Overview
Ubuntu 22.04 LTS hardened AMI for security-conscious EC2 workloads. CoreNova Hardened AMI helps DevSecOps and platform teams launch instances quickly without building SSH, firewall, logging, and update baselines from scratch.
Save setup time Subscribe in AWS Marketplace, launch with your EC2 key pair, and connect as ubuntu. Root SSH and password login are disabled. Typical use cases: bastion hosts, application servers, security-sensitive workloads, compliance-oriented lab environments, and teams standardized on Ubuntu Jammy.
What's included
- SSH hardening: PermitRootLogin no, PasswordAuthentication no, key-only access, modern cipher suites
- UFW: SSH (22/tcp) allowed by default; add application ports as needed
- auditd, rsyslog, and chrony enabled at boot
- AIDE integrity database initialized at build time
- Automatic security updates via unattended-upgrades
Built for transparency
- Reproducible Packer-based build pipeline (same CoreNova Hardened AMI series as our Amazon Linux 2023 offering: https://aws.amazon.com/marketplace/pp/prodview-gricbzzlztsae )
- CIS-oriented OpenSCAP scan workflow for Ubuntu 22.04 L1 Server profile (buyer retains final compliance responsibility)
- SemVer product versions with changelog
Pricing and trial
- Usage-based software pricing: $0.03/hour (Apply to all instance types; EC2 infrastructure billed separately)
- 14-day free trial on software fee
Getting started
- Subscribe in AWS Marketplace
- Launch with your key pair and security group (allow SSH from your admin CIDR-not 0.0.0.0/0 in production)
- Verify: systemctl is-active auditd chrony rsyslog && sudo ufw status
- Verify SSH: sudo sshd -T | grep -E 'permitrootlogin|passwordauthentication'
Important This product provides CIS-oriented hardening and OpenSCAP scan workflows. It does not constitute official CIS certification. Final compliance decisions remain with the buyer and their auditors.
Seller: CoreNova Intelligence Limited (CoreNova) Support: CoreNovaLabs@aipalnet.cn | https://aipalnet.cn
Highlights
- Ubuntu 22.04 LTS pre-hardened in minutes-14-day free trial on software fee. SSH, UFW, auditd, AIDE, and auto security updates already applied.
- SSH hardened out of the box: PermitRootLogin no, PasswordAuthentication no, key-only access with modern cipher suites.
- Transparent Packer build plus CIS-oriented OpenSCAP scan workflow-documented hardening, not a black-box image. Same CoreNova series as our AL2023 SKU.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Cost/hour |
|---|---|
t3.small Recommended | $0.03 |
t3.micro | $0.03 |
m5.large | $0.03 |
t3.xlarge | $0.03 |
t3a.small | $0.03 |
t3a.micro | $0.03 |
t3.2xlarge | $0.03 |
t3.medium | $0.03 |
t3.nano | $0.03 |
t3a.medium | $0.03 |
Vendor refund policy
30-day refund on AWS Marketplace software fees for this product. Email CoreNovaLabs@aipalnet.cn with your AWS account ID and purchase date. Software fees only; EC2 charges are not refundable by the seller. We reply within 5 business days. Free trial: no software charges during the trial.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Ubuntu 22.04 LTS Jammy hardened baseline (SSH, UFW, auditd, AIDE, unattended-upgrades). CIS-oriented OpenSCAP workflow; not a CIS certification.
Additional details
Usage instructions
- Subscribe to this product in AWS Marketplace, then Launch instance in us-east-1.
- Choose an EC2 key pair (password login is disabled).
- Security group: allow inbound TCP 22 from your admin IP only.
- Connect: ssh -i your-key.pem ubuntu@<instance-public-ip>
- Verify: systemctl is-active auditd chrony rsyslog && sudo ufw status | head -5
- Verify SSH: sudo sshd -T | grep -E 'permitrootlogin|passwordauthentication' Expected: permitrootlogin no; passwordauthentication no.
Support
Vendor support
Email: CoreNovaLabs@aipalnet.cn Web: https://aipalnet.cn Refund: 30-day software-fee refunds per AWS Marketplace Standard Contract (SCMP) Support hours: Email, business days (5x8). Include instance ID, AWS region, AMI ID, product version, and steps to reproduce.
Support scope: Documentation and guidance for launching and verifying this AMI (SSH access, baseline services, UFW). We do not provide 24/7 managed operations or application-level support unless separately agreed.
When contacting support, include: AWS region, AMI ID, instance ID, and a description of the issue with relevant logs.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.