This is a repackaged open source software product wherein additional charges apply for a pre-hardened SSH jump host with fail2ban brute-force protection, an AIDE file-integrity baseline initialised at first boot, Active Directory join tooling, Amazon CloudWatch log/metric integration, AWS Systems Manager access, and vendor support.
A bastion (jump) host is the single, audited entry point into a private network: administrators SSH to it and hop onward to servers that have no public exposure. This image is a minimal, pre-hardened jump host rather than a bare server image: intrusion prevention and file-integrity monitoring are installed and switched on, directory-integration tooling is present, and the host's own logs are wired into CloudWatch so its activity is visible outside the box.
What you get out of the box
CIS aligned base OS hardening with an opinionated sshd configuration: key only authentication, root login disabled, modern ciphers and MACs only, strict forwarding controls
fail2ban tuned for SSH with sensible ban policies; UFW allowing only SSH
Login banners for legal notice requirements, editable for your jurisdiction
No listening services except SSH: no web panel, no agents, minimal attack surface by design
Common use cases
Single audited door: administrators reach private EC2, RDS and container hosts through one logged channel
Contractor access: time boxed accounts with expiry, MFA and full session records
Compliance evidence: session logs and access records in your S3 bucket(optional), in formats auditors accept
Database tunnelling: controlled port forwarding to RDS and ElastiCache without exposing endpoints
MSP operations: one bastion per client VPC, deployed identically from this AMI
Usage notes
To activate CloudWatch and Session Manager, attach an IAM instance role with the AWS-managed policies CloudWatchAgentServerPolicy and AmazonSSMManagedInstanceCore. No AWS credentials are stored on the image.
Restrict inbound TCP 22 to your administrative IP ranges in the security group, or rely on Session Manager and close port 22 entirely. Use SSH agent forwarding or ProxyJump (ssh -J) to reach internal hosts. fail2ban configuration: /etc/fail2ban/jail.local; AIDE: /etc/aide/aide.conf and /var/lib/aide/aide.db; AD join: realm join .
Bastions are light. t3.micro suits most teams; t3.small when session recording is enabled with many concurrent users.
Highlights
Purpose-built SSH jump host: fail2ban with an sshd jail (5 failures / 10 minutes / 10-minute ban) plus AIDE file-integrity monitoring whose baseline database is generated on your instance at first boot, so the integrity reference reflects your deployment, not the build.
Enterprise access tooling installed and ready to configure: sssd, realmd, adcli, Kerberos and Samba client libraries for joining the host to Active Directory, ntpd-rs time sync, and an SSH-hardened base (key-only authentication, root login disabled, no baked-in keys or secrets).
Built-in observability and access: the Amazon CloudWatch agent ships fail2ban.log, the AIDE report, syslog and auth.log (every SSH login and ban is visible in CloudWatch) and publishes host metrics under CloudSOE/bastion-host; Amazon SSM Agent enables Session Manager as a keyless alternative path; a support file identifies the exact build; vendor support from CloudSOE.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for the software running on your chosen Amazon EC2 instance. Every dimension here is the same Bastion Host image; they differ only by the EC2 instance type you select. Smaller burstable t3 and t3a sizes suit light SSH jump-server use. The memory-optimized r5 and r6 families, up to bare-metal and large multi-xlarge sizes, give more CPU and memory. Your hourly rate scales with the instance size you pick. You start and stop instances as needed, and charges flow through your existing AWS account on one invoice.
Top-of-mind questions for buyers
What does the hourly rate cover, and what does it exclude?
The hourly rate covers the Bastion Host software image running on your chosen instance. It does not include the underlying Amazon EC2 compute charge, which AWS bills separately. Both appear on your AWS invoice. Storage and data transfer are also billed by AWS on top.
Am I charged the software rate when the instance is stopped?
The software rate meters running hours only. A fully stopped instance accrues no hourly software charge. You still pay AWS for attached storage while the instance is stopped. Start and stop the instance as needed to control software hours.
How do I choose which instance type to run this on?
Every dimension is the same hardened SSH jump-server image, so choose based on CPU and memory needs. Burstable t3 and t3a sizes fit light jump-server traffic. The r5 and r6 memory-optimized families, up to bare-metal sizes, serve heavier concurrent SSH use. Your hourly rate scales with the size picked.
cloudsoe.com+1
Helpful?
Vendor refund policy
Cancel Anytime
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Includes;
Latest OS patches
Additional details
Usage instructions
Quick Start:
SSH in as ubuntu and use this hardened host to jump to servers that are not exposed to the internet.
fail2ban and AIDE intrusion detection are preconfigured.
Restrict port 22 to your admin IP ranges in the security group.
Support
Vendor support
Vendor support for this AMI is provided by CloudSOE. To reach the support team, email support@cloudsoe.com with a description of your issue.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This is a repackaged open-source software product, with additional charges for a pre-hardened SSH jump host with fail2ban intrusion blocking, AIDE integrity checking, Active Directory/SSSD join tooling, Amazon CloudWatch log and metric shipping, the AWS Systems Manager agent, and vendor support.
This product has charges associated with it for seller support. Fail2Ban is a security tool that helps protect servers from brute force attacks by monitoring log files and banning IP addresses that exhibit malicious behavior.
Browser based remote access tool that provides easy access to hosts in all your VPCs, across accounts and regions. Windows desktops and Linux hosts are supported. No client software needed, a modern browser is all you need.
This is a repackaged open source software product wherein additional charges apply for seller hardening and maintenance. Oracle Linux 10 Hardened AMI with SELinux, SSH hardening, fail2ban, CloudWatch Agent, AIDE, chrony, SSM Agent and AWS CLI v2.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.