Launch AlmaLinux 9 with STIG-aligned partitions applied at install - a layout that cannot be retrofitted after launch, avoiding costly rebuilds when auditors flag disk-layout findings. StigReady Base adds EC2 hardening (v0.1.0), SBOM and CVE metadata per build, and Nitro boot verification.
Why StigReady Base for AlmaLinux 9:
STIG-required disk partition layouts must be in place at install time. Standard and many CIS-hardened AMIs lack that structure, leaving permanent findings on your PoA&M or forcing a full rebuild. StigReady Base delivers the layout and cloud baseline on official media so instances are ready for your scanning workflow.
Who this is for:
Platform and DevSecOps teams building regulated workloads on AWS - use this AMI as a golden image foundation before your own profiles or a scored StigReady Applied listing.
What you get (StigReady Base tier):
Separate mounts for /home, /tmp, /var, /var/log, /var/log/audit, /var/tmp (applied at install; not retrofittable after launch)
EC2 cloud baseline: IMDSv2 required, no pre-installed SSH authorized_keys, PermitRootLogin and password SSH disabled, host keys regenerated on first boot
Built from official OS install media; patched at build time
Boot-verified on real AWS EC2 Nitro before release
Per-version SBOM and CVE scan metadata (public catalog; see Support)
Not a fully remediated DISA STIG or CIS score - see StigReady Applied for OpenSCAP-scored remediation
How this differs:
Standard marketplace AMIs ship without STIG-aligned partitions. Post-launch STIG remediation cannot fix disk layout. StigReady Base addresses layout and EC2 hardening at the image; StigReady Applied adds scored ansible-lockdown remediation.
Getting started:
Subscribe and launch on a Nitro instance with your SSH key.
Connect as ec2-user; restrict security group TCP/22 to trusted IPs.