source software product wherein additional charges apply for baseline security hardening, kernel performance tuning, weekly automated patch integrations, versatile storage support (Standard & LVM), and pre-integrated AWS cloud utilities.
CentOS Stream 9 Minimal with essential utilities. Lightweight enterprise Linux with kernel 5.14, net-tools, zip, wget, vim pre-installed. SSH hardened, SELinux enforcing, auto-updates enabled. Long-term support until 2027. Perfect base for building custom server images or running containerized workloads on AWS.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.