This is a repackaged open source software product wherein additional charges apply for image hardening, maintenance, and support. Apache HTTP Server (httpd) on Amazon Linux 2023, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, firewall pre-configured for HTTP/HTTPS, and continuously patched images.
Apache HTTP Server (Hardened) on Amazon Linux 2023 is a production-ready, security-hardened image of the Apache HTTP Server (httpd), maintained and supported by Derek Coleman & Associates Inc.
This is repackaged open-source software. The Apache HTTP Server is developed by the Apache Software Foundation and is distributed under the Apache License 2.0. Apache and Apache HTTP Server are trademarks of the Apache Software Foundation; this listing is not endorsed by or affiliated with the ASF. This product bundles unmodified upstream Apache HTTP Server on a hardened Amazon Linux 2023 base; the charges associated with this listing are for image hardening, continuous patching, vulnerability scanning, and business-day support - not for the underlying open-source software, which remains free.
Hardening baseline: minimal package footprint, SSH key-only access (password authentication disabled), IMDSv2 enforced, host firewall pre-configured to expose only the web ports, server tokens minimized, and no default credentials anywhere. Images are rebuilt, scanned for HIGH and CRITICAL vulnerabilities, and republished on a regular cadence so that new launches start current. Serve content from /var/www/html, configure under /etc/httpd, and manage the service with systemd: sudo systemctl restart httpd.
Highlights
Production-ready: systemd-managed Apache HTTP Server; serve from /var/www/html, configure under /etc/httpd.
Security-hardened at build time: minimal packages, key-only SSH, IMDSv2-only, firewall enabled with only web ports open.
Continuously patched: rebuilt, vulnerability-scanned, and republished on a regular cadence.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour for the software, based on the EC2 instance size you launch. Three sizes are available: c7i.xlarge (4 vCPU / 8 GiB), c7i.2xlarge (8 vCPU / 16 GiB), and c7i.4xlarge (16 vCPU / 32 GiB). Pricing scales with the compute capacity of the instance, so larger instances carry a higher hourly software rate. There is no subscription and no minimum commitment. Charges stop when you terminate the instance. AWS infrastructure charges are billed separately by AWS.
Top-of-mind questions for buyers
What am I paying the hourly software rate for, since Apache HTTP Server is free open-source?
The hourly charge covers image hardening, continuous patching, vulnerability scanning, and business-day support. The underlying Apache HTTP Server stays free open-source software. You pay for the maintained, security-hardened Amazon Linux 2023 image, not the server software itself.
Am I charged the software rate when my instance is stopped or terminated?
Software charges accrue only while the instance runs. Charges stop when you terminate the instance. There is no subscription and no minimum. A stopped instance may still incur AWS storage fees for its EBS volume, billed separately by AWS.
What AWS resources does one instance create, and which charges come from AWS versus the software rate?
A single instance uses one EC2 instance and one gp3 EBS volume; no other AWS resources are created. AWS bills the compute and storage separately on your cloud invoice. The hourly software rate you see here covers only the hardened image and support.
products.dcassociatesgroup.com
Helpful?
Vendor refund policy
Usage-based hourly billing; charges stop when instances are terminated. Contact support@dcassociatesgroup.com for billing questions.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
[Security] Refreshed image: rebuilt on the latest hardened Amazon Linux 2023 baseline; all OS packages current at build.
Additional details
Usage instructions
Launch from AWS Marketplace (1-Click or EC2 console).
Connect via SSH with your EC2 key pair: ssh -i <key> ec2-user@<public-ip>. Root login is disabled; use sudo.
Serve content from /var/www/html; configuration lives under /etc/httpd. After changes: sudo systemctl restart httpd.
For HTTPS: httpd-firstboot.service generates a per-instance self-signed certificate at first boot (/etc/pki/tls/certs/localhost.crt + /etc/pki/tls/private/localhost.key) so mod_ssl starts; replace both with your own certificate and key in /etc/httpd/conf.d/ssl.conf, then: sudo systemctl restart httpd.
Verify: curl -I http://<public-ip> returns a response, or: sudo systemctl status httpd.
Sensitive data: there are no passwords or secrets anywhere in this product. Logs under /var/log may contain client IPs - treat as personal data.
Backup: snapshot the EBS volume (it contains all configuration and data).
Resources: a single instance uses 1 EC2 instance and 1 gp3 EBS volume; no other AWS resources are created.
Support by Derek Coleman & Associates Incorporated. Email: support@dcassociatesgroup.com. Business-day response. Covers image operation, hardening baseline, and launch issues.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This is a repackaged open source software product wherein additional charges apply for image hardening, maintenance, and support. Traefik reverse proxy on Amazon Linux 2023, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, dashboard and API disabled, runs as a non-root user, and continuously patched images.
This is a repackaged software product wherein additional charges apply for a pre-hardened, SI Core STIG Hardened image and seller support. Wordpress on Amazon Linux 2023 provides a robust environment for hosting your websites with enhanced security and performance. With easy integration into AWS services, Wordpress on Amazon Linux 2023 simplifies deployment while ensuring compliance with industry standards. This AMI comes pre-configured with the latest plugins and security measures, allowing you to focus on content creation rather than server management. Ideal for developers and businesses alike, Wordpress on Amazon Linux 2023 is perfect for scaling applications, managing high traffic, and ensuring uptime. Experience seamless updates and reliable support with Wordpress on Amazon Linux 2023.
This is a repackaged open source software product wherein additional charges apply for image hardening, maintenance, and support. Apache Tomcat 10.1 on Amazon Linux 2023 with Amazon Corretto 21, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, no manager apps or default users, and continuously patched images.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.