CoreNova SSM EKS Admin Bastion AMI (Amazon Linux 2023, x86_64): private Amazon EKS administration bastion for teams replacing public SSH jump hosts. Includes AWS CLI v2, Session Manager Plugin, kubectl version selector, Helm, eksctl, k9s, IAM examples, and AL2023 hardening.
Deploy CoreNova SSM EKS Admin Bastion AMI (Amazon Linux 2023, x86_64) as a private administration host for Amazon EKS.
CoreNova SSM EKS Admin Bastion is a private, SSM-first Amazon EKS administration workstation packaged as an Amazon Machine Image. It gives platform engineers, DevOps teams, MSPs, and startup CTOs a controlled EC2 host for kubectl, Helm, eksctl, and k9s without building or maintaining a public SSH jump box.
This is an administration and bastion AMI, not an EKS worker node image. Use it to operate existing or newly created EKS clusters from a private subnet with IAM and Kubernetes RBAC controlled by the buyer.
What you get
Amazon Linux 2023 hardened base maintained by CoreNova
SSM-first access model with Amazon SSM Agent and Session Manager Plugin
SSH key-only fallback with root login and password authentication disabled
AWS CLI v2 and kubectl multi-version selector for supported EKS minor versions
EKS Access Entry example and least-privilege IAM policy templates
Tool inventory at /etc/corenova/eks-admin-bastion/tool-versions.txt
Quickstart and examples under /opt/corenova/eks
Best for
Private EKS administration from a controlled EC2 instance
Replacing public SSH bastion hosts with Session Manager access
Standardized kubectl and Helm workstation for platform teams
MSP or consultant access host in customer AWS accounts
Security-conscious EKS troubleshooting and cluster inspection
Recommended deployment model
Launch into a private subnet, attach an IAM role with AmazonSSMManagedInstanceCore and your required EKS access policy, and connect with AWS Systems Manager Session Manager. Do not open inbound SSH unless your organization explicitly requires SSH fallback.
Security model
The AMI ships without hardcoded passwords, private keys, AWS credentials, kubeconfigs, or customer data. Buyers control IAM permissions, EKS Access Entries, Kubernetes RBAC, network access, logging retention, and secrets handling in their own AWS accounts.
Architecture and pricing
x86_64. Recommended instance type: t3.small.
Software fee: $0.04/hour for supported EC2 instance types. This product has charges associated with CoreNova packaging, maintenance, documentation, and seller support. AWS infrastructure costs such as EC2, EBS, NAT gateway, VPC endpoints, public IPv4, and data transfer are billed separately by AWS.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay an hourly software fee per running instance, billed by the hour with no upfront commitment. The twelve dimensions map to specific EC2 instance sizes, all x86_64. They span general-purpose burstable types (t3 and t3a families in micro, small, medium, and large sizes), general-purpose fixed-performance types (m6i.large, m7i.large), and compute-optimized types (c6i.large, c7i.large). You choose the size that fits your workload; the hourly rate applies for each hour an instance runs. AWS charges EC2, EBS, and other infrastructure separately. Currently offered only in the us-east-1 region.
Top-of-mind questions for buyers
What does the hourly software fee cover, and what does it not include?
The hourly fee covers the software license for one running instance of this admin bastion AMI. It does not include the underlying AWS infrastructure. You pay AWS separately for EC2, EBS storage, NAT Gateway, VPC endpoints, and data transfer. Those charges appear on your AWS bill, not the software fee.
Am I charged the hourly software fee when the instance is stopped?
The software fee applies per running instance per hour. A fully stopped instance does not accrue the hourly software charge. However, attached EBS storage may still incur AWS infrastructure fees while the instance is stopped. The software license meters only running time.
How do I pick between the twelve instance-size dimensions for billing?
Each dimension maps to one EC2 instance size, and its hourly rate applies for every hour that size runs. You select the size when launching the instance in EC2. The rate does not combine across sizes; you pay only for the size you actually run, per running hour.
www.corenovacloud.com
Helpful?
Vendor refund policy
30-day refund on Marketplace software fees for verified technical issues. AWS infrastructure charges are billed by AWS and are not refundable by the seller.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
CoreNova EKS Admin Bastion AMI (AL2023, x86_64)
Version: v20260709
Initial CoreNova EKS Admin Bastion release.
Baseline:
Amazon Linux 2023 hardened base with current upstream security updates at build time.
Expected SSH settings:
permitrootlogin no
passwordauthentication no
Sensitive data and credentials
The AMI does not include hardcoded passwords, private keys, AWS credentials, kubeconfigs, or customer data. Customer-created keys, kubeconfigs, and Kubernetes secrets remain in the buyer's AWS account.
Encryption
The Marketplace source AMI uses unencrypted EBS snapshots as required for AWS Marketplace AMI ingestion. Buyers can launch or copy the AMI with encrypted EBS volumes according to their own AWS account policy.
CoreNova supports AMI launch, AWS Systems Manager Session Manager access, EKS administration tool checks, Marketplace AMI metadata, and documented hardening behavior. Include AWS Region, AMI ID, EC2 Instance ID, instance type, EKS cluster version, tool output, and steps to reproduce.
Refund: 30-day refund on Marketplace software fees for verified technical issues. AWS infrastructure charges are billed by AWS and are not refundable by the seller.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
CoreNova SSM EKS Admin Bastion AMI (Amazon Linux 2023, Graviton ARM64): private Amazon EKS administration bastion for teams replacing public SSH jump hosts. Includes AWS CLI v2, Session Manager Plugin, kubectl version selector, Helm, eksctl, k9s, IAM examples, and AL2023 hardening.
This product has charges associated with it for Cloud Forge runtime hardening, automation, maintenance, and seller support. CoreNovaLabs Cloud Forge Hardened Database AMI provides a Docker and CloudFormation-ready Amazon Linux runtime for database and stateful workload deployments.
This product has charges associated with it for Cloud Forge runtime hardening, automation, maintenance, and seller support. CoreNovaLabs Cloud Forge Hardened App Runtime provides a Docker and CloudFormation-ready Amazon Linux runtime for self-hosted app deployments.
This product has charges associated with it for CoreNova hardening, maintenance, validation notes, and seller support. Ubuntu 22.04 LTS Hardened AMI provides a hardened Ubuntu 22.04 LTS EC2 baseline with SSH lockdown, audit logging, AIDE, firewall controls, and buyer-side OpenSCAP notes.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.