This product has charges associated with it for image hardening, maintenance, and support. Apache Kafka 4.3 (KRaft, no ZooKeeper) on Amazon Linux 2023 with Amazon Corretto, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, listeners bound to loopback until you configure them, and continuously patched images.
Apache Kafka (Hardened) on Amazon Linux 2023 is a production-ready, security-hardened single-node image of the Apache Kafka event-streaming platform in KRaft mode (no ZooKeeper), maintained and supported by Derek Coleman & Associates Incorporated.
This is repackaged open-source software. Apache Kafka is developed by the Apache Software Foundation and is distributed under the Apache License 2.0. Apache and Apache Kafka are trademarks of the Apache Software Foundation; this listing is not endorsed by or affiliated with the ASF. This product bundles unmodified upstream Apache Kafka (with patched bundled libraries where upstream jars carry known vulnerabilities) on a hardened Amazon Linux 2023 base; the charges associated with this listing are for image hardening, continuous patching, vulnerability scanning, and business-day support - not for the underlying open-source software, which remains free.
Hardening baseline: minimal package footprint, SSH key-only access (password authentication disabled), IMDSv2 enforced, and no exposed default listeners - Kafka ships with no authentication, so the broker binds to 127.0.0.1 and the storage formats itself on first boot; exposing listeners with SASL/TLS to trusted CIDRs is a deliberate customer configuration step. Images are rebuilt, scanned for HIGH and CRITICAL vulnerabilities, and republished on a regular cadence so that new launches start current. The broker is validated at build time with an end-to-end smoke test.
Highlights
Security-hardened at build time: minimal packages, key-only SSH, IMDSv2-only, broker bound to loopback until you configure authenticated listeners.
Continuously patched: rebuilt, vulnerability-scanned, and republished on a regular cadence; vulnerable bundled jars remediated at build.
Production-ready: Kafka 4.3 in KRaft mode (no ZooKeeper); storage auto-formats on first boot; systemd-managed.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour for a running instance, with the rate set by which compute size you launch. The three options — c7i.xlarge, c7i.2xlarge, and c7i.4xlarge — are the same hardened Apache Kafka software on different EC2 instance sizes. They scale by vCPU and memory, so a larger size carries a higher hourly rate. Pick the size that fits your workload; there are no tiers or feature differences between them. Charges accrue only while an instance runs. AWS bills the software fee and your underlying compute, storage, and network separately.
Top-of-mind questions for buyers
What compute resources do the c7i.xlarge, c7i.2xlarge, and c7i.4xlarge sizes each provide?
Each name reflects an EC2 compute-optimized instance size. The c7i.xlarge is the smallest of the three, the c7i.2xlarge is roughly double its vCPU and memory, and the c7i.4xlarge doubles again. You pick the size that matches your Kafka throughput and topic load.
Am I charged when the Kafka instance is stopped or paused?
The software fee meters only while an instance runs. A fully stopped instance accrues no software charge. Stopped instances may still incur AWS storage fees for attached volumes, billed separately by AWS. The software licence counts running time only.
Does the hourly software fee include the underlying AWS compute and storage?
No. The hourly software fee covers the hardened Kafka image only. AWS bills the compute, storage, and network your instance consumes separately under your own AWS account. Both charges appear on your AWS invoice, but they are metered independently.
www.dcassociatesgroup.com
Helpful?
Vendor refund policy
Usage-based hourly billing; charges stop when instances are terminated. Contact support@dcassociatesgroup.com for billing questions.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
[Security] Refreshed image: rebuilt on the latest hardened Amazon Linux 2023 baseline; all OS packages current at build.
Additional details
Usage instructions
Launch from AWS Marketplace (1-Click or EC2 console). Connect via SSH: ssh -i <key> ec2-user@<public-ip>. Kafka runs in KRaft mode and binds to 127.0.0.1:9092; verify locally with: /opt/kafka/bin/kafka-topics.sh --bootstrap-server 127.0.0.1:9092 --list. To serve clients, configure listeners plus SASL/TLS in /opt/kafka/config/server.properties, restart with: sudo systemctl restart kafka, and open port 9092 to trusted CIDRs only. Root login is disabled; use sudo. There are no passwords anywhere in this product.
Support
Vendor support
Support by Derek Coleman & Associates Incorporated. Email: support@dcassociatesgroup.com. Business-day response. Covers image operation, hardening baseline, and launch issues.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This is a repackaged open source software product wherein additional charges apply for technical support. Softwares included: Ubuntu and Apache Web Server
Enterprise-grade Kafka UI and API for deep visibility, precise control, and instant action across your ecosystem. Kpow is secure, vendor-agnostic, and trusted by Fortune 500s for managing Apache Kafka at scale.
Tomcat is an application server designed to execute Java servlets and render web pages that use Java Server page coding. Tomcat acts as a webserver or servlet container.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.