This product has charges associated with it for hardening, security configuration, and support.
Memcached is the classic high-performance distributed in-memory cache - a single multithreaded C daemon used to speed up web apps and databases. Unlike bare Memcached AMIs that bind to 0.0.0.0 with no authentication and leave UDP enabled (a notorious DDoS amplification vector), this Lynxroute build is security baked in: SASL authentication required, bound to the private interface only, UDP disabled, UFW firewall pre-configured, and a CIS Level 1 hardened Ubuntu 24.04 LTS base.
A locked-down, VPC-internal cache that is safe to run from first boot.
BSD-3-Clause license - fully auditable, no vendor lock-in.
This is a repackaged software product wherein additional charges apply for hardening, security configuration, and support.
WHAT IS MEMCACHED
Memcached is a high-performance, distributed in-memory object caching system, implemented as a single multithreaded C daemon built on libevent. It stores arbitrary key-value pairs in RAM to take load off databases and APIs, with a slab allocator, LRU eviction, per-key TTL expiry, atomic increment/decrement and compare-and-swap, and text, binary and meta protocols. Applications shard transparently across nodes using consistent hashing in the client, with mature client libraries for PHP, Python, Java, Node.js, Go, Ruby and most other languages. It is the battle-tested caching layer behind many of the largest web platforms. Memcached is in-memory only with no persistence by design - the cache is rebuilt by the application after a restart. BSD-3-Clause license, no vendor lock-in.
WHAT THIS AMI ADDS
Security hardening:
SASL authentication required at first boot - a unique random credential is generated, not a default or empty password
Bound to the private interface and loopback only - never 0.0.0.0, never exposed to the internet
CIS Conformance Report at /etc/lynxroute/cis-report.html
CIS Tailored Profile at /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
Highlights
Memcached security baked in: SASL authentication required, bound to the private interface only, and UDP disabled - unlike bare Memcached AMIs that bind to 0.0.0.0 with no auth and leave UDP open as a DDoS amplification vector.
CIS Level 1 hardened Ubuntu 24.04 LTS: auditd, fail2ban, AppArmor, SSH key-only, IMDSv2 enforced. CVE-scanned before every release. SBOM (CycloneDX) and CIS Conformance Report included.
Drop-in caching layer for web apps and databases: works with every standard Memcached client across PHP, Python, Java, Node.js, Go and more. BSD-3-Clause license - fully auditable, no vendor lock-in.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 5 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
You pay by the hour based on the EC2 instance size you choose to run this hardened Memcached image. Five instance types are available: t3.small, t3.medium, and t3.large use burstable general-purpose compute, while m6i.large and m6i.xlarge offer fixed general-purpose compute. Pricing scales with instance size and compute capacity, so larger instances carry a higher hourly rate. All five run the same software image; you select the size that fits your memory and workload needs. Billing is usage-based with no upfront commitment.
Top-of-mind questions for buyers
What resources do I get with each hourly instance type?
Each rate maps to one running EC2 instance of the size you pick. The t3.small, t3.medium, and t3.large use burstable compute that flexes with demand. The m6i.large and m6i.xlarge provide fixed compute. Larger sizes give more memory and CPU for bigger cache workloads.
Am I charged when the instance is stopped?
The hourly software charge meters running time only. A fully stopped instance does not accrue the software fee. You may still pay underlying AWS storage costs for the attached volume while the instance sits stopped. Charges resume when you start the instance again.
What security work is already done in this image before I deploy?
The image ships with CIS Level 1 hardening on Ubuntu 24.04 LTS, including SSH and kernel hardening, firewall, and intrusion prevention. Each release is scanned for known vulnerabilities. Unique credentials generate at first boot, so no shared or default passwords exist. A software bill of materials and conformance report are bundled inside.
lynxroute.com
Helpful?
Vendor refund policy
We do not offer refunds for this product. AWS infrastructure charges are billed separately by AWS and are not refundable by us.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Open port 11211 in the Security Group ONLY to your trusted app-tier sources (never 0.0.0.0/0)
Connect from an app server in the same VPC using a SASL-capable client on the private IP and port 11211
Memcached is a VPC-internal cache: it is bound to the private interface only, requires SASL
authentication, and has UDP disabled. It is never exposed to the public internet.
Example (Python, python-binary-memcached):
import bmemcached
c = bmemcached.Client(("<PRIVATE_IP>:11211",), "<username>", "<password>")
c.set("key", "value"); print(c.get("key"))
The SASL username and password are saved to /root/memcached-credentials.txt at first boot.
The cache is in-memory only - it is empty after a reboot by design.
Lynxroute is not affiliated with the Memcached project. This AMI packages the BSD-3-Clause open-source Memcached distribution as a self-hosted EC2 service (distinct from Amazon ElastiCache for Memcached, which is a managed offering).
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for seller support. Memcached is a high-performance, distributed memory caching system used to speed up dynamic web applications by reducing database load.
This product has charges associated with it for seller support. Memcached is a high-performance, open-source distributed memory caching system that stores frequently accessed data in RAM to reduce database load and accelerate web application performance. It is widely used to cache database queries, API responses, session data, and other dynamic content, helping applications achieve lower latency and improved scalability.
Couchbase Server is a NoSQL database that delivers unparalleled performance at scale, on premises and in any cloud. It features memory-first architecture, built-in cache, geo-distributed deployment, and workload isolation.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.