This is a repackaged open source software product wherein additional charges apply for image hardening, maintenance, and support. Squid caching proxy on Amazon Linux 2023, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, and continuously patched images.
Squid Proxy (Hardened) on Amazon Linux 2023 is a production-ready, security-hardened image of the Squid caching and forwarding web proxy, maintained and supported by Derek Coleman & Associates Inc.
This is repackaged open-source software. Squid is developed by the Squid Project and is distributed under the GNU General Public License v2 or later. This product bundles unmodified upstream Squid on a hardened Amazon Linux 2023 base; the charges associated with this listing are for image hardening, continuous patching, vulnerability scanning, and business-day support - not for the underlying open-source software, which remains free.
Hardening baseline: minimal package footprint, SSH key-only access (password authentication disabled), IMDSv2 enforced, and a deny-all default proxy policy: the stock /etc/squid/squid.conf allows only localhost and denies every other client (http_access deny all), so although the image firewall and the 1-Click security group pre-open TCP 3128, no remote client can use the proxy until you add ACLs for your networks (for example http_access allow localnet) - a deliberate customer configuration step; narrow the security group's 3128 rule to those client CIDRs when you do, so the instance is never an open proxy. Images are rebuilt, scanned for HIGH and CRITICAL vulnerabilities, and republished on a regular cadence so that new launches start current. Manage the service with systemd: sudo systemctl restart squid.
Highlights
Production-ready: systemd-managed Squid; tune ACLs and cache in /etc/squid/squid.conf.
Security-hardened at build time: minimal packages, key-only SSH, IMDSv2-only, deny-all proxy policy - the stock squid.conf allows only localhost (http_access deny all), so the pre-opened TCP 3128 cannot be used as an open proxy until you add your own ACLs.
Continuously patched: rebuilt, vulnerability-scanned, and republished on a regular cadence.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour for the running instance, with the rate tied to the EC2 instance size you launch. Three sizes are offered: c7i.xlarge (4 vCPU / 8 GiB), c7i.2xlarge (8 vCPU / 16 GiB), and c7i.4xlarge (16 vCPU / 32 GiB). Larger instances carry higher hourly software rates because pricing scales with vCPU count. Charges accrue only while an instance runs and stop when you terminate it. There is no subscription or minimum. AWS infrastructure charges are separate and billed by AWS.
Top-of-mind questions for buyers
What does one hourly unit cover for each c7i instance size?
Each unit is one running EC2 instance of the size you launch, metered per hour. The c7i.xlarge gives 4 vCPU / 8 GiB, c7i.2xlarge gives 8 vCPU / 16 GiB, and c7i.4xlarge gives 16 vCPU / 32 GiB. The hourly software rate scales with vCPU count.
Am I charged when the instance is stopped or terminated?
Software charges accrue only while an instance runs. When you terminate the instance, charges stop. There is no subscription or minimum. Note that stopped instances may still incur AWS storage fees for the attached EBS volume, which AWS bills separately.
What is included in the software charge, and what does AWS bill separately?
The software charge covers image hardening, continuous patching, vulnerability scanning, and business-day support. The underlying open-source Squid software remains free. AWS bills compute, storage, and network usage separately under your own AWS agreement. A single instance uses one EC2 instance and one gp3 EBS volume.
products.dcassociatesgroup.com+1
Helpful?
Vendor refund policy
Usage-based hourly billing; charges stop when instances are terminated. Contact support@dcassociatesgroup.com for billing questions.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
[Security] Refreshed image: rebuilt on the latest hardened Amazon Linux 2023 baseline; all OS packages current at build.
Additional details
Usage instructions
Launch from AWS Marketplace (1-Click or EC2 console).
Connect via SSH with your EC2 key pair: ssh -i <key> ec2-user@<public-ip>. Root login is disabled; use sudo.
Edit /etc/squid/squid.conf to set your ACLs (the stock config allows only localhost and denies all other clients; e.g. uncomment http_access allow localnet), then: sudo systemctl restart squid. The image firewall and the 1-Click security group pre-open TCP 3128 - narrow the security group's 3128 rule to your client CIDRs when you enable access.
Verify: sudo systemctl status squid.
Sensitive data: there are no passwords or secrets anywhere in this product. Logs under /var/log may contain client IPs - treat as personal data.
Backup: snapshot the EBS volume (it contains all configuration and data).
Resources: a single instance uses 1 EC2 instance and 1 gp3 EBS volume; no other AWS resources are created.
Support by Derek Coleman & Associates Incorporated. Email: support@dcassociatesgroup.com. Business-day response. Covers image operation, hardening baseline, and launch issues.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This is a repackaged open source software product wherein additional charges apply for image hardening, maintenance, and support. Traefik reverse proxy on Amazon Linux 2023, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, dashboard and API disabled, runs as a non-root user, and continuously patched images.
This is a repackaged open source software product wherein additional charges apply for image hardening, maintenance, and support. Envoy proxy on Amazon Linux 2023, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, admin interface on localhost only, runs as a non-root user, and continuously patched images.
This product has charges associated with it for providing seller premium support. The Amazon Linux 2023 instance is pre-configured and hardened to the Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG) standard, delivering enhanced security over a baseline image. Benefit from a fully maintained hardened image with regular STIG updates, security patches, and hotfixes, along with limited premium OS support to assist with troubleshooting, optimization, and compliance guidance. This makes it an ideal choice for companies that require a secure, compliance-ready, production-quality OS backed by expert assistance.
This is a repackaged software product wherein additional charges apply for a pre-hardened, SI Core STIG Hardened image and seller support. The Amazon Linux 2023 AMI is designed for developers looking to build and deploy applications on the AWS cloud quickly and securely. This AMI offers improved performance, enhanced security features, and a familiar development environment, making it an ideal choice for various workloads. With the Amazon Linux 2023 AMI, users benefit from seamless integration with AWS services and optimized access to the AWS ecosystem. Whether running microservices, web applications, or containerized workloads, the Amazon Linux 2023 AMI provides the necessary tools for efficient cloud operations.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.