Listing Thumbnail

    Composable Agentic Platform (CAP) - RHEL Enterprise Edition

     Info
    Sold by: TomorrowX 
    Deployed on AWS
    The Composable Agentic Platform (CAP) is the TomorrowX Data Mediation™ platform: Programmable Data Agents observe, govern and transform live traffic without changing your systems. Agents operate in the data path between systems, terminating connections at the protocol level and processing requests and responses in flight, so capability is added between systems, not inside them. CAP Console composes solutions from pre engineered, security and performance tested components and deploys them across the agent fleet. Built for enterprise and public sector organisations, CAP enables governed AI adoption, cyber uplift, legacy system extension and interoperability without invasive change, rewrites, centralising data or forced migration, including in highly regulated, secure and air gapped environments.

    Overview

    The Composable Agentic Platform (CAP) is the TomorrowX Data Mediation™ platform, a control architecture that ensures the right data, context and controls participate in every AI, cyber and interoperability workflow. CAP is not an application platform or an embedded rules engine. Programmable Data Agents operate in the data path itself, terminating connections at the protocol level, processing live requests and responses in flight and passing traffic on, all without changes to the systems on either side. Capability is added between systems, not inside them, so organisations can observe, govern, transform, simulate and augment interactions without rewriting, migrating or directly integrating the applications involved.

    CAP Console is the composition and operations environment. Teams assemble solution logic, user experiences and operational workflows from pre engineered, security and performance tested components, reuse proven building blocks, prototype with agility and move proven designs into production across web and multi protocol environments. This reduces delivery effort, shortens development cycles and accelerates deployment.

    Built for enterprise and public sector organisations operating in highly regulated, secure and air gapped environments, CAP enables governed AI adoption, cyber uplift, legacy system extension and interoperability without invasive change, major redevelopment, centralising data or forced migration. Interventions can be proven, changed or removed without making the surrounding estate dependent on an irreversible transformation.

    The Enterprise Edition includes the full TomorrowX library of plug and play functional and programming components, giving teams a repeatable foundation for composing production ready solutions at speed, closer to where systems, controls and operational requirements already exist.

    Highlights

    • Data Mediation™ in the data path: Programmable Data Agents observe, govern and transform live traffic at the protocol level, without changing the systems on either side.
    • Connect AI and cyber capabilities to existing systems without invasive change, application rewrites, centralising data or forced migration, including in regulated, secure and air-gapped environments.
    • Compose web and multi-protocol solutions from pre-engineered, security and performance tested components, and move proven designs into production at speed.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Rhel 10.1 (Coughlan)

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Composable Agentic Platform (CAP) - RHEL Enterprise Edition

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (10)

     Info
    Dimension
    Cost/hour
    t3.large
    Recommended
    $35.675
    t3.xlarge
    $35.675
    t3a.xlarge
    $35.675
    t3a.large
    $35.675
    t3a.medium
    $35.675
    m5.large
    $35.675
    m5.xlarge
    $35.675
    t3.medium
    $35.675
    m6i.large
    $35.675
    m6i.xlarge
    $35.675

    AI Insights

     Info

    Dimensions summary

    You pay by the hour based on the AWS EC2 instance type you run. All ten dimensions bill on the same usage model, so cost scales with how long each instance runs. The choices span general-purpose and compute-balanced instance families in medium, large, and xlarge sizes. Larger sizes give more CPU and memory per hour. You select the instance that matches the compute your Data Mediation workload needs, then pay only for the hours used. No upfront commitment applies under this usage model.

    Top-of-mind questions for buyers

    The t3 and t3a families are burstable general-purpose instances, suited to workloads with variable CPU demand. The m5 and m6i families provide steadier CPU-to-memory balance for consistent compute. Within each family, medium, large, and xlarge sizes scale CPU and memory upward. You match the instance to your Data Mediation workload's steadiness and size.
    Software charges accrue per running instance-hour under this usage model. A fully stopped instance stops accruing hourly software charges. Underlying AWS resources, such as attached storage, may still incur separate AWS fees while the instance is stopped. The software licence meters only running time.
    The runtime deploys inside customer-controlled environments in your data path. Billing still follows the hourly instance model you select on Marketplace. You pay for the EC2 instance-hours the runtime consumes. Retaining control over data, systems, and actions does not change the per-hour metering.
    tomorrowx.com
    Helpful?

    Vendor refund policy

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    This is a feature release of the Composable Agentic Platform (CAP) Console on Red Hat Enterprise Linux 10.1 (Coughlan), delivering enterprise single sign-on across three protocols - hardened SAML 2.0, a new OpenID Connect login option, and a modernised LDAP directory login - together with write-only masking for multi-line credential vault fields, upstream cookie suppression for forwarding agents, and Console fixes. The embedded Jetty 12.1.10 server runtime is unchanged from the previous AMI. Local logon remains the default, so sign-in behaviour is unchanged until an access manager is configured. All existing rulesets, extensions, and TCL scripts continue to work unchanged. This AMI also carries the intervening build 30080 maintenance round (UTF-8 form handling, performance data retrieval, agent window titles, run-time settings layout, headless start) for deployments coming from the previous AMI.

    Enterprise single sign-on:

    • One access manager at a time - The Console authenticates against a single configured access manager: SAML 2.0, OpenID Connect, or LDAP. The configuration file now ships with ready-to-populate SAML and OpenID Connect sections under Authentication.
    • OpenID Connect login (new) - Authorization code flow with PKCE against any OpenID Connect identity provider (Entra ID, Okta, Keycloak, Ping). Configure with OIDCDiscoveryURL or OIDCIssuer, OIDCClientID and OIDCClientSecret; the client secret can be sourced from a Console credential vault entry. User accounts are auto-provisioned from ID token claims, including the standard roles claim (for example Entra ID app roles), with the same user type and role mapping as SAML. Logging out of the Console also ends the identity provider session when the provider advertises an end session endpoint.
    • SAML improvements - A new optional SAMLEntityID property sets a stable SP entity ID, announced as the SAML issuer and enforced as the assertion audience; without it the Console continues to use its /console/SAML URL as the entity ID. Single log-out: logging out of the Console now also ends the identity provider session when the identity provider metadata advertises a SAML single logout endpoint.
    • LDAP login modernised - Reliable group mapping for users that are members of many directory groups, new CAPUserType_ and CAPUserRole_ group names (existing configurations keep working), custom search filters via LDAPSearchFilter with the CAPUSERNAME token, LDAPS trust store scoped to the directory connection with credential vault support for the trust store password, connection timeouts so an unreachable directory fails logons quickly, and hardened logon validation. The user directory password is no longer stored by the Console.
    • Fail-closed option - A new optional RequireAccessManager=true property refuses all logons when the configured access manager plugin fails to load, instead of falling back to local logon.
    • Proxy and hardening - The Console honours the X-Forwarded-Proto header when building and validating sign-on URLs, enabling SAML and OpenID Connect behind TLS-terminating load balancers; the header is restricted to http or https, and the OpenID Connect sign-on redirect is origin-checked against the identity provider discovery document.
    • Provisioning audit - Users auto-provisioned by SAML or OpenID Connect sign-on are recorded in the Console audit log, both on creation and when identity provider attributes change an existing account. The identity provider is authoritative on every login, so out-of-band privilege changes to federated accounts are reverted and audited at the next sign-in.

    Credential vault:

    • Masked multi-line fields - Multi-line text fields can now be masked with the padlock. A masked field never displays its stored value again - the Console shows a placeholder and the value is changed by pasting a replacement - so PEM certificates and private keys are no longer readable from the vault screen.

    Forwarding agents:

    • Strip upstream cookies - The new Strip upstream cookies setting on the Forwarding tab discards all cookies set by upstream hosts instead of relaying them to the browser, so third party services fronted by the proxy cannot plant cookies on the end user's browser. When enabled it supersedes the Clean cookie path setting. Requires the updated Built-in Proxy extension on the agent; older agents ignore the setting and log a warning.

    Console fixes:

    • Rules Editor - Comment rules render correctly again: the comment box honours its configured width with proper word wrap and left-aligned text, and the comment description is edited in a multi-line field. Comments had been drawn as standard rule boxes with the width setting ignored since V11.
    • Policy Dial API - Setting a dial and reverting it shortly after now applies correctly, and reads immediately after a write return the written value. Previously a quick revert within the status poll interval could be silently skipped.
    • Credential vault - The buttons of a newly added vault field no longer raise a script error on mouse events.

    Platform updates:

    • Console at build 30090, RulesBase at build 30090 - The Console application and the shared rules libraries both move to build 30090 for this release. The CAP Agent engine remains at build 30080: engine code is unchanged, and rule execution behaviour is identical.
    • One new dependency - The Nimbus JOSE+JWT library (nimbus-jose-jwt 9.37.4) is added for OpenID Connect token validation; it is recorded in the SBOM and legal notices. All other bundled dependency versions are unchanged from the previous baseline (HttpClient5 5.6.4, HttpCore5 5.4.3, Log4j API 2.25.5, and the rest).
    • RHEL 10.1 + JDK 21 LTS baseline retained - The AMI keeps the Red Hat Enterprise Linux 10.1 (Coughlan) + JDK 21 LTS foundation, the embedded Jetty 12.1.10 server, systemd cap-console service, first-boot cap-init credential initialisation, and pre-installed AWS Systems Manager agent.
    • Reproducible AMI build - The AMI is produced by the same auditable EC2 Image Builder pipeline (triggered from GitHub Actions OIDC) used for prior releases, baked from the identical CI-built Console distribution published to all other channels.

    Upgrade notes:

    • Existing installations can take the same Console content as an in-place update via the TomorrowX update server; the in-place update does not perform a server-level Jetty change and requires no PDA restart. The single sign-on features are dormant until an access manager is configured, so existing local logons are unaffected by the update itself.
    • When enabling an access manager, note that local form logons are refused while it is active. Create and verify any credential vault entries the configuration references (for example the OpenID Connect client secret) BEFORE enabling the access manager, and keep the configuration file accessible for recovery. The Authentication pages under Installation and Configuration in the product documentation walk through the setup for each identity provider, including Entra ID, and the role provisioning pattern.
    • The Strip upstream cookies setting requires the updated Built-in Proxy extension and the build 30090 RulesBaseFactory extension from the update server, applied through the normal extension deployment process. Older Built-in Proxy versions ignore the setting and log a warning naming it, while the rest of the forwarding configuration still deploys.

    For full documentation see: https://docs.tomorrowx.com/cap/vZHo2144m1e79o3WX0RU 

    Additional details

    Usage instructions

    As with all new programming languages, the Hello, World! program generally is a computer program that outputs or displays the message Hello, World. Such a program is very simple in most programming languages and is often used to illustrate the basic syntax of a programming language. It is often the first program written by people learning to code.

    Now step inside and follow these steps to complete your very first composition with the Composable Agentic Platform by TomorrowX. https://docs.tomorrowx.com/cap/vZHo2144m1e79o3WX0RU/how-to/guides/hello-world 

    IMPORTANT: Please read the docs - Essential things to do first In order to manage the default accounts, and change passwords. https://docs.tomorrowx.com/cap/vZHo2144m1e79o3WX0RU/get-started/essential-things-to-do-first 

    First time users can launch the console at http://{Instance IP/DNS}/console e.g. http://12.34.56.78/console  User ID: ec2-user Password: {instance-id}

    Further information can be found in the dedicated AWS User Deployment Guide. https://docs.tomorrowx.com/cap/vZHo2144m1e79o3WX0RU/deploy-and-configure/installation-and-configuration/aws-user-deployment-guide 

    Support

    Vendor support

    Support is delivered through partners, with TomorrowX providing platform support and specialist advisory capability where applicable. Support levels scale by license tier and are confirmed during onboarding. The customer retains control of infrastructure and networking within their AWS environment. For platform support requests, please visit: - https://tomorrowx.dev/get-help/ 

    Watch: How to launch on AWS Marketplace (3m:20s)
    https://player.vimeo.com/video/726599460?h=c6cd92b504 

    Red Hat Enterprise Linux on Amazon EC2 FAQs https://aws.amazon.com/partners/redhat/faqs/  .

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.