This product has charges associated with it for hardening, security configuration, and support.
Kong Gateway (OSS) is a cloud-native API gateway and reverse proxy built on OpenResty (NGINX + LuaJIT). Unlike bare Kong AMIs that expose the Admin API on every interface, ship no authentication on the control plane, and require an external database, this Lynxroute build is ready out of the box: DB-less declarative configuration (no Postgres to deploy or operate), the Admin API locked to localhost and reachable only through a TLS + HTTP Basic Auth perimeter, anonymous telemetry disabled, UFW firewall pre-configured, and a CIS Level 1 hardened Ubuntu 24.04 LTS base.
Apache-2.0 license - fully auditable, no vendor lock-in.
This is a repackaged software product wherein additional charges apply for hardening, security configuration, and support.
WHAT IS KONG GATEWAY
Kong Gateway (OSS) is a cloud-native API gateway and reverse proxy built on OpenResty (NGINX + LuaJIT). It routes, secures, and observes API traffic with bundled plugins for key-auth, JWT, ACL, rate-limiting, request and response transformation, CORS, Prometheus metrics, and OpenTelemetry. API consumers connect to the proxy data plane, while operators manage configuration through the Admin API using the deck CLI or a declarative YAML file. This image runs in DB-less mode: configuration lives in a single declarative /etc/kong/kong.yml, so there is no database to deploy, secure, or operate. Apache-2.0 license, no per-API fees, no vendor lock-in. The Enterprise-only Kong Manager web console, RBAC, and OIDC are not part of this OSS build - management is via the Admin API.
WHAT THIS AMI ADDS
Security hardening:
DB-less mode - declarative /etc/kong/kong.yml, no database to deploy or expose
Admin API bound to 127.0.0.1 only; remote management via an Nginx TLS + HTTP Basic Auth perimeter, with a single admin credential generated at first boot
Proxy data plane on ports 8000 (HTTP) and 8443 (HTTPS)
Anonymous usage reporting disabled
UFW firewall - ports 22, 8000, 8443, 443
fail2ban, AppArmor
CVE scan - every image is scanned for vulnerabilities before release
OS hardening (CIS Level 1):
CIS Ubuntu 24.04 LTS Level 1 benchmark applied via ansible-lockdown
CIS Conformance Report at /etc/lynxroute/cis-report.html
CIS Tailored Profile at /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
Highlights
Kong Gateway security baked in: DB-less declarative config (no database to operate), the Admin API locked to localhost behind a TLS + HTTP Basic Auth perimeter, a single admin credential generated at first boot, and anonymous telemetry off - unlike bare Kong AMIs that expose the Admin API on every interface and ship no control-plane authentication.
CIS Level 1 hardened Ubuntu 24.04 LTS: auditd, fail2ban, AppArmor, SSH key-only, IMDSv2 enforced. CVE-scanned before every release. SBOM (CycloneDX) and CIS Conformance Report included.
Cloud-native API gateway on OpenResty: routing, key-auth, JWT, ACL, rate-limiting, request and response transformation, Prometheus and OpenTelemetry - managed via the Admin API and the deck CLI. Apache-2.0 license - fully auditable, no vendor lock-in.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 5 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
You pay by the hour based on the EC2 instance size you run. The five options map to different compute capacities. The t3.small, t3.medium, and t3.large are burstable instances that scale up in size. The m6i.large and m6i.xlarge are general-purpose instances offering steadier performance. Larger instances carry higher hourly rates. You choose the instance that fits your workload, and billing tracks your actual running hours. The software itself is the same hardened API gateway image across all sizes; only the underlying compute differs.
Top-of-mind questions for buyers
What resources do the burstable t3 instances differ from the m6i instances in providing?
The t3.small, t3.medium, and t3.large are burstable instances. They run at a baseline level and spend credits for short bursts of higher performance. The m6i.large and m6i.xlarge give steady, sustained performance without a credit system. Burstable instances suit variable or lighter traffic; m6i instances suit consistent loads.
Am I charged when I stop or pause my instance?
The software meters running hours only. When you stop an instance, hourly software charges stop accruing. You may still pay separate AWS fees for attached storage while the instance is stopped, but those are AWS charges, not this listing's software charge.
Is the API gateway software different depending on which instance size I pick?
No. Every size runs the same hardened, DB-less API gateway image. Each ships CIS Level 1 hardening, CVE scanning, a CycloneDX SBOM, and unique credentials generated at first boot. Only the underlying compute capacity changes with your instance choice, not the software or its included security features.
lynxroute.com
Helpful?
Vendor refund policy
We do not offer refunds for this product. AWS infrastructure charges (EC2, EBS, data transfer) are billed separately by AWS and are not refundable by us.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Kong Gateway 3.9.3
Updated Kong Gateway to 3.9.3
Certbot pre-installed - enable HTTPS with one command: sudo certbot --nginx -d yourdomain.com
Rebuilt on the latest CIS Level 1 hardened Ubuntu 24.04 LTS base
Manage Kong through the Admin API over TLS + HTTP Basic Auth:
curl -k -u admin:<password> https://<PUBLIC_IP>/
Add a Service and Route. Kong runs DB-less, so edit the declarative config and reload:
sudo nano /etc/kong/kong.yml # add a service + route (an example is included)
sudo kong reload
...or push a full configuration remotely with the deck CLI against https://<PUBLIC_IP>/
Send API traffic through the proxy data plane:
http://<PUBLIC_IP>:8000/example-route (HTTP; replace example-route with your configured route path)
https://<PUBLIC_IP>:8443/example-route (HTTPS; replace example-route with your configured route path)
The admin password is generated at first boot and saved to /root/kong-credentials.txt.
This is the OSS gateway in DB-less mode - there is no web console (Kong Manager is an Enterprise feature). Manage Kong via the Admin API (deck CLI) or the declarative /etc/kong/kong.yml file.
The raw Admin API stays bound to 127.0.0.1; the only remote management path is the TLS + HTTP Basic Auth perimeter on port 443.
For a trusted certificate on the perimeter, Certbot is pre-installed:
sudo certbot --nginx -d your.domain.com
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Kong Konnect is the first unified API management platform that is designed for the cloud native era and provides the easiest way to operate Kong Gateway.
Kong Konnect is the unified API management platform delivered as a service that can manage Kong Gateway, Kong AI Gateway, Kong Ingress Controller, and Kong Mesh with a single management console to deliver API configuration, portal, service catalog, and analytics capabilities.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.