CoreNova SSM EKS Admin Bastion AMI (Amazon Linux 2023, Graviton ARM64): private Amazon EKS administration bastion for teams replacing public SSH jump hosts. Includes AWS CLI v2, Session Manager Plugin, kubectl version selector, Helm, eksctl, k9s, IAM examples, and AL2023 hardening.
Deploy CoreNova SSM EKS Admin Bastion AMI (Amazon Linux 2023, Graviton ARM64) as a private administration host for Amazon EKS.
CoreNova SSM EKS Admin Bastion is a private, SSM-first Amazon EKS administration workstation packaged as an Amazon Machine Image. It gives platform engineers, DevOps teams, MSPs, and startup CTOs a controlled EC2 host for kubectl, Helm, eksctl, and k9s without building or maintaining a public SSH jump box.
This is an administration and bastion AMI, not an EKS worker node image. Use it to operate existing or newly created EKS clusters from a private subnet with IAM and Kubernetes RBAC controlled by the buyer.
What you get
Amazon Linux 2023 hardened base maintained by CoreNova
SSM-first access model with Amazon SSM Agent and Session Manager Plugin
SSH key-only fallback with root login and password authentication disabled
AWS CLI v2 and kubectl multi-version selector for supported EKS minor versions
EKS Access Entry example and least-privilege IAM policy templates
Tool inventory at /etc/corenova/eks-admin-bastion/tool-versions.txt
Quickstart and examples under /opt/corenova/eks
Best for
Private EKS administration from a controlled EC2 instance
Replacing public SSH bastion hosts with Session Manager access
Standardized kubectl and Helm workstation for platform teams
MSP or consultant access host in customer AWS accounts
Security-conscious EKS troubleshooting and cluster inspection
Recommended deployment model
Launch into a private subnet, attach an IAM role with AmazonSSMManagedInstanceCore and your required EKS access policy, and connect with AWS Systems Manager Session Manager. Do not open inbound SSH unless your organization explicitly requires SSH fallback.
Security model
The AMI ships without hardcoded passwords, private keys, AWS credentials, kubeconfigs, or customer data. Buyers control IAM permissions, EKS Access Entries, Kubernetes RBAC, network access, logging retention, and secrets handling in their own AWS accounts.
Software fee: $0.04/hour for supported EC2 instance types. This product has charges associated with CoreNova packaging, maintenance, documentation, and seller support. AWS infrastructure costs such as EC2, EBS, NAT gateway, VPC endpoints, public IPv4, and data transfer are billed separately by AWS.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay an hourly software fee for each running instance, billed by the hour with no upfront commitment. The 17 dimensions all use ARM64 Graviton instance types, so you pick the size that fits your workload. They fall into three families: t4g burstable sizes (micro through xlarge), m6g and m7g general-purpose sizes (medium through xlarge), and c6g and c7g compute-focused sizes (medium through xlarge). Larger sizes carry higher hourly rates. AWS charges EC2, storage, and network infrastructure separately from this software fee.
Top-of-mind questions for buyers
What does the hourly software fee cover, and what does it exclude?
The hourly fee covers only the pre-configured management host software: Amazon Linux 2023 with pre-installed kubectl, Helm, eksctl, and k9s. AWS bills EC2 compute, EBS storage, NAT Gateway, VPC Endpoint, and network transfer separately. You also manage IAM permissions, EKS access, and patching yourself.
Am I charged the software fee when the instance is stopped?
The software fee applies per running instance per hour. A stopped instance does not accrue the hourly software fee. Stopped instances may still incur AWS storage charges for the attached EBS volume, which AWS bills separately from this listing.
How do I choose between the t4g, m-series, and c-series instance sizes?
Each dimension bills the same hourly fee structure but maps to a different ARM64 Graviton instance type. The t4g sizes are burstable, m6g and m7g are general-purpose, and c6g and c7g are compute-focused. Pick the size that matches your workload; the hourly rate scales with size.
www.corenovacloud.com
Helpful?
Vendor refund policy
30-day refund on Marketplace software fees for verified technical issues. AWS infrastructure charges are billed by AWS and are not refundable by the seller.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
CoreNova EKS Admin Bastion AMI (AL2023, Graviton ARM64)
Version: v20260709
Initial CoreNova EKS Admin Bastion release.
Baseline:
Amazon Linux 2023 hardened base with current upstream security updates at build time.
Expected SSH settings:
permitrootlogin no
passwordauthentication no
Sensitive data and credentials
The AMI does not include hardcoded passwords, private keys, AWS credentials, kubeconfigs, or customer data. Customer-created keys, kubeconfigs, and Kubernetes secrets remain in the buyer's AWS account.
Encryption
The Marketplace source AMI uses unencrypted EBS snapshots as required for AWS Marketplace AMI ingestion. Buyers can launch or copy the AMI with encrypted EBS volumes according to their own AWS account policy.
CoreNova supports AMI launch, AWS Systems Manager Session Manager access, EKS administration tool checks, Marketplace AMI metadata, and documented hardening behavior. Include AWS Region, AMI ID, EC2 Instance ID, instance type, EKS cluster version, tool output, and steps to reproduce.
Refund: 30-day refund on Marketplace software fees for verified technical issues. AWS infrastructure charges are billed by AWS and are not refundable by the seller.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
CoreNova SSM EKS Admin Bastion AMI (Amazon Linux 2023, x86_64): private Amazon EKS administration bastion for teams replacing public SSH jump hosts. Includes AWS CLI v2, Session Manager Plugin, kubectl version selector, Helm, eksctl, k9s, IAM examples, and AL2023 hardening.
This product has charges associated with it for Cloud Forge runtime hardening, automation, maintenance, and seller support. CoreNovaLabs Cloud Forge Hardened Database AMI provides a Docker and CloudFormation-ready Amazon Linux runtime for database and stateful workload deployments.
This product has charges associated with it for Cloud Forge runtime hardening, automation, maintenance, and seller support. CoreNovaLabs Cloud Forge Hardened App Runtime provides a Docker and CloudFormation-ready Amazon Linux runtime for self-hosted app deployments.
This product has charges associated with it for CoreNova hardening, maintenance, validation notes, and seller support. Ubuntu 22.04 LTS Hardened AMI provides a hardened Ubuntu 22.04 LTS EC2 baseline with SSH lockdown, audit logging, AIDE, firewall controls, and buyer-side OpenSCAP notes.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.