This product has charges associated with it for image hardening, maintenance, and support. Apache Tomcat 10.1 on Amazon Linux 2023 with Amazon Corretto 21, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, no manager apps or default users, and continuously patched images.
Apache Tomcat (Hardened) on Amazon Linux 2023 is a production-ready, security-hardened image of the Apache Tomcat servlet container running on Amazon Corretto 21, maintained and supported by Derek Coleman & Associates Incorporated.
This is repackaged open-source software. Apache Tomcat is developed by the Apache Software Foundation and is distributed under the Apache License 2.0. Apache and Apache Tomcat are trademarks of the Apache Software Foundation; this listing is not endorsed by or affiliated with the ASF. This product bundles unmodified upstream Apache Tomcat on a hardened Amazon Linux 2023 base; the charges associated with this listing are for image hardening, continuous patching, vulnerability scanning, and business-day support - not for the underlying open-source software, which remains free.
Hardening baseline: minimal package footprint, SSH key-only access (password authentication disabled), IMDSv2 enforced, and no default credentials anywhere - the manager, host-manager, docs, and examples webapps are removed, no Tomcat users are enabled, and the server version banner is suppressed. Images are rebuilt, scanned for HIGH and CRITICAL vulnerabilities, and republished on a regular cadence so that new launches start current. Deploy applications under /opt/tomcat/webapps and manage the service with systemd: sudo systemctl restart tomcat.
Highlights
Security-hardened at build time: minimal packages, key-only SSH, IMDSv2-only, manager/example apps removed, no enabled Tomcat users, version banner suppressed.
Continuously patched: rebuilt, vulnerability-scanned, and republished on a regular cadence.
Production-ready: systemd-managed Tomcat 10.1 on Amazon Corretto 21; deploy WARs under /opt/tomcat/webapps.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour based on the compute instance size you run. The three options map to different EC2 instance types: c7i.xlarge, c7i.2xlarge, and c7i.4xlarge. These differ in vCPU and memory capacity, so cost scales with the instance you choose. Software fees are metered per hour by AWS and appear on your existing cloud bill. There is no upfront commitment. You start paying when the instance runs and stop when you stop it. Pick the instance size that fits your workload's compute needs.
Top-of-mind questions for buyers
What determines the difference in cost between the three c7i instance options?
The software fee is metered per vCPU per hour. Each instance size carries a different vCPU count, so the c7i.xlarge, c7i.2xlarge, and c7i.4xlarge accrue different hourly rates. The instance you choose maps directly to the compute capacity you get and the hourly charge you pay.
Am I charged when the instance is stopped or paused?
Software fees meter running time only. When you stop the instance, the hourly software charge stops. A stopped instance may still incur underlying AWS storage fees for its attached volumes, but the software license does not accrue while the instance is not running.
What do I get with this image beyond the base Apache Tomcat software?
You get a hardened Amazon Machine Image built on Amazon Linux 2023. It ships with no default credentials and is aligned to CIS benchmarks. The image is rebuilt monthly against current security advisories. It deploys into your own AWS account under your IAM, VPC, and billing controls.
www.dcassociatesgroup.com+2
Helpful?
Vendor refund policy
Usage-based hourly billing; charges stop when instances are terminated. Contact support@dcassociatesgroup.com for billing questions.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
[Security] Refreshed image: rebuilt on the latest hardened Amazon Linux 2023 baseline; all OS packages current at build.
Additional details
Usage instructions
Launch from AWS Marketplace (1-Click or EC2 console). Connect via SSH: ssh -i <key> ec2-user@<public-ip>. Tomcat serves on port 8080; deploy applications by placing WAR files under /opt/tomcat/webapps, then: sudo systemctl restart tomcat. The manager and host-manager apps are removed by design; administer via SSH. Root login is disabled; use sudo. There are no passwords anywhere in this product.
Support
Vendor support
Support by Derek Coleman & Associates Incorporated. Email: support@dcassociatesgroup.com. Business-day response. Covers image operation, hardening baseline, and launch issues.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This is a repackaged open source software product wherein additional charges apply for technical support. Softwares included: Ubuntu and Apache Web Server
Bansir offers this software product repackaged where additional charges apply for technical support provided by Bansir Cloud email support@bansircloud.com.
Enterprise-grade Kafka UI and API for deep visibility, precise control, and instant action across your ecosystem. Kpow is secure, vendor-agnostic, and trusted by Fortune 500s for managing Apache Kafka at scale.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.